Revshawn
Topic Starter
I played video games late into the night last night and it appears that I now have a sound problem. All of the audio coming from my computer sounds robotic.
It could very well be that my hardware is defective. I often have heating issues with my computer and a lot of times I have to leave the casing open in order to allow my computer to not overheat. But here's the weird part. When I used System Restore to roll back the computer to a previous state, the log-in music plays perfectly through the speakers for the first time I run it on that save state. So that rules out hardware defectiveness. It is only when I get to the desktop that the robotic sounds start playing through the computer again whenever I try to play a sound and from that point on the login music sounds robotic as well.
Can a virus do this? I'm trying to decide whether or not I need to go buy a sound card. This all started happening last night.
OTL Extras logfile created on: 3/17/2012 1:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.17% Memory free
3.85 Gb Paging File | 3.04 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 55.68 Gb Free Space | 23.91% Space Free | Partition Type: NTFS
Computer Name: OWNER-077917ECD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Mega Zipper.CHM] – C:\Program Files\Mega Zipper\MegaZipper.exe ()
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.chm [@ = chm.file] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"59127:TCP" = 59127:TCP:*:Enabled:Pando Media Booster
"59127:UDP" = 59127:UDP:*:Enabled:Pando Media Booster
"57975:TCP" = 57975:TCP:*:Enabled:Pando Media Booster
"57975:UDP" = 57975:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"59127:TCP" = 59127:TCP:*:Enabled:Pando Media Booster
"59127:UDP" = 59127:UDP:*:Enabled:Pando Media Booster
"57975:TCP" = 57975:TCP:*:Enabled:Pando Media Booster
"57975:UDP" = 57975:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe – (Nexon)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\StarCraft II\StarCraft II.exe" = C:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe:*:Enabled:StarCraft II
"C:\WINDOWS\system32\lxdqcoms.exe" = C:\WINDOWS\system32\lxdqcoms.exe:*:Enabled:Z2400 Series Server – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – (Google)
"C:\Program Files\Steam\steamapps\haru_p\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\haru_p\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Pidgin\pidgin.exe" = C:\Program Files\Pidgin\pidgin.exe:*:Enabled:Pidgin – (The Pidgin developer community)
"C:\Program Files\StarCraft II\Versions\Base17326\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base17326\SC2.exe:*:Enabled:StarCraft II
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – (Nexon Corp.)
"C:\Program Files\Steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe" = C:\Program Files\Steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe:*:Enabled:Lead and Gold - Gangs of the Wild West – ()
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"C:\Program Files\TalkShoe\pjsua_win.exe" = C:\Program Files\TalkShoe\pjsua_win.exe:*:Enabled:pjsua_win – ()
"C:\Program Files\Steam\steamapps\common\wolfenstein 3d\Wolf3d.bat" = C:\Program Files\Steam\steamapps\common\wolfenstein 3d\Wolf3d.bat:*:Enabled:Wolfenstein 3D – ()
"C:\Program Files\Steam\steamapps\common\altitude\altitude.exe" = C:\Program Files\Steam\steamapps\common\altitude\altitude.exe:*:Enabled:altitude
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Steam\steamapps\common\grand theft auto iv\GTAIV\GTAIV.exe" = C:\Program Files\Steam\steamapps\common\grand theft auto iv\GTAIV\GTAIV.exe:*:Enabled:Grand Theft Auto IV
"C:\Program Files\Paradox Interactive\Supreme Ruler Cold War\SupremeRulerCW.exe" = C:\Program Files\Paradox Interactive\Supreme Ruler Cold War\SupremeRulerCW.exe:*:Enabled:Supreme Ruler Cold War – (BattleGoat Studios)
"C:\Program Files\Steam\steamapps\common\sega classics\SEGAGenesisClassics.exe" = C:\Program Files\Steam\steamapps\common\sega classics\SEGAGenesisClassics.exe:*:Enabled:SEGA Genesis & Mega Drive Classics – ()
"C:\Program Files\Steam\steamapps\common\call of duty black ops\BlackOpsMP.exe" = C:\Program Files\Steam\steamapps\common\call of duty black ops\BlackOpsMP.exe:*:Enabled:Call of Duty: Black Ops - Multiplayer – ()
"C:\Program Files\Steam\steamapps\common\birth of america\BoA.exe" = C:\Program Files\Steam\steamapps\common\birth of america\BoA.exe:*:Enabled:Birth Of America – (A.G.E)
"C:\Program Files\Steam\steamapps\common\birth of america\Birth of America Quick Start.pdf" = C:\Program Files\Steam\steamapps\common\birth of america\Birth of America Quick Start.pdf:*:Enabled:Birth Of America – ()
"C:\Program Files\Steam\steamapps\common\birth of america\Docs\Birth of America Manual.pdf" = C:\Program Files\Steam\steamapps\common\birth of america\Docs\Birth of America Manual.pdf:*:Enabled:Birth Of America – ()
"C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe" = C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe:*:Enabled:DOOM 3 – (id Software)
"C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\HoI2.exe" = C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\HoI2.exe:*:Enabled:Hearts of Iron II: Complete – (Paradox Interactive)
"C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\hoi2.bat" = C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\hoi2.bat:*:Enabled:Hearts of Iron II: Complete – ()
"C:\Program Files\Steam\steamapps\common\oblivion\OblivionLauncher.exe" = C:\Program Files\Steam\steamapps\common\oblivion\OblivionLauncher.exe:*:Enabled:The Elder Scrolls IV: Oblivion – (Bethesda Softworks)
"C:\Program Files\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe" = C:\Program Files\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe:*:Enabled:Fallout: New Vegas – (Bethesda Softworks, Obsidian Entertainment)
"C:\Program Files\Steam\steamapps\common\star wars empire at war\runme.exe" = C:\Program Files\Steam\steamapps\common\star wars empire at war\runme.exe:*:Enabled:Star Wars: Empire at War Gold – ()
"C:\Program Files\Steam\steamapps\common\star wars empire at war\runme2.exe" = C:\Program Files\Steam\steamapps\common\star wars empire at war\runme2.exe:*:Enabled:Star Wars: Empire at War Gold – ()
"C:\Program Files\Steam\steamapps\common\mountblade warband\mb_warband.exe" = C:\Program Files\Steam\steamapps\common\mountblade warband\mb_warband.exe:*:Enabled:Mount & Blade: Warband – ( Taleworlds Entertainment)
