Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Possible Downloader Trojan/Rootkit affecting Windows Explorer and .exe


  • Please log in to reply

#1
MinstrelGeek

MinstrelGeek

    New Member

  • Member
  • Pip
  • 5 posts
Hi Geekteam! I think I may have posted this in the wrong forum location since I wasn't receiving any responses from your support team (originally in WIN XP forum). It's unnerving to see you again, meaning, I thought that my spyware/virus issues were all resolved (I had previously had major issues with w32.Virut and had to reformat the hard drive), but I'm really starting to lose hope. I have been here before under another nick, but I had to make a new account. Currently, I have this ongoing issue with Windows Explorer (not IE). Whenever I start the WIN XP OS, Explorer crashes and I receive the error message box that says "Explorer needs to shut down and be restarted. We are sorry for any inconvenience.". Then "Dr Watson" debugger comes up and crashes too. I have to then go into Task Manager to manually end the Dr Watson process and then Explorer restarts and everything is somewhat OK. The system will operate like normal until I log off and logon again or restart. I shut off the Dr Watson debugger in the registry temporarily, but that did not change anything. I hope you can give me some ideas as to why it's doing this, because I googled it, found lots of similar issues, but not one fixed the problem. I've tried to correct this by running SFC, chkdsk, un-installing/ re-installing both IE 7 and IE 8 and also SP3. Nothing worked, Windows Explorer and other executables are still crashing. Btw, I've scanned for viruses with 4 different Anti-virus scanners, both online and installed (I have Avira Antivir Premium, Norton Antivirus Online, not enabled in real time, and ThreatFire installed) and Spybot S&D with tea-timer running, SpywareGuard, Malwarebytes, SuperAntispyware and Windows Defender. The system is clean as whistle (supposedly). Any advice and suggestions you can give is welcome. I have followed all the procedures in the Malware and Spyware guide and the MBAM log is below...

Malwarebytes' Anti-Malware 1.41
Database version: 2914
Windows 5.1.2600 Service Pack 3

10/6/2009 5:06:58 AM
mbam-log-2009-10-06 (05-06-58).txt

Scan type: Quick Scan
Objects scanned: 109793
Time elapsed: 6 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

When I ran the RootRepeal scan when I got to Step 5 it was a bit confusing because the procedure didn't follow the instructions. It read as follows...

#5 In the Select Scan dialog, check:

a. Drivers
b. Processes
c. SSDT
d. Hidden Services

#6 Click the OK button
#7 In the next dialog, select all drives showing
#8 Click OK to start the scan

At #7 there was no "next dialog" to select "all drives showing". It printed out the scan results as follows, I hope it is what you were expecting...

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/06 05:25
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA81DD000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79E3000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7197000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SYMEFA.SYS
Image Path: SYMEFA.SYS
Address: 0xF7416000 Size: 323584 File Visible: No Signed: -
Status: -

SSDT
-------------------
#: 012 Function Name: NtAlertResumeThread
Status: Hooked by "<unknown>" at address 0x8ae2e2e0

#: 013 Function Name: NtAlertThread
Status: Hooked by "<unknown>" at address 0x8ac6e0e8

#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41b94

#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41586

#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a415da

#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41640

#: 041 Function Name: NtCreateKey
Status: Hooked by "TfSysMon.sys" at address 0xf740aa1c

#: 043 Function Name: NtCreateMutant
Status: Hooked by "<unknown>" at address 0x8a61c558

#: 047 Function Name: NtCreateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a4172e

#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a417ba

#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "<unknown>" at address 0x8a9ac6d8

#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a4184a

#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41980

#: 063 Function Name: NtDeleteKey
Status: Hooked by "TfSysMon.sys" at address 0xf740ac10

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "TfSysMon.sys" at address 0xf740acb6

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a419d4

#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "<unknown>" at address 0x8a9aa0a0

#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "<unknown>" at address 0x8ac91430

#: 091 Function Name: NtImpersonateThread
Status: Hooked by "<unknown>" at address 0x8accdb98

#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41a3a

#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xf7a77afa

#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "<unknown>" at address 0x8aa520c8

#: 114 Function Name: NtOpenEvent
Status: Hooked by "<unknown>" at address 0x8ac078d8

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41a8c

#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xf7a77ac8

#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x8a9fae20

#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41ae4

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41b3c

#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41bfa

#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xf7a77b04

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41c58

#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41cb6

#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41d74

#: 213 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x8aa58bb8

#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x89e1e168

#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "<unknown>" at address 0x8ab8a078

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41d08

#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41dde

#: 254 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x8a5500e8

#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41e30

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41e90

#: 258 Function Name: NtTerminateThread
Status: Hooked by "<unknown>" at address 0x8a60c1c8

#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "<unknown>" at address 0x8abb3250

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\drivers\PCTAppEvent.sys" at address 0xa7a41ef4

==EOF==

When I ran the OTL it generated the OTL.text report, but as once before it didn't make an Extras.Txt report, is this some sort of "glitch" in the program? Anyway, the report is below...