"C:\Program Files\Steam\steamapps\common\recettear\recettear.exe" = C:\Program Files\Steam\steamapps\common\recettear\recettear.exe:*:Enabled:Recettear: An Item Shop's Tale – (Easygamestation, Carpe Fulgur LLC)
"C:\Program Files\Steam\steamapps\common\recettear\custom.exe" = C:\Program Files\Steam\steamapps\common\recettear\custom.exe:*:Enabled:Recettear: An Item Shop's Tale – ()
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Steam\steamapps\common\sonic adventure dx\Sonic Adventure DX.exe" = C:\Program Files\Steam\steamapps\common\sonic adventure dx\Sonic Adventure DX.exe:*:Enabled:Sonic Adventure DX – (SEGA)
"C:\Program Files\Steam\steamapps\common\sonic adventure dx\config.exe" = C:\Program Files\Steam\steamapps\common\sonic adventure dx\config.exe:*:Enabled:Sonic Adventure DX – (SEGA)
"C:\Program Files\Steam\steamapps\common\star wars battlefront ii\GameData\BattlefrontII.exe" = C:\Program Files\Steam\steamapps\common\star wars battlefront ii\GameData\BattlefrontII.exe:*:Enabled:Star Wars - Battlefront II – ()
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*:Enabled:Combat Arms – (Nexon)
"C:\Program Files\Steam\steamapps\common\portal 2\portal2.exe" = C:\Program Files\Steam\steamapps\common\portal 2\portal2.exe:*:Enabled:Portal 2 – ()
"C:\Program Files\Steam\steamapps\common\duke nukem forever\System\DukeForever.exe" = C:\Program Files\Steam\steamapps\common\duke nukem forever\System\DukeForever.exe:*:Enabled:Duke Nukem Forever – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\Shogun2.exe" = C:\Program Files\Steam\steamapps\common\total war shogun 2\Shogun2.exe:*:Enabled:Total War: SHOGUN 2 – (The Creative Assembly Ltd)
"C:\Program Files\Steam\steamapps\common\total war shogun 2\data\encyclopedia\how_to_play.html" = C:\Program Files\Steam\steamapps\common\total war shogun 2\data\encyclopedia\how_to_play.html:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat" = C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat" = C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\poker night at the inventory\CelebrityPoker.exe" = C:\Program Files\Steam\steamapps\common\poker night at the inventory\CelebrityPoker.exe:*:Enabled:Poker Night at the Inventory – (Telltale Games)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\steamapps\common\sid meier's civilization v\Launcher.exe" = C:\Program Files\Steam\steamapps\common\sid meier's civilization v\Launcher.exe:*:Enabled:Sid Meier's Civilization V – (Firaxis Games)
"C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe" = C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2 – ()
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)
"C:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe" = C:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe:*:Enabled:The Elder Scrolls V: Skyrim – (Bethesda Softworks)
"C:\Program Files\Steam\steamapps\common\the sims 3\Game\Bin\Sims3Launcher.exe" = C:\Program Files\Steam\steamapps\common\the sims 3\Game\Bin\Sims3Launcher.exe:*:Enabled:The Sims™ 3 – (Electronic Arts, Inc.)
"C:\Program Files\Steam\steamapps\common\the sims 3\Support\EA Help\Electronic_Arts_Technical_Support.htm" = C:\Program Files\Steam\steamapps\common\the sims 3\Support\EA Help\Electronic_Arts_Technical_Support.htm:*:Enabled:The Sims™ 3 – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 29
"{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}" = Jing
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EAE665D-957A-4D04-9679-3AD582008877}" = NVIDIA PhysX
"{59C80C5E-8C92-40FF-B910-2BB5C7281F61}" = Europa Universalis III
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6BF4613C-0A46-43AA-8FA8-0CB9F2C1A548}" = InterVideo WinDVR 3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77CEF490-8C06-437D-A91A-725765DFE6E0}" = Sengoku
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C3B7F54-C6E2-4A74-9937-9C6EBA10C4A2}" = Victoria 2
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A30269D0-4F0B-44BB-A169-C665CA856EEC}}_is1" = Crusader Kings II version 1.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.18
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0209
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F7AD1EF2-2670-40C2-A541-939265AF2F98}_is1" = Free Internet Eraser
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AIM_7" = AIM 7
"Ascension to the Throne_is1" = Ascension to the Throne
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"Cisco Connect" = Cisco Connect
"Combat Arms" = Combat Arms
"Crusader Kings_is1" = Crusader Kings
"Democracy 2_is1" = Democracy 2
"Deus Vult_is1" = Deus Vult
"Divine Wind_is1" = Divine Wind version 5.1
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Fraps" = Fraps (remove only)
"ie8" = Windows Internet Explorer 8
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.5.0 (Basic)
"KOIELangPack" = Korean Language Support
"Mega Zipper" = Mega Zipper 1.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Pidgin" = Pidgin
"RPGƒcƒN[ƒ‹2003 Embric" = RPGƒcƒN[ƒ‹2003 - Embric of Wulfhammer's Castle
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 105600" = Terraria
"Steam App 22130" = Hearts of Iron II: Complete
"Steam App 22330" = The Elder Scrolls IV: Oblivion
"Steam App 22380" = Fallout: New Vegas
"Steam App 2270" = Wolfenstein 3D
"Steam App 22700" = Sacred 2: Fallen Angel
"Steam App 2930" = Birth Of America
"Steam App 31280" = Poker Night at the Inventory
"Steam App 32470" = Star Wars: Empire at War Gold
"Steam App 34270" = SEGA Genesis & Mega Drive Classics
"Steam App 34330" = Total War: SHOGUN 2
"Steam App 41300" = Altitude
"Steam App 42120" = Lead and Gold - Gangs of the Wild West
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"Steam App 440" = Team Fortress 2
"Steam App 47890" = The Sims™ 3
"Steam App 48700" = Mount and Blade: Warband
"Steam App 550" = Left 4 Dead 2
"Steam App 57900" = Duke Nukem Forever
"Steam App 6060" = Star Wars - Battlefront II
"Steam App 620" = Portal 2
"Steam App 70400" = Recettear: An Item Shop's Tale
"Steam App 71250" = Sonic Adventure DX
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 9050" = DOOM 3
"Supreme Ruler Cold War_is1" = Supreme Ruler Cold War Update 7.1.1
"SystemRequirementsLab" = System Requirements Lab
"TalkShoe Live! 2.0" = TalkShoe Live! 2.0
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Victoria II: A House Divided_is1" = Victoria II: A House Divided version 2.0
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/6/2011 12:03:02 PM | Computer Name = OWNER-077917ECD | Source = Application Error | ID = 1000
Description = Faulting application eu3game.exe, version 0.0.0.0, faulting module
eu3game.exe, version 0.0.0.0, fault address 0x00532dfa.
Error - 9/21/2011 4:23:57 PM | Computer Name = OWNER-077917ECD | Source = Application Error | ID = 1000
Description = Faulting application dgcsrv.exe, version 1.4.5.17816, faulting module
libdmspvenc.dll, version 0.0.0.0, fault address 0x000173e8.
Error - 9/23/2011 9:06:02 PM | Computer Name = OWNER-077917ECD | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 14.0.835.186, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/17/2012 10:30:13 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 10:48:34 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 10:54:42 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 11:13:05 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 11:35:45 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7031
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 0 milliseconds: Restart the service.
Error - 3/17/2012 11:35:48 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 2 time(s).
Error - 3/17/2012 11:36:14 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Update Service Daemon service terminated unexpectedly.
It has done this 1 time(s).
Error - 3/17/2012 11:38:46 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).
Error - 3/17/2012 12:05:22 PM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 12:07:17 PM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
< End of report >
OTL logfile created on: 3/17/2012 1:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.17% Memory free
3.85 Gb Paging File | 3.04 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 55.68 Gb Free Space | 23.91% Space Free | Partition Type: NTFS
Computer Name: OWNER-077917ECD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\AIM\aim.exe (AOL Inc.)
PRC - C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\lxdqcoms.exe ( )
PRC - C:\Program Files\Google\Google Talk\googletalk.exe (Google)
PRC - C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)
PRC - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Yahoo!\Messenger\yui.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d6b4509225efde2a4e3db77205f8a51\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\b06e49ed8cbe07dbb90e313fa634b27b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ed2bf0d86229128c194a872f70fe15ee\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d912066086a59f09424c7c69f95e2c55\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\689bb394bcb437ed085c22a43aba30c6\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1a5d89d569e2e12842daf4d87c57361a\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\46c57d845e55232a89e98101075cd455\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\76e431fde1b252312b331f7108259fda\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\AIM\nssckbi.dll ()
MOD - C:\Program Files\Mega Zipper\contmenu.dll ()
MOD - C:\Program Files\TechSmith\Jing\Recorder.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (lxdq_device) – C:\WINDOWS\system32\lxdqcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MpKslb15de7ab) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26421DD1-7044-431A-A7B4-E6E0E4C6C210}\MpKslb15de7ab.sys File not found
DRV - (MpKsl6b98c264) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02DF796A-A198-49D2-8101-20DA646B3E4A}\MpKsl6b98c264.sys File not found
DRV - (MpKsl495d238b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{934B5864-E545-43CE-BCDF-8CCE8CEB00FF}\MpKsl495d238b.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (EagleXNt) – C:\WINDOWS\system32\drivers\EagleXNt.sys File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (AmdLLD) – C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (RTL8187B) – C:\WINDOWS\system32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (emAudio) – C:\WINDOWS\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (DCamUSBEMPIA) – C:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2304157
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2304157
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "www.google-feed.net"
FF - prefs.js..browser.startup.homepage: "http://www.rotoworld.com/teams/related/nfl/car/carolina-panthers"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..keyword.URL: "http://www.smartwebsearch.net/index.php?form=5&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 03:02:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/27 00:27:57 | 000,000,000 | —D | M]
[2010/10/20 16:03:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/28 00:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions
[2011/08/26 21:23:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/02 02:19:58 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/03/13 03:16:36 | 000,000,000 | —D | M] (XfireXO) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2011/02/06 23:35:23 | 000,002,138 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\searchplugins\GoogleFeed.xml
[2012/01/27 02:34:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5AUCYZ7E.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/03/17 03:02:02 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/27 00:27:51 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/27 00:27:51 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/04/12 09:47:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [USB2Check] C:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [WinDVR SchSvr] C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)
O4 - HKCU..\Run: [Aim] C:\Program Files\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D60DC9E-7363-4C07-A04E-FC83FC02A8FB}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/20 13:02:22 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/17 10:00:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2012/03/17 10:00:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012/03/17 01:15:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/03/17 00:41:17 | 000,000,000 | —D | C] – C:\Program Files\Adobe Photoshop CS5.1
[2012/03/17 00:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/03/17 00:39:50 | 000,000,000 | —D | C] – C:\Program Files\Adobe Download Assistant
[2012/03/17 00:39:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/03/15 22:15:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Victoria 2 5.1
[2012/03/14 20:11:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Xfire
[2012/02/23 22:56:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
[2012/02/23 22:56:25 | 000,000,000 | —D | C] – C:\Program Files\TechSmith
[2012/02/17 04:47:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Crusader Kings II
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/17 12:26:47 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/17 12:06:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/17 12:06:54 | 2145,898,496 | -HS- | M] () – C:\hiberfil.sys
[2012/03/17 11:15:36 | 000,496,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/17 11:15:36 | 000,084,558 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/17 11:12:43 | 000,267,008 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/17 02:23:52 | 000,091,656 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney Turtle Crossing.jpg
[2012/03/17 02:00:00 | 000,000,342 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-OWNER-077917ECD-Owner.job
[2012/03/17 01:48:45 | 001,253,065 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney turtle-crossing.jpg
[2012/03/17 00:39:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Download Assistant.lnk
[2012/03/17 00:30:28 | 001,203,382 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney.bmp
[2012/03/17 00:26:17 | 000,030,889 | —- | M] () – C:\Documents and Settings\Owner\Desktop\fox_hurney.jpg
[2012/03/17 00:24:53 | 001,730,231 | —- | M] () – C:\Documents and Settings\Owner\Desktop\turtle-crossing.jpg
[2012/03/16 16:58:39 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/15 19:47:02 | 000,528,358 | —- | M] () – C:\Documents and Settings\Owner\Desktop\TipDialogImage_mirroredJungle.png
[2012/03/13 15:00:39 | 000,078,840 | —- | M] () – C:\Documents and Settings\Owner\Desktop\hidden05_080222a-l.jpg
[2012/03/12 23:08:56 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/03/12 05:14:17 | 000,001,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Victoria 2.lnk
[2012/03/07 23:08:01 | 000,154,077 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Col_hdr_1.jpg
[2012/03/03 02:56:35 | 000,078,628 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gods&generalslee1.JPG;
[2012/03/03 02:51:04 | 000,502,650 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Robert E Lee 2.jpg
[2012/02/29 15:21:24 | 000,042,392 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2012/02/25 16:09:46 | 000,030,329 | —- | M] () – C:\Documents and Settings\Owner\Desktop\poptart1red1.gif
[2012/02/25 15:54:17 | 000,292,700 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/02/25 15:54:17 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/02/25 15:54:14 | 000,292,700 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/02/19 19:50:13 | 001,203,382 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The rocket.bmp
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/17 12:26:47 | 000,000,742 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/17 12:26:47 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/17 01:49:43 | 000,091,656 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney Turtle Crossing.jpg