OTL logfile created on: 10/6/2009 5:37:34 AM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Dennis\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 43.35% Memory free
3.84 Gb Paging File | 2.67 Gb Available in Paging File | 69.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 58.43 Gb Free Space | 78.41% Space Free | Partition Type: NTFS
Drive D: | 34.32 Gb Total Space | 32.35 Gb Free Space | 94.28% Space Free | Partition Type: NTFS
Drive E: | 196.02 Gb Total Space | 21.37 Gb Free Space | 10.90% Space Free | Partition Type: NTFS
Drive F: | 2.54 Gb Total Space | 2.51 Gb Free Space | 98.68% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CLIFTHOUSE
Current User Name: Dennis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2006/11/03 19:19:58 | 00,013,592 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2003/07/25 10:40:48 | 00,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXBCES.EXE
PRC - [2003/07/25 10:35:59 | 00,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXPPS.EXE
PRC - [2009/02/14 16:29:14 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/08/29 15:54:49 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/08/29 15:54:18 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/10/03 19:57:32 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVGLS\avgwdsvc.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [1999/12/13 01:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe
PRC - [2009/08/28 09:24:32 | 00,609,792 | ---- | M] () -- C:\Program Files\iolo\common\lib\ioloServiceManager.exe
PRC - [2009/07/25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007/04/19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2009/04/30 16:01:10 | 00,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/02/11 11:06:36 | 00,210,216 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/10/04 01:30:44 | 00,115,560 | R--- | M] (Symantec Corporation) -- D:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
PRC - [2009/10/03 19:57:35 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVGLS\avgnsx.exe
PRC - [2008/12/11 16:58:44 | 00,146,800 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe
PRC - [2005/08/08 01:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2009/09/23 10:07:35 | 00,070,928 | ---- | M] (PC Tools) -- D:\Program Files\ThreatFire\TFService.exe
PRC - [2000/06/26 07:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe
PRC - [2009/08/29 15:54:19 | 00,194,817 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
PRC - [2009/08/29 15:54:26 | 00,434,945 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
PRC - [2009/10/04 01:30:44 | 00,115,560 | R--- | M] (Symantec Corporation) -- D:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
PRC - [2009/08/26 22:04:17 | 00,252,696 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.exe
PRC - [2009/08/26 22:04:17 | 00,162,584 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2009/08/26 22:04:17 | 00,138,008 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe
PRC - [2006/11/23 15:10:42 | 00,056,928 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2009/08/29 15:54:17 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2003/07/25 10:58:19 | 00,057,344 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
PRC - [2009/02/23 10:49:16 | 02,652,056 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
PRC - [2009/07/01 12:37:06 | 00,037,888 | ---- | M] () -- D:\Program Files\Winamp\winampa.exe
PRC - [2003/07/25 11:15:23 | 00,049,152 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
PRC - [2003/07/02 10:03:54 | 00,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
PRC - [2009/06/23 11:48:12 | 00,019,456 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTHELPER.EXE
PRC - [2003/06/18 01:00:00 | 00,045,056 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
PRC - [2006/11/27 15:19:10 | 01,582,616 | ---- | M] (Hagel Technologies Ltd) -- C:\Program Files\DU Meter\DUMeter.exe
PRC - [2009/09/23 10:07:38 | 00,382,224 | ---- | M] (PC Tools) -- D:\Program Files\ThreatFire\TFTray.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/05/08 10:35:50 | 02,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2006/11/03 19:20:12 | 00,866,584 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Defender\MSASCui.exe
PRC - [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/10/03 19:57:33 | 01,950,488 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVGLS\avgtray.exe
PRC - [2003/02/11 20:36:58 | 00,061,440 | ---- | M] (Clasys Ltd.) -- D:\Program Files\iNTERNET Turbo\idetect.exe
PRC - [2007/04/19 13:26:52 | 00,484,904 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
PRC - [2007/05/04 10:39:12 | 00,149,040 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2004/12/02 18:23:34 | 00,102,400 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PRC - [2004/08/17 15:07:44 | 00,143,360 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
PRC - [2004/11/30 11:00:00 | 00,135,168 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
PRC - [2009/06/02 08:59:46 | 05,451,536 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Logitech Vid\vid.exe
PRC - [2009/09/25 09:24:55 | 00,160,592 | ---- | M] (Siber Systems) -- D:\Program Files\AI Roboform\RoboTaskBarIcon.exe
PRC - [2007/05/04 10:39:28 | 00,910,896 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/05/08 10:34:08 | 00,559,888 | ---- | M] () -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2003/08/29 19:05:35 | 00,360,448 | ---- | M] () -- D:\Program Files\SpywareGuard\sgmain.exe
PRC - [2009/01/09 19:57:32 | 07,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2005/05/10 16:32:18 | 00,135,168 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\MediaSource\RemoteControl\OSDMenu.EXE
PRC - [2008/03/18 20:31:20 | 04,742,184 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
PRC - [2009/01/09 20:00:52 | 07,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/05/04 10:39:24 | 00,267,824 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
PRC - [2003/08/29 11:14:56 | 00,233,472 | ---- | M] () -- D:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2008/03/18 20:31:20 | 04,742,184 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
PRC - [2008/03/18 20:31:20 | 04,742,184 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
PRC - [2008/03/18 20:31:20 | 04,742,184 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
PRC - [2008/03/18 20:31:20 | 04,742,184 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/09/17 03:52:15 | 00,908,280 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/10/06 05:21:06 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Dennis\My Documents\Downloads\RootRepeal.exe
PRC - [2009/10/06 05:36:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dennis\My Documents\Downloads\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/08/29 15:54:19 | 00,194,817 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService [Auto | Running])
SRV - [2009/08/29 15:54:49 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/08/29 15:54:18 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2009/08/29 15:54:26 | 00,434,945 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService [Auto | Running])
SRV - [2009/07/09 12:22:18 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/10/03 19:57:32 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- D:\Program Files\AVG\AVGLS\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/09/13 07:35:26 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service [On_Demand | Stopped])
SRV - [1999/12/13 01:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe -- (Creative Service for CDROM Access [Auto | Running])
SRV - [2009/02/14 16:29:14 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/08/27 18:34:59 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/08/28 09:24:32 | 00,609,792 | ---- | M] () -- C:\Program Files\iolo\common\lib\ioloServiceManager.exe -- (ioloFileInfoList [Auto | Running])
SRV - [2009/08/28 09:24:32 | 00,609,792 | ---- | M] () -- C:\Program Files\iolo\common\lib\ioloServiceManager.exe -- (ioloSystemService [Auto | Running])
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/07/25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2003/07/25 10:40:48 | 00,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXBCES.EXE -- (LexBceS [Auto | Running])
SRV - [2007/04/19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2009/04/30 16:01:10 | 00,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running])
SRV - [2009/02/11 11:06:36 | 00,210,216 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/05/04 10:39:24 | 00,267,824 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])
SRV - [2009/10/04 01:30:44 | 00,115,560 | R--- | M] (Symantec Corporation) -- D:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe -- (Norton AntiVirus [Auto | Running])
SRV - [2008/12/11 16:58:44 | 00,146,800 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe -- (PCToolsFirewallPlus [Auto | Running])
SRV - [2005/08/08 01:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - [2009/09/23 10:07:35 | 00,070,928 | ---- | M] (PC Tools) -- D:\Program Files\ThreatFire\TFService.exe -- (ThreatFire [Auto | Running])
SRV - [2006/11/03 19:19:58 | 00,013,592 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend [Auto | Running])
SRV - [2000/06/26 07:44:20 | 00,053,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe -- (WMDM PMSP Service [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.ne...ch?r=minisearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.ne...ch?r=minisearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.ne...ch?r=minisearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://minstrel.blog.com/
IE - HKCU\..\URLSearchHook: *{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;cf.netzero.net;qs.netzero.ne
t;*.quicken.com;*.pogo.com;<local>

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Answers.com"
FF - prefs.js..browser.startup.homepage: "http://users.rcn.com/minstrel01"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [email protected]:2.609.002.003
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.7.4
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090525
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.07
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..keyword.URL: "http://us.yhs.search...2-tb-web_us&p="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 7900
FF - prefs.js..network.proxy.no_proxies_on: "searchap.untd.com,127.0.0.1,localhost,*microsoft.com,*windowsupdate.com,*wustat.windows.com,*test-speed.com,liveupdate.symantecliveupdate.com,*symantec.com,*.nai.com,*.networkassociates.com,cf.netzero.net,qs.netzero.ne
t,*.quicken.com,*.pogo.com,localhost,127.0.0.1"

FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/08/27 07:47:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: D:\Program Files\AI Roboform\Firefox [2009/09/25 09:28:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/26 15:22:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/10/02 17:35:55 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Program Files\AVG\AVGLS\Firefox [2009/10/03 19:57:32 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: D:\Program Files\AVG\AVGLS\Toolbar\Firefox\[email protected] [2009/10/04 21:56:32 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009/09/30 05:18:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009/10/05 13:50:37 | 00,000,000 | ---D | M]

[2009/09/14 15:47:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Extensions
[2009/09/14 15:47:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/06 04:35:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Firefox\Profiles\hahzz7le.default\extensions
[2009/09/26 15:55:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Firefox\Profiles\hahzz7le.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/06 04:35:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Firefox\Profiles\hahzz7le.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/09/23 03:55:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Firefox\Profiles\hahzz7le.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/09/23 07:39:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\mozilla\Firefox\Profiles\hahzz7le.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}

O1 HOSTS File: (338192 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11596 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVGLS\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - D:\Program Files\Norton AntiVirus\Engine\16.0.0.125\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\AI Roboform\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - D:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\AI Roboform\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - D:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - D:\Program Files\AI Roboform\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - D:\Program Files\AVG\AVGLS\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] D:\Program Files\AVG\AVGLS\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [Detect] D:\Program Files\iNTERNET Turbo\idetect.exe (Clasys Ltd.)
O4 - HKLM..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Lexmark X6100 Series] C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ThreatFire] D:\Program Files\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [Windows Defender] D:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [RoboForm] D:\Program Files\AI Roboform\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TClockEx] D:\Program Files\TClockEx\TCLOCKEX.EXE (Dale Nurden)
O4 - HKLM..\RunServices: [Detect] D:\Program Files\iNTERNET Turbo\idetect.exe (Clasys Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = D:\Program Files\Logitech\QuickCam\eReg.exe File not found
O4 - Startup: C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O8 - Extra context menu item: Customize Menu - D:\Program Files\AI Roboform\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - D:\Program Files\AI Roboform\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - D:\Program Files\AI Roboform\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - D:\Program Files\AI Roboform\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_15.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - D:\Program Files\AI Roboform\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - D:\Program Files\AI Roboform\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - D:\Program Files\AI Roboform\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - D:\Program Files\AI Roboform\RoboFormComSavePass.html ()
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - D:\Program Files\Paltalk Messenger\Paltalk.exe (AVM Software Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - D:\Program Files\AI Roboform\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - D:\Program Files\AI Roboform\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bit...m/qsax/qsax.cab (qsax Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6796.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creat...101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1254437804859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.59.247.45 208.59.247.46
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVGLS\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - D:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - D:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - D:\Program Files\SpywareGuard\spywareguard.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/26 21:12:30 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: LanmanServer - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: Messenger - File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2009/09/25 09:52:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/03 19:57:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/10/03 19:57:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8ls
[2009/09/26 20:32:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\inSpeak
[2009/10/02 17:28:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2009/10/04 05:54:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/10/04 01:30:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/10/04 01:29:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/09/25 09:28:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/10/02 17:30:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2009/10/03 18:35:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\AVG8
[2009/09/26 20:32:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\inSpeak
[2009/09/24 15:37:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\IObit
[2009/09/24 13:43:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\Paltalk
[2009/09/23 07:39:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\QuickScan
[2009/09/28 22:33:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\Steinberg
[2009/09/23 02:01:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\Windows Desktop Search
[2009/09/23 02:32:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Application Data\Windows Search
[2009/09/23 16:10:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Local Settings\Application Data\ApplicationHistory
[2009/10/03 20:01:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Local Settings\Application Data\AVG Security Toolbar
[2009/09/23 01:48:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Local Settings\Application Data\LogiShrd
[2009/10/01 13:08:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\Local Settings\Application Data\Yahoo
[2009/10/02 17:29:02 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2009/10/04 01:30:52 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009/10/03 19:57:31 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/10/03 08:36:43 | 00,000,000 | ---D | C] -- C:\Program Files\DivX
[2009/09/26 20:32:33 | 00,000,000 | ---D | C] -- C:\Program Files\inSpeak
[2009/09/25 09:52:45 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/09/25 09:52:39 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/10/02 07:27:33 | 00,000,000 | ---D | C] -- C:\Program Files\Logitech
[2009/10/02 17:28:05 | 00,000,000 | ---D | C] -- C:\Program Files\McAfee
[2009/09/25 14:55:05 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/10/04 02:38:47 | 00,000,000 | ---D | C] -- C:\Program Files\OXXOGames
[2009/09/25 09:50:35 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/09/25 14:54:55 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/10/04 05:01:01 | 00,000,000 | ---D | C] -- C:\Program Files\Selectsoft
[2009/09/25 09:24:56 | 00,000,000 | ---D | C] -- C:\Program Files\Siber Systems
[2009/09/28 17:34:20 | 00,000,000 | ---D | C] -- C:\Program Files\Steinberg
[2009/09/23 02:01:05 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2009/09/23 01:58:47 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2009/10/04 01:30:25 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2009/10/01 13:08:12 | 00,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2009/10/05 13:56:47 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/10/04 04:46:27 | 00,000,000 | -HSD | C] -- C:\WINDOWS\ftpcache
[2009/10/04 01:30:57 | 00,035,888 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/10/04 01:30:53 | 00,124,464 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/10/04 01:30:53 | 00,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/10/04 01:30:45 | 00,362,544 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.sys
[2009/10/04 01:30:45 | 00,309,296 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.sys
[2009/10/04 01:30:45 | 00,305,712 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.sys
[2009/10/04 01:30:45 | 00,254,512 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.sys
[2009/10/04 01:30:45 | 00,198,192 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symtdi.sys
[2009/10/04 01:30:45 | 00,089,904 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symfw.sys
[2009/10/04 01:30:45 | 00,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.sys
[2009/10/04 01:30:45 | 00,040,496 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symndisv.sys
[2009/10/04 01:30:45 | 00,037,424 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symndis.sys
[2009/10/04 01:30:45 | 00,034,608 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symids.sys
[2009/10/04 01:30:45 | 00,024,752 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symredrv.sys
[2009/10/04 01:30:45 | 00,012,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symdns.sys
[2009/10/04 01:30:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV\1000000.07D
[2009/10/04 01:30:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV
[2009/10/03 19:57:57 | 00,253,576 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/10/03 19:57:57 | 00,108,296 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/10/03 02:54:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop\ERU OS Backup
[2009/10/02 22:01:41 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/10/01 18:45:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/09/30 17:06:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/09/30 07:43:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/09/28 17:35:32 | 00,286,720 | ---- | C] (Steinberg) -- C:\WINDOWS\System32\Mp3com.dll