[2012/03/17 01:48:32 | 001,253,065 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney turtle-crossing.jpg
[2012/03/17 01:17:23 | 000,000,342 | —- | C] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-OWNER-077917ECD-Owner.job
[2012/03/17 01:14:48 | 000,000,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2012/03/17 01:12:44 | 000,000,832 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2012/03/17 01:12:15 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2012/03/17 01:10:48 | 000,001,026 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2012/03/17 01:10:36 | 000,001,176 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2012/03/17 01:09:50 | 000,000,728 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Help.lnk
[2012/03/17 00:39:50 | 000,000,796 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Download Assistant.lnk
[2012/03/17 00:39:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Download Assistant.lnk
[2012/03/17 00:30:28 | 001,203,382 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney.bmp
[2012/03/17 00:26:17 | 000,030,889 | —- | C] () – C:\Documents and Settings\Owner\Desktop\fox_hurney.jpg
[2012/03/17 00:24:52 | 001,730,231 | —- | C] () – C:\Documents and Settings\Owner\Desktop\turtle-crossing.jpg
[2012/03/15 19:46:57 | 000,528,358 | —- | C] () – C:\Documents and Settings\Owner\Desktop\TipDialogImage_mirroredJungle.png
[2012/03/13 15:00:39 | 000,078,840 | —- | C] () – C:\Documents and Settings\Owner\Desktop\hidden05_080222a-l.jpg
[2012/03/12 05:14:17 | 000,001,799 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Victoria 2.lnk
[2012/03/07 23:08:00 | 000,154,077 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Col_hdr_1.jpg
[2012/03/03 02:56:34 | 000,078,628 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gods&generalslee1.JPG;
[2012/03/03 02:51:03 | 000,502,650 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Robert E Lee 2.jpg
[2012/02/29 15:21:24 | 000,042,392 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2012/02/25 16:09:45 | 000,030,329 | —- | C] () – C:\Documents and Settings\Owner\Desktop\poptart1red1.gif
[2012/02/25 15:53:02 | 000,007,843 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2012/02/19 19:50:12 | 001,203,382 | —- | C] () – C:\Documents and Settings\Owner\Desktop\The rocket.bmp
[2011/10/05 12:50:50 | 002,783,770 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/09/22 14:58:23 | 000,056,312 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/09/21 15:30:08 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/09/21 15:30:08 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/09/21 15:30:08 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/09/21 15:30:08 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/09/21 15:30:08 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/09/21 15:30:08 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/09/21 14:35:55 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2011/04/28 20:58:08 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/24 00:15:49 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/04/12 09:31:42 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/12 09:31:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/12 09:31:42 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/12 09:31:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/12 09:31:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/18 15:38:33 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2011/03/18 15:38:32 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2011/02/23 22:19:54 | 000,539,152 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/23 14:20:40 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2011/02/07 01:08:27 | 000,003,584 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/06 23:35:48 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/12/31 02:40:51 | 000,142,848 | —- | C] () – C:\WINDOWS\gamedelete.exe
[2010/12/03 00:49:41 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2010/12/03 00:49:41 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/11/24 00:59:07 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/18 21:01:53 | 000,292,700 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/18 21:01:51 | 000,292,700 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/18 21:01:51 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/10/20 16:03:31 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/10/20 14:06:48 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2010/10/20 13:41:33 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/10/20 13:38:24 | 000,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/10/20 13:03:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/10/20 13:00:01 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/20 08:49:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/10/20 08:48:26 | 000,267,008 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2011/02/08 23:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/10/21 14:52:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/07/07 23:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2010/10/20 14:49:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/11 16:20:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2011/09/21 15:34:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/10/20 14:48:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/18 22:51:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/03/18 22:51:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2012/03/17 04:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2012/03/17 01:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/02/06 23:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.minecraft
[2012/03/17 13:05:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.purple
[2011/02/08 23:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2010/10/20 14:49:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG10
[2012/01/29 00:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2012/03/17 00:39:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/03/17 10:00:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2010/10/20 16:45:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\enchant
[2012/01/29 01:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2011/09/18 01:23:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LolClient
[2011/02/25 11:44:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mount&Blade; Warband
[2012/01/29 00:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenCandy
[2011/03/16 23:21:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Red Alert 3 Demo
[2012/01/29 00:10:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sammsoft
[2010/12/12 04:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/02/22 21:16:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\The Creative Assembly
[2012/02/26 02:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TS3Client
[2010/12/18 01:59:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VBA-M
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/20 13:02:22 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/20 12:57:08 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/08/29 17:42:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/04/12 09:52:52 | 000,015,048 | —- | M] () – C:\ComboFix.txt
[2010/10/20 13:02:22 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/03/17 12:06:54 | 2145,898,496 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/10/20 13:02:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/02/08 23:24:45 | 000,000,470 | -H– | M] () – C:\IPH.PH
[2010/10/20 13:02:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 22:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 00:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/03/17 12:30:43 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/04/12 09:56:29 | 000,032,124 | —- | M] () – C:\TDSSKiller.2.4.11.0_12.04.2011_09.55.47_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/20 13:02:05 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/13 12:02:22 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/20 08:47:25 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/10/20 08:47:25 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/10/20 08:47:25 | 000,929,792 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/20 13:02:26 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/20 13:19:18 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/20 13:19:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/11/03 12:17:32 | 000,232,501 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Minecraft.exe
[2010/12/18 01:59:24 | 000,798,720 | —- | M] (http://vba-m.com/) – C:\Documents and Settings\Owner\Desktop\VisualBoyAdvance-M.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-18 00:14:14
< End of report >
It could very well be that my hardware is defective. I often have heating issues with my computer and a lot of times I have to leave the casing open in order to allow my computer to not overheat. But here's the weird part. When I used System Restore to roll back the computer to a previous state, the log-in music plays perfectly through the speakers for the first time I run it on that save state. So that rules out hardware defectiveness. It is only when I get to the desktop that the robotic sounds start playing through the computer again whenever I try to play a sound and from that point on the login music sounds robotic as well.
Can a virus do this? I'm trying to decide whether or not I need to go buy a sound card. This all started happening last night.
OTL Extras logfile created on: 3/17/2012 1:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.17% Memory free
3.85 Gb Paging File | 3.04 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 55.68 Gb Free Space | 23.91% Space Free | Partition Type: NTFS
Computer Name: OWNER-077917ECD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Mega Zipper.CHM] – C:\Program Files\Mega Zipper\MegaZipper.exe ()
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.chm [@ = chm.file] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"59127:TCP" = 59127:TCP:*:Enabled:Pando Media Booster
"59127:UDP" = 59127:UDP:*:Enabled:Pando Media Booster
"57975:TCP" = 57975:TCP:*:Enabled:Pando Media Booster
"57975:UDP" = 57975:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"59127:TCP" = 59127:TCP:*:Enabled:Pando Media Booster
"59127:UDP" = 59127:UDP:*:Enabled:Pando Media Booster
"57975:TCP" = 57975:TCP:*:Enabled:Pando Media Booster
"57975:UDP" = 57975:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe – (Nexon)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\StarCraft II\StarCraft II.exe" = C:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base16755\SC2.exe:*:Enabled:StarCraft II
"C:\WINDOWS\system32\lxdqcoms.exe" = C:\WINDOWS\system32\lxdqcoms.exe:*:Enabled:Z2400 Series Server – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqtime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdqjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – (Google)
"C:\Program Files\Steam\steamapps\haru_p\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\haru_p\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Pidgin\pidgin.exe" = C:\Program Files\Pidgin\pidgin.exe:*:Enabled:Pidgin – (The Pidgin developer community)
"C:\Program Files\StarCraft II\Versions\Base17326\SC2.exe" = C:\Program Files\StarCraft II\Versions\Base17326\SC2.exe:*:Enabled:StarCraft II
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – (Nexon Corp.)
"C:\Program Files\Steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe" = C:\Program Files\Steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe:*:Enabled:Lead and Gold - Gangs of the Wild West – ()
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"C:\Program Files\TalkShoe\pjsua_win.exe" = C:\Program Files\TalkShoe\pjsua_win.exe:*:Enabled:pjsua_win – ()
"C:\Program Files\Steam\steamapps\common\wolfenstein 3d\Wolf3d.bat" = C:\Program Files\Steam\steamapps\common\wolfenstein 3d\Wolf3d.bat:*:Enabled:Wolfenstein 3D – ()
"C:\Program Files\Steam\steamapps\common\altitude\altitude.exe" = C:\Program Files\Steam\steamapps\common\altitude\altitude.exe:*:Enabled:altitude
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Steam\steamapps\common\grand theft auto iv\GTAIV\GTAIV.exe" = C:\Program Files\Steam\steamapps\common\grand theft auto iv\GTAIV\GTAIV.exe:*:Enabled:Grand Theft Auto IV
"C:\Program Files\Paradox Interactive\Supreme Ruler Cold War\SupremeRulerCW.exe" = C:\Program Files\Paradox Interactive\Supreme Ruler Cold War\SupremeRulerCW.exe:*:Enabled:Supreme Ruler Cold War – (BattleGoat Studios)
"C:\Program Files\Steam\steamapps\common\sega classics\SEGAGenesisClassics.exe" = C:\Program Files\Steam\steamapps\common\sega classics\SEGAGenesisClassics.exe:*:Enabled:SEGA Genesis & Mega Drive Classics – ()
"C:\Program Files\Steam\steamapps\common\call of duty black ops\BlackOpsMP.exe" = C:\Program Files\Steam\steamapps\common\call of duty black ops\BlackOpsMP.exe:*:Enabled:Call of Duty: Black Ops - Multiplayer – ()
"C:\Program Files\Steam\steamapps\common\birth of america\BoA.exe" = C:\Program Files\Steam\steamapps\common\birth of america\BoA.exe:*:Enabled:Birth Of America – (A.G.E)
"C:\Program Files\Steam\steamapps\common\birth of america\Birth of America Quick Start.pdf" = C:\Program Files\Steam\steamapps\common\birth of america\Birth of America Quick Start.pdf:*:Enabled:Birth Of America – ()
"C:\Program Files\Steam\steamapps\common\birth of america\Docs\Birth of America Manual.pdf" = C:\Program Files\Steam\steamapps\common\birth of america\Docs\Birth of America Manual.pdf:*:Enabled:Birth Of America – ()
"C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe" = C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe:*:Enabled:DOOM 3 – (id Software)
"C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\HoI2.exe" = C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\HoI2.exe:*:Enabled:Hearts of Iron II: Complete – (Paradox Interactive)
"C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\hoi2.bat" = C:\Program Files\Steam\steamapps\common\hearts of iron 2 complete pack\hoi2.bat:*:Enabled:Hearts of Iron II: Complete – ()
"C:\Program Files\Steam\steamapps\common\oblivion\OblivionLauncher.exe" = C:\Program Files\Steam\steamapps\common\oblivion\OblivionLauncher.exe:*:Enabled:The Elder Scrolls IV: Oblivion – (Bethesda Softworks)
"C:\Program Files\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe" = C:\Program Files\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe:*:Enabled:Fallout: New Vegas – (Bethesda Softworks, Obsidian Entertainment)
"C:\Program Files\Steam\steamapps\common\star wars empire at war\runme.exe" = C:\Program Files\Steam\steamapps\common\star wars empire at war\runme.exe:*:Enabled:Star Wars: Empire at War Gold – ()
"C:\Program Files\Steam\steamapps\common\star wars empire at war\runme2.exe" = C:\Program Files\Steam\steamapps\common\star wars empire at war\runme2.exe:*:Enabled:Star Wars: Empire at War Gold – ()
"C:\Program Files\Steam\steamapps\common\mountblade warband\mb_warband.exe" = C:\Program Files\Steam\steamapps\common\mountblade warband\mb_warband.exe:*:Enabled:Mount & Blade: Warband – ( Taleworlds Entertainment)
"C:\Program Files\Steam\steamapps\common\recettear\recettear.exe" = C:\Program Files\Steam\steamapps\common\recettear\recettear.exe:*:Enabled:Recettear: An Item Shop's Tale – (Easygamestation, Carpe Fulgur LLC)
"C:\Program Files\Steam\steamapps\common\recettear\custom.exe" = C:\Program Files\Steam\steamapps\common\recettear\custom.exe:*:Enabled:Recettear: An Item Shop's Tale – ()