[2009/09/28 17:35:32 | 00,040,960 | ---- | C] (Steinberg Media Technologies AG) -- C:\WINDOWS\System32\Mros432.dll
[2009/09/28 17:35:32 | 00,036,864 | ---- | C] (Steinberg) -- C:\WINDOWS\System32\audioencoderenum.dll
[2009/09/26 20:32:33 | 00,168,960 | ---- | C] (Independent Codec Group / www.openacm.org) -- C:\WINDOWS\System32\speex32.acm
[2009/09/26 00:41:18 | 00,389,120 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\LameACM.acm
[2009/09/25 14:55:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/09/25 14:54:19 | 00,000,000 | ---D | C] -- C:\0367e838a123902f292eb984
[2009/09/25 09:28:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dennis\My Documents\My RoboForm Data
[2009/09/24 13:43:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\PaltalkScene
[2009/09/23 17:57:15 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2009/09/23 13:44:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2009/09/23 07:23:17 | 00,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2009/09/23 07:23:12 | 00,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2009/09/23 07:22:55 | 00,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe
[2009/09/23 07:22:49 | 00,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2009/09/23 07:22:24 | 00,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2009/09/23 07:22:20 | 00,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2009/09/23 07:22:08 | 00,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys
[2009/09/23 07:21:48 | 00,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2009/09/23 07:21:33 | 00,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2009/09/23 07:21:29 | 00,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2009/09/23 07:21:24 | 00,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2009/09/23 07:21:16 | 00,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys
[2009/09/23 07:21:11 | 00,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys
[2009/09/23 07:21:06 | 00,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys
[2009/09/23 07:21:01 | 00,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys
[2009/09/23 07:20:43 | 00,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys
[2009/09/23 07:20:24 | 00,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys
[2009/09/23 07:20:20 | 00,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys
[2009/09/23 07:20:15 | 00,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys
[2009/09/23 07:20:08 | 00,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2009/09/23 07:19:43 | 00,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2009/09/23 07:19:25 | 00,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2009/09/23 07:19:21 | 00,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2009/09/23 07:19:04 | 00,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2009/09/23 07:19:00 | 00,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2009/09/23 07:18:55 | 00,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2009/09/23 07:18:51 | 00,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2009/09/23 07:18:46 | 00,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2009/09/23 07:18:42 | 00,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2009/09/23 07:18:03 | 00,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys
[2009/09/23 07:17:57 | 00,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2009/09/23 07:17:52 | 00,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2009/09/23 07:17:51 | 00,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2009/09/23 07:17:46 | 00,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2009/09/23 07:17:42 | 00,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2009/09/23 07:17:27 | 00,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2009/09/23 07:17:23 | 00,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2009/09/23 07:16:30 | 00,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll
[2009/09/23 07:16:26 | 00,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll
[2009/09/23 07:16:22 | 00,285,760 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys
[2009/09/23 07:16:17 | 00,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2009/09/23 07:16:12 | 00,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2009/09/23 07:15:47 | 00,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys
[2009/09/23 07:15:12 | 00,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2009/09/23 07:15:07 | 00,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2009/09/23 07:15:03 | 00,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2009/09/23 07:14:59 | 00,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2009/09/23 07:14:55 | 00,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2009/09/23 07:14:25 | 00,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2009/09/23 07:14:21 | 00,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2009/09/23 07:14:17 | 00,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2009/09/23 07:14:07 | 00,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2009/09/23 07:13:35 | 00,161,568 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2009/09/23 07:13:31 | 00,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys
[2009/09/23 07:13:27 | 00,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2009/09/23 07:13:23 | 00,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2009/09/23 07:12:50 | 00,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2009/09/23 07:12:42 | 00,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2009/09/23 07:12:38 | 00,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2009/09/23 07:12:19 | 00,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2009/09/23 07:12:16 | 00,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2009/09/23 07:12:12 | 00,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2009/09/23 07:12:08 | 00,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2009/09/23 07:12:04 | 00,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2009/09/23 07:12:00 | 00,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2009/09/23 07:11:56 | 00,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2009/09/23 07:11:52 | 00,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2009/09/23 07:11:48 | 00,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys
[2009/09/23 07:11:40 | 00,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2009/09/23 07:11:36 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2009/09/23 07:11:36 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/09/23 07:11:36 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/09/23 07:11:34 | 00,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll
[2009/09/23 07:11:33 | 00,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll
[2009/09/23 07:11:31 | 00,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys
[2009/09/23 07:11:27 | 00,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys
[2009/09/23 07:11:18 | 00,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2009/09/23 07:11:11 | 00,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINDOWS\System32\dllcache\rocket.sys
[2009/09/23 07:11:07 | 00,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys
[2009/09/23 07:11:02 | 00,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\reslog32.dll
[2009/09/23 07:10:47 | 00,714,762 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2009/09/23 07:10:43 | 00,899,146 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2009/09/23 07:10:07 | 00,130,942 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlv.sys
[2009/09/23 07:10:03 | 00,112,574 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlp.sys
[2009/09/23 07:09:59 | 00,128,286 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserli.sys
[2009/09/23 07:09:44 | 00,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys
[2009/09/23 07:08:45 | 00,169,984 | ---- | C] (Cisco Systems) -- C:\WINDOWS\System32\dllcache\pcx500.sys
[2009/09/23 07:08:42 | 00,086,016 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\pctspk.exe
[2009/09/23 07:08:27 | 00,026,153 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2009/09/23 07:08:25 | 00,029,502 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\pca200e.sys
[2009/09/23 07:08:21 | 00,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys
[2009/09/23 07:07:33 | 00,054,186 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otcsercb.sys
[2009/09/23 07:07:29 | 00,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys
[2009/09/23 07:07:26 | 00,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys
[2009/09/23 07:07:22 | 00,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys
[2009/09/23 07:07:03 | 00,051,552 | ---- | C] (Kensington Technology Group) -- C:\WINDOWS\System32\dllcache\ntgrip.sys
[2009/09/23 07:06:48 | 00,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2009/09/23 07:06:45 | 00,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2009/09/23 07:06:40 | 00,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\dllcache\ngrpci.sys
[2009/09/23 07:06:39 | 00,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys
[2009/09/23 07:06:29 | 00,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys
[2009/09/23 07:06:25 | 00,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll
[2009/09/23 07:06:16 | 00,091,488 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2009/09/23 07:06:13 | 00,027,936 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3d.sys
[2009/09/23 07:06:09 | 00,033,088 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2009/09/23 07:06:06 | 00,059,104 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2009/09/23 07:06:02 | 00,013,664 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.sys
[2009/09/23 07:05:59 | 00,035,392 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.dll
[2009/09/23 07:05:48 | 00,075,520 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxport.sys
[2009/09/23 07:05:44 | 00,007,168 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxport.dll
[2009/09/23 07:05:41 | 00,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys
[2009/09/23 07:05:37 | 00,019,968 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxicfg.dll
[2009/09/23 07:05:34 | 00,021,888 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxcard.sys
[2009/09/23 07:05:29 | 00,103,296 | ---- | C] (Matrox Graphics Inc) -- C:\WINDOWS\System32\dllcache\mtxvideo.sys
[2009/09/23 07:04:46 | 00,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys
[2009/09/23 07:04:15 | 00,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2009/09/23 07:03:50 | 00,797,500 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltsmt.sys