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Steam\steamapps\common\sonic adventure dx\Sonic Adventure DX.exe" = C:\Program Files\Steam\steamapps\common\sonic adventure dx\Sonic Adventure DX.exe:*:Enabled:Sonic Adventure DX – (SEGA)
"C:\Program Files\Steam\steamapps\common\sonic adventure dx\config.exe" = C:\Program Files\Steam\steamapps\common\sonic adventure dx\config.exe:*:Enabled:Sonic Adventure DX – (SEGA)
"C:\Program Files\Steam\steamapps\common\star wars battlefront ii\GameData\BattlefrontII.exe" = C:\Program Files\Steam\steamapps\common\star wars battlefront ii\GameData\BattlefrontII.exe:*:Enabled:Star Wars - Battlefront II – ()
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*:Enabled:Combat Arms – (Nexon)
"C:\Program Files\Steam\steamapps\common\portal 2\portal2.exe" = C:\Program Files\Steam\steamapps\common\portal 2\portal2.exe:*:Enabled:Portal 2 – ()
"C:\Program Files\Steam\steamapps\common\duke nukem forever\System\DukeForever.exe" = C:\Program Files\Steam\steamapps\common\duke nukem forever\System\DukeForever.exe:*:Enabled:Duke Nukem Forever – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\Shogun2.exe" = C:\Program Files\Steam\steamapps\common\total war shogun 2\Shogun2.exe:*:Enabled:Total War: SHOGUN 2 – (The Creative Assembly Ltd)
"C:\Program Files\Steam\steamapps\common\total war shogun 2\data\encyclopedia\how_to_play.html" = C:\Program Files\Steam\steamapps\common\total war shogun 2\data\encyclopedia\how_to_play.html:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat" = C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat" = C:\Program Files\Steam\steamapps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat:*:Enabled:Total War: SHOGUN 2 – ()
"C:\Program Files\Steam\steamapps\common\poker night at the inventory\CelebrityPoker.exe" = C:\Program Files\Steam\steamapps\common\poker night at the inventory\CelebrityPoker.exe:*:Enabled:Poker Night at the Inventory – (Telltale Games)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\steamapps\common\sid meier's civilization v\Launcher.exe" = C:\Program Files\Steam\steamapps\common\sid meier's civilization v\Launcher.exe:*:Enabled:Sid Meier's Civilization V – (Firaxis Games)
"C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe" = C:\Program Files\Steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2 – ()
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)
"C:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe" = C:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe:*:Enabled:The Elder Scrolls V: Skyrim – (Bethesda Softworks)
"C:\Program Files\Steam\steamapps\common\the sims 3\Game\Bin\Sims3Launcher.exe" = C:\Program Files\Steam\steamapps\common\the sims 3\Game\Bin\Sims3Launcher.exe:*:Enabled:The Sims™ 3 – (Electronic Arts, Inc.)
"C:\Program Files\Steam\steamapps\common\the sims 3\Support\EA Help\Electronic_Arts_Technical_Support.htm" = C:\Program Files\Steam\steamapps\common\the sims 3\Support\EA Help\Electronic_Arts_Technical_Support.htm:*:Enabled:The Sims™ 3 – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 29
"{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}" = Jing
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EAE665D-957A-4D04-9679-3AD582008877}" = NVIDIA PhysX
"{59C80C5E-8C92-40FF-B910-2BB5C7281F61}" = Europa Universalis III
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6BF4613C-0A46-43AA-8FA8-0CB9F2C1A548}" = InterVideo WinDVR 3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77CEF490-8C06-437D-A91A-725765DFE6E0}" = Sengoku
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C3B7F54-C6E2-4A74-9937-9C6EBA10C4A2}" = Victoria 2
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A30269D0-4F0B-44BB-A169-C665CA856EEC}}_is1" = Crusader Kings II version 1.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.18
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0209
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F7AD1EF2-2670-40C2-A541-939265AF2F98}_is1" = Free Internet Eraser
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AIM_7" = AIM 7
"Ascension to the Throne_is1" = Ascension to the Throne
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"Cisco Connect" = Cisco Connect
"Combat Arms" = Combat Arms
"Crusader Kings_is1" = Crusader Kings
"Democracy 2_is1" = Democracy 2
"Deus Vult_is1" = Deus Vult
"Divine Wind_is1" = Divine Wind version 5.1
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Fraps" = Fraps (remove only)
"ie8" = Windows Internet Explorer 8
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.5.0 (Basic)
"KOIELangPack" = Korean Language Support
"Mega Zipper" = Mega Zipper 1.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Pidgin" = Pidgin
"RPGƒcƒN[ƒ‹2003 Embric" = RPGƒcƒN[ƒ‹2003 - Embric of Wulfhammer's Castle
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 105600" = Terraria
"Steam App 22130" = Hearts of Iron II: Complete
"Steam App 22330" = The Elder Scrolls IV: Oblivion
"Steam App 22380" = Fallout: New Vegas
"Steam App 2270" = Wolfenstein 3D
"Steam App 22700" = Sacred 2: Fallen Angel
"Steam App 2930" = Birth Of America
"Steam App 31280" = Poker Night at the Inventory
"Steam App 32470" = Star Wars: Empire at War Gold
"Steam App 34270" = SEGA Genesis & Mega Drive Classics
"Steam App 34330" = Total War: SHOGUN 2
"Steam App 41300" = Altitude
"Steam App 42120" = Lead and Gold - Gangs of the Wild West
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"Steam App 440" = Team Fortress 2
"Steam App 47890" = The Sims™ 3
"Steam App 48700" = Mount and Blade: Warband
"Steam App 550" = Left 4 Dead 2
"Steam App 57900" = Duke Nukem Forever
"Steam App 6060" = Star Wars - Battlefront II
"Steam App 620" = Portal 2
"Steam App 70400" = Recettear: An Item Shop's Tale
"Steam App 71250" = Sonic Adventure DX
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 9050" = DOOM 3
"Supreme Ruler Cold War_is1" = Supreme Ruler Cold War Update 7.1.1
"SystemRequirementsLab" = System Requirements Lab
"TalkShoe Live! 2.0" = TalkShoe Live! 2.0
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Victoria II: A House Divided_is1" = Victoria II: A House Divided version 2.0
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/6/2011 12:03:02 PM | Computer Name = OWNER-077917ECD | Source = Application Error | ID = 1000
Description = Faulting application eu3game.exe, version 0.0.0.0, faulting module
eu3game.exe, version 0.0.0.0, fault address 0x00532dfa.
Error - 9/21/2011 4:23:57 PM | Computer Name = OWNER-077917ECD | Source = Application Error | ID = 1000
Description = Faulting application dgcsrv.exe, version 1.4.5.17816, faulting module
libdmspvenc.dll, version 0.0.0.0, fault address 0x000173e8.
Error - 9/23/2011 9:06:02 PM | Computer Name = OWNER-077917ECD | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 14.0.835.186, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/17/2012 10:30:13 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 10:48:34 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 10:54:42 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 11:13:05 AM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 11:35:45 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7031
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 0 milliseconds: Restart the service.
Error - 3/17/2012 11:35:48 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 2 time(s).
Error - 3/17/2012 11:36:14 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Update Service Daemon service terminated unexpectedly.
It has done this 1 time(s).
Error - 3/17/2012 11:38:46 AM | Computer Name = OWNER-077917ECD | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).
Error - 3/17/2012 12:05:22 PM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
Error - 3/17/2012 12:07:17 PM | Computer Name = OWNER-077917ECD | Source = Tcpip | ID = 4191
Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.
Interfaces
on this adapter will not be initialized.
< End of report >
OTL logfile created on: 3/17/2012 1:16:27 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 75.17% Memory free
3.85 Gb Paging File | 3.04 Gb Available in Paging File | 78.93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 55.68 Gb Free Space | 23.91% Space Free | Partition Type: NTFS
Computer Name: OWNER-077917ECD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\AIM\aim.exe (AOL Inc.)
PRC - C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\lxdqcoms.exe ( )
PRC - C:\Program Files\Google\Google Talk\googletalk.exe (Google)
PRC - C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)
PRC - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Yahoo!\Messenger\yui.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d6b4509225efde2a4e3db77205f8a51\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\b06e49ed8cbe07dbb90e313fa634b27b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ed2bf0d86229128c194a872f70fe15ee\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d912066086a59f09424c7c69f95e2c55\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\689bb394bcb437ed085c22a43aba30c6\PresentationFramework.Luna.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1a5d89d569e2e12842daf4d87c57361a\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\46c57d845e55232a89e98101075cd455\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\76e431fde1b252312b331f7108259fda\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\AIM\nssckbi.dll ()
MOD - C:\Program Files\Mega Zipper\contmenu.dll ()
MOD - C:\Program Files\TechSmith\Jing\Recorder.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (lxdq_device) – C:\WINDOWS\system32\lxdqcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MpKslb15de7ab) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26421DD1-7044-431A-A7B4-E6E0E4C6C210}\MpKslb15de7ab.sys File not found
DRV - (MpKsl6b98c264) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{02DF796A-A198-49D2-8101-20DA646B3E4A}\MpKsl6b98c264.sys File not found
DRV - (MpKsl495d238b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{934B5864-E545-43CE-BCDF-8CCE8CEB00FF}\MpKsl495d238b.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (EagleXNt) – C:\WINDOWS\system32\drivers\EagleXNt.sys File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (AmdLLD) – C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (RTL8187B) – C:\WINDOWS\system32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (emAudio) – C:\WINDOWS\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (DCamUSBEMPIA) – C:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2304157
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2304157
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "www.google-feed.net"
FF - prefs.js..browser.startup.homepage: "http://www.rotoworld.com/teams/related/nfl/car/carolina-panthers"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..keyword.URL: "http://www.smartwebsearch.net/index.php?form=5&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/17 03:02:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/27 00:27:57 | 000,000,000 | —D | M]
[2010/10/20 16:03:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/28 00:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions
[2011/08/26 21:23:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/02 02:19:58 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/03/13 03:16:36 | 000,000,000 | —D | M] (XfireXO) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2011/02/06 23:35:23 | 000,002,138 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5aucyz7e.default\searchplugins\GoogleFeed.xml
[2012/01/27 02:34:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5AUCYZ7E.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/03/17 03:02:02 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/27 00:27:51 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/27 00:27:51 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/04/12 09:47:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [USB2Check] C:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [WinDVR SchSvr] C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe (InterVideo Inc.)
O4 - HKCU..\Run: [Aim] C:\Program Files\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Jing] C:\Program Files\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D60DC9E-7363-4C07-A04E-FC83FC02A8FB}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/20 13:02:22 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/17 10:00:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2012/03/17 10:00:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012/03/17 01:15:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/03/17 00:41:17 | 000,000,000 | —D | C] – C:\Program Files\Adobe Photoshop CS5.1
[2012/03/17 00:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/03/17 00:39:50 | 000,000,000 | —D | C] – C:\Program Files\Adobe Download Assistant
[2012/03/17 00:39:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/03/15 22:15:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Victoria 2 5.1
[2012/03/14 20:11:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Xfire
[2012/02/23 22:56:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TechSmith
[2012/02/23 22:56:25 | 000,000,000 | —D | C] – C:\Program Files\TechSmith
[2012/02/17 04:47:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Crusader Kings II
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/17 12:26:47 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/17 12:06:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/17 12:06:54 | 2145,898,496 | -HS- | M] () – C:\hiberfil.sys
[2012/03/17 11:15:36 | 000,496,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/17 11:15:36 | 000,084,558 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/17 11:12:43 | 000,267,008 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/17 02:23:52 | 000,091,656 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney Turtle Crossing.jpg
[2012/03/17 02:00:00 | 000,000,342 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-OWNER-077917ECD-Owner.job
[2012/03/17 01:48:45 | 001,253,065 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney turtle-crossing.jpg
[2012/03/17 00:39:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Download Assistant.lnk
[2012/03/17 00:30:28 | 001,203,382 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney.bmp
[2012/03/17 00:26:17 | 000,030,889 | —- | M] () – C:\Documents and Settings\Owner\Desktop\fox_hurney.jpg
[2012/03/17 00:24:53 | 001,730,231 | —- | M] () – C:\Documents and Settings\Owner\Desktop\turtle-crossing.jpg
[2012/03/16 16:58:39 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/15 19:47:02 | 000,528,358 | —- | M] () – C:\Documents and Settings\Owner\Desktop\TipDialogImage_mirroredJungle.png
[2012/03/13 15:00:39 | 000,078,840 | —- | M] () – C:\Documents and Settings\Owner\Desktop\hidden05_080222a-l.jpg
[2012/03/12 23:08:56 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/03/12 05:14:17 | 000,001,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Victoria 2.lnk
[2012/03/07 23:08:01 | 000,154,077 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Col_hdr_1.jpg
[2012/03/03 02:56:35 | 000,078,628 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gods&generalslee1.JPG;
[2012/03/03 02:51:04 | 000,502,650 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Robert E Lee 2.jpg
[2012/02/29 15:21:24 | 000,042,392 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2012/02/25 16:09:46 | 000,030,329 | —- | M] () – C:\Documents and Settings\Owner\Desktop\poptart1red1.gif
[2012/02/25 15:54:17 | 000,292,700 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2012/02/25 15:54:17 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2012/02/25 15:54:14 | 000,292,700 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2012/02/19 19:50:13 | 001,203,382 | —- | M] () – C:\Documents and Settings\Owner\Desktop\The rocket.bmp