[2009/09/23 07:03:47 | 00,802,683 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\ltsm.sys
[2009/09/23 07:03:46 | 00,420,992 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2009/09/23 07:03:42 | 00,576,746 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2009/09/23 07:03:39 | 00,727,786 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ltck000c.sys
[2009/09/23 07:03:30 | 00,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys
[2009/09/23 07:03:27 | 00,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys
[2009/09/23 07:03:23 | 00,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys
[2009/09/23 07:03:20 | 00,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys
[2009/09/23 07:03:15 | 00,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2009/09/23 07:03:12 | 00,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2009/09/23 07:02:17 | 00,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys
[2009/09/23 07:02:10 | 00,045,632 | ---- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) -- C:\WINDOWS\System32\dllcache\ip5515.sys
[2009/09/23 07:01:37 | 00,372,824 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\iconf32.dll
[2009/09/23 06:59:31 | 00,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2009/09/23 06:59:19 | 00,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2009/09/23 06:58:48 | 00,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys
[2009/09/23 06:58:46 | 00,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys
[2009/09/23 06:58:43 | 00,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys
[2009/09/23 06:58:28 | 00,454,912 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fxusbase.sys
[2009/09/23 06:58:16 | 00,455,296 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fusbbase.sys
[2009/09/23 06:58:14 | 00,455,680 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fus2base.sys
[2009/09/23 06:58:10 | 00,442,240 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2009/09/23 06:58:07 | 00,441,728 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2009/09/23 06:58:05 | 00,444,416 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcibase.sys
[2009/09/23 06:58:04 | 00,034,173 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\forehe.sys
[2009/09/23 06:57:46 | 00,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2009/09/23 06:57:42 | 00,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2009/09/23 06:57:39 | 00,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2009/09/23 06:57:31 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2009/09/23 06:57:29 | 00,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunib.dll
[2009/09/23 06:57:26 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/09/23 06:57:26 | 00,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuni.dll
[2009/09/23 06:57:24 | 00,034,816 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimg.dll
[2009/09/23 06:57:23 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/09/23 06:57:18 | 00,043,008 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucm.dll
[2009/09/23 06:57:02 | 00,072,192 | ---- | C] (ESS Technology Inc.) -- C:\WINDOWS\System32\dllcache\es1969.sys
[2009/09/23 06:55:55 | 00,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2009/09/23 06:55:50 | 00,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys
[2009/09/23 06:55:40 | 00,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2009/09/23 06:55:38 | 00,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2009/09/23 06:55:36 | 00,952,007 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diwan.sys
[2009/09/23 06:55:31 | 00,236,060 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\ditrace.exe
[2009/09/23 06:55:29 | 00,038,985 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvsu.dll
[2009/09/23 06:55:28 | 00,031,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvpp.dll
[2009/09/23 06:55:26 | 00,006,729 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvci.dll
[2009/09/23 06:55:24 | 00,091,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\dimaint.sys
[2009/09/23 06:55:00 | 00,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys
[2009/09/23 06:54:58 | 00,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys
[2009/09/23 06:54:54 | 00,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys
[2009/09/23 06:54:27 | 00,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2009/09/23 06:54:26 | 00,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2009/09/23 06:54:24 | 00,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys
[2009/09/23 06:54:23 | 00,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2009/09/23 06:54:22 | 00,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2009/09/23 06:54:21 | 00,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2009/09/23 06:54:19 | 00,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys
[2009/09/23 06:54:17 | 00,249,856 | ---- | C] (Comtrol® Corporation) -- C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2009/09/23 06:54:09 | 00,216,064 | ---- | C] (COMPAQ Inc.) -- C:\WINDOWS\System32\dllcache\cpscan.dll
[2009/09/23 06:54:07 | 00,060,970 | ---- | C] (Compaq Computer Corp.) -- C:\WINDOWS\System32\dllcache\cpqtrnd5.sys
[2009/09/23 06:53:56 | 00,020,736 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2009/09/23 06:53:47 | 00,980,034 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\cicap.sys
[2009/09/23 06:53:38 | 00,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys
[2009/09/23 06:53:37 | 00,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys
[2009/09/23 06:53:36 | 00,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys
[2009/09/23 06:53:35 | 00,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys
[2009/09/23 06:53:34 | 00,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys
[2009/09/23 06:53:32 | 00,714,698 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2009/09/23 06:53:31 | 00,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys
[2009/09/23 06:53:29 | 00,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys
[2009/09/23 06:53:28 | 00,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys
[2009/09/23 06:53:27 | 00,032,256 | ---- | C] (Eicon Technology Corporation) -- C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2009/09/23 06:53:25 | 00,164,923 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diapi2.sys
[2009/09/23 06:53:25 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/09/23 06:52:45 | 00,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys
[2009/09/23 06:52:44 | 00,010,368 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbscn.sys
[2009/09/23 06:52:43 | 00,060,416 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brserwdm.sys
[2009/09/23 06:52:43 | 00,011,008 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2009/09/23 06:52:42 | 00,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brserif.dll
[2009/09/23 06:52:41 | 00,005,120 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2009/09/23 06:52:40 | 00,039,552 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparwdm.sys
[2009/09/23 06:52:39 | 00,003,168 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparimg.sys
[2009/09/23 06:52:38 | 00,041,472 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfusb.dll
[2009/09/23 06:52:38 | 00,032,256 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2009/09/23 06:52:37 | 00,029,696 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmflpt.dll
[2009/09/23 06:52:35 | 00,015,360 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2009/09/23 06:52:35 | 00,003,968 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltup.sys
[2009/09/23 06:52:34 | 00,012,160 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2009/09/23 06:52:33 | 00,002,944 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brfilt.sys
[2009/09/23 06:52:32 | 00,012,800 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brevif.dll
[2009/09/23 06:52:32 | 00,009,728 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brcoinst.dll
[2009/09/23 06:52:31 | 00,019,456 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brbidiif.dll
[2009/09/23 06:52:27 | 00,871,388 | ---- | C] (BCM) -- C:\WINDOWS\System32\dllcache\bcmdm.sys
[2009/09/23 06:52:23 | 00,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys
[2009/09/23 06:52:22 | 00,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll
[2009/09/23 06:52:21 | 00,089,952 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\b1cbase.sys
[2009/09/23 06:52:20 | 00,037,568 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmwan.sys
[2009/09/23 06:52:20 | 00,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys
[2009/09/23 06:52:19 | 00,144,384 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmenum.dll
[2009/09/23 06:52:18 | 00,087,552 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2009/09/23 06:51:59 | 00,077,568 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ati.sys
[2009/09/23 06:51:58 | 00,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys
[2009/09/23 06:51:52 | 00,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys
[2009/09/23 06:50:58 | 00,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys
[2009/09/23 06:50:58 | 00,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys
[2009/09/23 06:50:57 | 00,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys
[2009/09/23 06:50:57 | 00,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys
[2009/09/23 06:50:56 | 00,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys
[2009/09/23 06:50:56 | 00,020,160 | ---- | C] (ADMtek Incorporated) -- C:\WINDOWS\System32\dllcache\adm8511.sys
[2009/09/23 06:50:53 | 00,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll
[2009/09/23 06:50:52 | 00,297,728 | ---- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\dllcache\ac97sis.sys
[2009/09/23 06:50:50 | 00,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll
[2009/09/23 06:50:48 | 00,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2009/09/23 06:50:47 | 00,762,780 | ---- | C] (3Com, Inc.) -- C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2009/09/23 06:50:47 | 00,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2009/09/23 02:01:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/09/23 01:59:22 | 00,000,000 | ---D | C] -- C:\d3611f46b44d2d324242a36f
[2009/09/23 01:56:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009/09/23 01:56:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2009/09/23 01:53:33 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2009/09/23 01:53:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2009/09/23 01:53:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2009/09/22 10:01:12 | 00,000,000 | -HSD | C] -- C:\found.000

========== Files - Modified Within 14 Days ==========

[2009/10/06 05:26:27 | 00,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2270AF61-FFC4-4800-A450-FF3C27AC3774}.job
[2009/10/06 04:51:59 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/10/06 04:50:16 | 04,931,715 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000000-00001102-00000004-20021102}.CDF
[2009/10/06 04:48:45 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/06 04:48:43 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/06 04:48:05 | 00,031,852 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000003-00000000-00000000-00001102-00000004-20021102}.rfx
[2009/10/06 04:48:05 | 00,031,852 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000003-00000000-00000000-00001102-00000004-20021102}.rfx
[2009/10/06 04:48:05 | 00,031,812 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000003-00000000-00000000-00001102-00000004-20021102}.rfx
[2009/10/06 04:48:05 | 00,031,812 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000003-00000000-00000000-00001102-00000004-20021102}.rfx
[2009/10/06 04:48:05 | 00,011,564 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000003-00000000-00000000-00001102-00000004-20021102}.rfx
[2009/10/06 04:03:46 | 05,296,656 | -H-- | M] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\IconCache.db
[2009/10/05 20:26:03 | 04,934,362 | ---- | M] () -- C:\WINDOWS\{00000003-00000000-00000000-00001102-00000004-20021102}.BAK
[2009/10/05 10:51:21 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/10/05 10:51:21 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2009/10/05 07:09:14 | 00,000,606 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Shortcut to iTurbo.exe.lnk
[2009/10/05 07:09:00 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/05 05:20:47 | 00,000,662 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\CableNut.lnk
[2009/10/05 05:03:20 | 00,639,582 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\Cat.DB
[2009/10/05 04:46:08 | 00,000,556 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\SpywareGuard LiveUpdate.lnk
[2009/10/05 04:46:08 | 00,000,536 | ---- | M] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\SpywareGuard.lnk
[2009/10/05 04:46:08 | 00,000,536 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\SpywareGuard.lnk
[2009/10/04 22:05:50 | 00,000,423 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iNTERNET Turbo.lnk
[2009/10/04 16:33:18 | 00,000,435 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2009/10/04 05:54:13 | 00,001,052 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\MumboJumbo.com - Premium Casual Games.lnk
[2009/10/04 05:54:13 | 00,000,886 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Samantha Swift and the Golden Touch.lnk
[2009/10/04 05:13:15 | 00,000,839 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\2002 Games.lnk
[2009/10/04 02:38:48 | 00,000,812 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Viva Game Center.lnk
[2009/10/04 01:30:53 | 00,010,635 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/10/04 01:30:52 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/10/04 01:30:52 | 00,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/10/04 01:30:52 | 00,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/10/04 01:30:46 | 00,000,958 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.lnk
[2009/10/04 01:30:45 | 00,362,544 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.sys
[2009/10/04 01:30:45 | 00,309,296 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.sys
[2009/10/04 01:30:45 | 00,305,712 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.sys
[2009/10/04 01:30:45 | 00,254,512 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.sys
[2009/10/04 01:30:45 | 00,198,192 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symtdi.sys
[2009/10/04 01:30:45 | 00,089,904 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symfw.sys
[2009/10/04 01:30:45 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.sys
[2009/10/04 01:30:45 | 00,040,496 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symndisv.sys
[2009/10/04 01:30:45 | 00,037,424 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symndis.sys
[2009/10/04 01:30:45 | 00,035,888 | R--- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SymIM.sys
[2009/10/04 01:30:45 | 00,034,608 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symids.sys
[2009/10/04 01:30:45 | 00,024,752 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symredrv.sys
[2009/10/04 01:30:45 | 00,012,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\symdns.sys
[2009/10/04 01:30:36 | 00,003,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.inf
[2009/10/04 01:30:36 | 00,001,754 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.inf
[2009/10/04 01:30:36 | 00,001,611 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymNet.inf
[2009/10/04 01:30:36 | 00,001,389 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.inf
[2009/10/04 01:30:36 | 00,001,383 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.inf
[2009/10/04 01:30:36 | 00,000,641 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.inf
[2009/10/04 01:30:36 | 00,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\isolate.ini
[2009/10/04 01:30:27 | 00,013,089 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymNet.cat
[2009/10/04 01:30:27 | 00,010,659 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.cat
[2009/10/04 01:30:27 | 00,010,621 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.cat
[2009/10/04 01:30:27 | 00,010,617 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.cat
[2009/10/04 01:30:27 | 00,010,613 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.CAT
[2009/10/04 01:30:27 | 00,010,609 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.cat
[2009/10/03 23:38:01 | 00,000,125 | ---- | M] () -- C:\WINDOWS\SBWIN.INI
[2009/10/03 19:57:58 | 00,000,632 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG LinkScanner®.lnk
[2009/10/03 19:57:57 | 00,253,576 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/10/03 19:57:57 | 00,108,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/10/03 14:23:02 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/02 22:05:33 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/02 21:45:21 | 00,001,748 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Belarc Advisor.lnk
[2009/10/02 17:31:25 | 00,000,663 | ---- | M] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/02 17:31:08 | 00,000,519 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\NTREGOPT.lnk
[2009/10/02 17:31:08 | 00,000,506 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\ERUNT.lnk
[2009/10/02 09:46:21 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/02 07:29:48 | 00,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Logitech Vid.lnk
[2009/10/02 07:27:44 | 00,001,850 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software.lnk
[2009/10/02 03:27:18 | 00,000,760 | ---- | M] () -- C:\Documents and Settings\Dennis\Application Data\setup_ldm.iss
[2009/10/02 03:14:20 | 00,000,717 | ---- | M] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2009/10/01 16:10:32 | 00,000,237 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\OriginalRCNCable.ccs
[2009/10/01 13:49:35 | 00,338,192 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/01 13:43:24 | 00,000,801 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Spybot - Search & Destroy.lnk
[2009/10/01 13:08:32 | 00,000,734 | ---- | M] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
[2009/10/01 13:08:19 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Widgets.lnk
[2009/10/01 12:59:18 | 00,000,544 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\ColorMania.lnk
[2009/09/30 12:44:11 | 00,034,595 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\TMS092109.odt
[2009/09/28 23:54:14 | 00,034,072 | ---- | M] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/28 19:45:31 | 00,160,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/28 17:38:18 | 00,000,652 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\FL Studio 4.lnk
[2009/09/28 17:36:08 | 00,000,678 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Cubasis VST 4.lnk
[2009/09/28 17:35:00 | 00,000,632 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WaveLab Lite.lnk
[2009/09/28 16:52:51 | 00,003,584 | ---- | M] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/28 15:51:07 | 00,335,280 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091001-134935.backup
[2009/09/28 15:29:11 | 00,335,280 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090928-155107.backup
[2009/09/28 13:54:37 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/09/28 03:24:45 | 00,458,784 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/09/28 03:24:45 | 00,006,560 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/09/27 08:21:00 | 00,000,789 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090928-152911.backup
[2009/09/26 22:22:55 | 00,026,659 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\WTGKSAHG.odt
[2009/09/26 21:27:15 | 00,000,616 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\inSpeak Communicator.lnk
[2009/09/26 20:57:35 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Windows Media Player.lnk
[2009/09/26 15:30:27 | 00,016,024 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\covlsamp.odt
[2009/09/26 02:31:13 | 00,622,690 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/26 02:31:13 | 00,524,188 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/09/26 02:31:13 | 00,088,596 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/09/25 09:53:28 | 00,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/09/25 09:50:55 | 00,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/09/25 07:50:50 | 00,000,241 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/09/25 01:57:52 | 00,021,327 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\DWCRsme.odt
[2009/09/25 01:57:09 | 00,073,728 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\dencresm.rsm
[2009/09/25 01:56:44 | 00,025,152 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\DenResme.odt
[2009/09/25 01:56:11 | 00,020,197 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\DennisResume.odt
[2009/09/24 15:37:10 | 00,000,748 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/09/24 15:37:10 | 00,000,154 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\IObit Freeware.url
[2009/09/24 14:56:47 | 00,011,351 | ---- | M] () -- C:\Documents and Settings\Dennis\My Documents\ACRESD08.odt
[2009/09/24 13:43:12 | 00,000,718 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PaltalkScene.lnk
[2009/09/24 13:43:12 | 00,000,524 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\Upgrade to Paltalk Extreme.lnk
[2009/09/23 10:07:48 | 00,059,664 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\TfSysMon.sys
[2009/09/23 10:07:47 | 00,033,552 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\TfNetMon.sys
[2009/09/23 10:07:46 | 00,051,984 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\TfFsMon.sys
[2009/09/23 07:44:57 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/09/23 07:39:50 | 00,000,769 | ---- | M] () -- C:\Documents and Settings\Dennis\Desktop\QuickScan Folder.lnk
[2009/09/23 06:47:34 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/09/23 06:47:33 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/09/23 02:01:21 | 00,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2009/09/23 01:59:01 | 00,000,569 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/09/23 01:56:27 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