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/17 12:26:47 | 000,000,742 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/17 12:26:47 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/17 01:49:43 | 000,091,656 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney Turtle Crossing.jpg
[2012/03/17 01:48:32 | 001,253,065 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney turtle-crossing.jpg
[2012/03/17 01:17:23 | 000,000,342 | —- | C] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-OWNER-077917ECD-Owner.job
[2012/03/17 01:14:48 | 000,000,870 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2012/03/17 01:12:44 | 000,000,832 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2012/03/17 01:12:15 | 000,000,925 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2012/03/17 01:10:48 | 000,001,026 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2012/03/17 01:10:36 | 000,001,176 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2012/03/17 01:09:50 | 000,000,728 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Help.lnk
[2012/03/17 00:39:50 | 000,000,796 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Download Assistant.lnk
[2012/03/17 00:39:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Download Assistant.lnk
[2012/03/17 00:30:28 | 001,203,382 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Marty Hurney.bmp
[2012/03/17 00:26:17 | 000,030,889 | —- | C] () – C:\Documents and Settings\Owner\Desktop\fox_hurney.jpg
[2012/03/17 00:24:52 | 001,730,231 | —- | C] () – C:\Documents and Settings\Owner\Desktop\turtle-crossing.jpg
[2012/03/15 19:46:57 | 000,528,358 | —- | C] () – C:\Documents and Settings\Owner\Desktop\TipDialogImage_mirroredJungle.png
[2012/03/13 15:00:39 | 000,078,840 | —- | C] () – C:\Documents and Settings\Owner\Desktop\hidden05_080222a-l.jpg
[2012/03/12 05:14:17 | 000,001,799 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Victoria 2.lnk
[2012/03/07 23:08:00 | 000,154,077 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Col_hdr_1.jpg
[2012/03/03 02:56:34 | 000,078,628 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gods&generalslee1.JPG;
[2012/03/03 02:51:03 | 000,502,650 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Robert E Lee 2.jpg
[2012/02/29 15:21:24 | 000,042,392 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2012/02/25 16:09:45 | 000,030,329 | —- | C] () – C:\Documents and Settings\Owner\Desktop\poptart1red1.gif
[2012/02/25 15:53:02 | 000,007,843 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2012/02/19 19:50:12 | 001,203,382 | —- | C] () – C:\Documents and Settings\Owner\Desktop\The rocket.bmp
[2011/10/05 12:50:50 | 002,783,770 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/09/22 14:58:23 | 000,056,312 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/09/21 15:30:08 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2011/09/21 15:30:08 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2011/09/21 15:30:08 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2011/09/21 15:30:08 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2011/09/21 15:30:08 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2011/09/21 15:30:08 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2011/09/21 14:35:55 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2011/04/28 20:58:08 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/24 00:15:49 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/04/12 09:31:42 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/12 09:31:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/12 09:31:42 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/12 09:31:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/12 09:31:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/18 15:38:33 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2011/03/18 15:38:32 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2011/02/23 22:19:54 | 000,539,152 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/23 14:20:40 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2011/02/07 01:08:27 | 000,003,584 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/06 23:35:48 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/12/31 02:40:51 | 000,142,848 | —- | C] () – C:\WINDOWS\gamedelete.exe
[2010/12/03 00:49:41 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2010/12/03 00:49:41 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/11/24 00:59:07 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/18 21:01:53 | 000,292,700 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/18 21:01:51 | 000,292,700 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/18 21:01:51 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/10/20 16:03:31 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/10/20 14:06:48 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2010/10/20 13:41:33 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/10/20 13:38:24 | 000,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/10/20 13:03:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/10/20 13:00:01 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/10/20 08:49:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/10/20 08:48:26 | 000,267,008 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2011/02/08 23:23:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/10/21 14:52:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/07/07 23:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2010/10/20 14:49:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/11 16:20:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2011/09/21 15:34:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/10/20 14:48:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/18 22:51:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/03/18 22:51:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2012/03/17 04:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2012/03/17 01:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/02/06 23:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.minecraft
[2012/03/17 13:05:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\.purple
[2011/02/08 23:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2010/10/20 14:49:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG10
[2012/01/29 00:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2012/03/17 00:39:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/03/17 10:00:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2010/10/20 16:45:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\enchant
[2012/01/29 01:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2011/09/18 01:23:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LolClient
[2011/02/25 11:44:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mount&Blade; Warband
[2012/01/29 00:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenCandy
[2011/03/16 23:21:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Red Alert 3 Demo
[2012/01/29 00:10:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sammsoft
[2010/12/12 04:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/02/22 21:16:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\The Creative Assembly
[2012/02/26 02:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TS3Client
[2010/12/18 01:59:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VBA-M
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/20 13:02:22 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/20 12:57:08 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/08/29 17:42:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/04/12 09:52:52 | 000,015,048 | —- | M] () – C:\ComboFix.txt
[2010/10/20 13:02:22 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/03/17 12:06:54 | 2145,898,496 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/10/20 13:02:22 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/02/08 23:24:45 | 000,000,470 | -H– | M] () – C:\IPH.PH
[2010/10/20 13:02:22 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 22:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 00:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/03/17 12:30:43 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/04/12 09:56:29 | 000,032,124 | —- | M] () – C:\TDSSKiller.2.4.11.0_12.04.2011_09.55.47_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/20 13:02:05 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/08/13 12:02:22 | 000,147,968 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdqdrpp.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/20 08:47:25 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/10/20 08:47:25 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/10/20 08:47:25 | 000,929,792 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/20 13:02:26 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/20 13:19:18 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/20 13:19:17 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/11/03 12:17:32 | 000,232,501 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Minecraft.exe
[2010/12/18 01:59:24 | 000,798,720 | —- | M] (http://vba-m.com/) – C:\Documents and Settings\Owner\Desktop\VisualBoyAdvance-M.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-18 00:14:14
< End of report >