========== Files - No Company Name ==========
[2009/10/05 07:09:14 | 00,000,606 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\Shortcut to iTurbo.exe.lnk
[2009/10/05 05:18:22 | 00,000,662 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\CableNut.lnk
[2009/10/05 04:46:08 | 00,000,556 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\SpywareGuard LiveUpdate.lnk
[2009/10/05 04:46:08 | 00,000,536 | ---- | C] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\SpywareGuard.lnk
[2009/10/05 04:46:08 | 00,000,536 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\SpywareGuard.lnk
[2009/10/04 22:05:50 | 00,000,423 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iNTERNET Turbo.lnk
[2009/10/04 05:54:13 | 00,001,052 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\MumboJumbo.com - Premium Casual Games.lnk
[2009/10/04 05:54:13 | 00,000,886 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\Samantha Swift and the Golden Touch.lnk
[2009/10/04 05:13:15 | 00,000,839 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\2002 Games.lnk
[2009/10/04 02:38:48 | 00,000,812 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Viva Game Center.lnk
[2009/10/04 01:31:12 | 00,639,582 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\Cat.DB
[2009/10/04 01:30:53 | 00,010,635 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/10/04 01:30:53 | 00,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/10/04 01:30:46 | 00,000,958 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.lnk
[2009/10/04 01:30:36 | 00,003,375 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.inf
[2009/10/04 01:30:36 | 00,001,754 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.inf
[2009/10/04 01:30:36 | 00,001,611 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymNet.inf
[2009/10/04 01:30:36 | 00,001,389 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.inf
[2009/10/04 01:30:36 | 00,001,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.inf
[2009/10/04 01:30:36 | 00,000,641 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.inf
[2009/10/04 01:30:36 | 00,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\isolate.ini
[2009/10/04 01:30:27 | 00,013,089 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymNet.cat
[2009/10/04 01:30:27 | 00,010,659 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\SymEFA.cat
[2009/10/04 01:30:27 | 00,010,621 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtspx.cat
[2009/10/04 01:30:27 | 00,010,617 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\srtsp.cat
[2009/10/04 01:30:27 | 00,010,613 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\BHDrvx86.CAT
[2009/10/04 01:30:27 | 00,010,609 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1000000.07D\ccHPx86.cat
[2009/10/03 19:57:58 | 00,000,632 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG LinkScanner®.lnk
[2009/10/03 14:27:17 | 00,000,330 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/10/02 17:31:25 | 00,000,663 | ---- | C] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/02 17:31:08 | 00,000,519 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\NTREGOPT.lnk
[2009/10/02 17:31:08 | 00,000,506 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\ERUNT.lnk
[2009/10/02 07:29:48 | 00,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Logitech Vid.lnk
[2009/10/02 07:27:43 | 00,001,850 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software.lnk
[2009/10/02 03:27:18 | 00,000,760 | ---- | C] () -- C:\Documents and Settings\Dennis\Application Data\setup_ldm.iss
[2009/10/02 03:14:38 | 00,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/10/02 03:14:20 | 00,000,717 | ---- | C] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2009/10/01 16:10:32 | 00,000,237 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\OriginalRCNCable.ccs
[2009/10/01 13:43:24 | 00,000,801 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\Spybot - Search & Destroy.lnk
[2009/10/01 13:08:32 | 00,000,734 | ---- | C] () -- C:\Documents and Settings\Dennis\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
[2009/10/01 13:08:19 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Widgets.lnk
[2009/10/01 12:59:18 | 00,000,544 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\ColorMania.lnk
[2009/09/30 21:44:13 | 00,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2270AF61-FFC4-4800-A450-FF3C27AC3774}.job
[2009/09/28 19:44:48 | 00,001,080 | ---- | C] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/09/28 19:44:48 | 00,001,080 | ---- | C] () -- C:\WINDOWS\System32\settings.sfm
[2009/09/28 17:38:18 | 00,000,652 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\FL Studio 4.lnk
[2009/09/28 17:36:08 | 00,000,678 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\Cubasis VST 4.lnk
[2009/09/28 17:35:00 | 00,000,632 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WaveLab Lite.lnk
[2009/09/28 16:52:51 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/27 18:39:00 | 00,458,784 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/09/27 18:39:00 | 00,006,560 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/09/26 20:32:41 | 00,000,616 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\inSpeak Communicator.lnk
[2009/09/26 19:19:11 | 00,026,659 | ---- | C] () -- C:\Documents and Settings\Dennis\My Documents\WTGKSAHG.odt
[2009/09/26 15:30:25 | 00,016,024 | ---- | C] () -- C:\Documents and Settings\Dennis\My Documents\covlsamp.odt
[2009/09/26 00:41:18 | 00,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2009/09/25 09:53:28 | 00,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/09/25 09:50:55 | 00,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/09/24 18:44:33 | 05,296,656 | -H-- | C] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\IconCache.db
[2009/09/24 15:37:10 | 00,000,748 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/09/24 15:37:10 | 00,000,154 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\IObit Freeware.url
[2009/09/24 13:43:12 | 00,000,718 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PaltalkScene.lnk
[2009/09/24 13:43:12 | 00,000,524 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\Upgrade to Paltalk Extreme.lnk
[2009/09/24 13:28:45 | 00,034,595 | ---- | C] () -- C:\Documents and Settings\Dennis\My Documents\TMS092109.odt
[2009/09/23 07:39:50 | 00,000,769 | ---- | C] () -- C:\Documents and Settings\Dennis\Desktop\QuickScan Folder.lnk
[2009/09/23 07:23:11 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2009/09/23 07:23:06 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2009/09/23 07:22:54 | 00,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2009/09/23 07:09:53 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2009/09/23 07:09:48 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2009/09/23 07:09:43 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2009/09/23 07:09:42 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2009/09/23 07:09:27 | 00,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2009/09/23 07:04:54 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2009/09/23 07:03:11 | 00,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2009/09/23 07:03:07 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/09/23 07:01:53 | 00,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2009/09/23 07:01:50 | 00,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2009/09/23 07:01:43 | 00,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2009/09/23 07:00:39 | 13,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2009/09/23 06:59:28 | 00,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2009/09/23 06:59:22 | 00,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2009/09/23 06:59:16 | 00,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2009/09/23 06:59:10 | 00,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2009/09/23 06:59:05 | 00,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2009/09/23 06:58:49 | 00,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2009/09/23 06:55:35 | 00,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2009/09/23 06:55:33 | 00,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2009/09/23 06:55:32 | 00,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2009/09/23 06:53:46 | 00,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2009/09/23 06:53:15 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
[2009/09/23 06:53:14 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
[2009/09/23 06:53:14 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
[2009/09/23 06:53:13 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
[2009/09/23 06:53:12 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2009/09/23 06:53:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
[2009/09/23 06:53:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
[2009/09/23 06:53:10 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
[2009/09/23 06:53:10 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
[2009/09/23 06:53:10 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
[2009/09/23 06:53:09 | 00,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
[2009/09/23 06:53:09 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
[2009/09/23 06:53:08 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
[2009/09/23 06:53:08 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
[2009/09/23 06:53:08 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
[2009/09/23 06:53:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
[2009/09/23 06:53:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
[2009/09/23 06:53:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
[2009/09/23 06:53:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
[2009/09/23 06:53:05 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
[2009/09/23 06:53:05 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
[2009/09/23 06:53:05 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
[2009/09/23 06:53:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
[2009/09/23 06:53:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
[2009/09/23 06:53:03 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
[2009/09/23 06:53:03 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
[2009/09/23 06:53:03 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
[2009/09/23 06:53:02 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
[2009/09/23 06:53:02 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
[2009/09/23 06:53:01 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
[2009/09/23 06:53:01 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
[2009/09/23 06:53:01 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
[2009/09/23 06:53:00 | 00,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
[2009/09/23 06:53:00 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
[2009/09/23 06:53:00 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
[2009/09/23 06:52:59 | 00,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
[2009/09/23 06:52:59 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
[2009/09/23 06:52:58 | 00,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
[2009/09/23 06:52:58 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
[2009/09/23 06:52:57 | 00,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
[2009/09/23 06:52:57 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
[2009/09/23 06:52:56 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
[2009/09/23 06:52:56 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
[2009/09/23 06:52:55 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
[2009/09/23 06:52:54 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
[2009/09/23 06:52:53 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
[2009/09/23 06:52:52 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
[2009/09/23 06:52:52 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
[2009/09/23 06:52:52 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
[2009/09/23 06:52:51 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
[2009/09/23 06:52:51 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
[2009/09/23 06:52:50 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
[2009/09/23 06:52:49 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
[2009/09/23 06:52:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
[2009/09/23 06:52:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
[2009/09/23 06:52:48 | 00,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
[2009/09/23 06:52:48 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
[2009/09/23 06:52:47 | 00,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
[2009/09/23 06:52:31 | 00,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009/09/23 06:52:29 | 00,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2009/09/23 06:52:13 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2009/09/23 06:52:13 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2009/09/23 06:52:12 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2009/09/23 06:52:11 | 00,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2009/09/23 06:52:11 | 00,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2009/09/23 06:52:10 | 00,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2009/09/23 06:52:09 | 00,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2009/09/23 06:52:09 | 00,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2009/09/23 06:52:07 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2009/09/23 06:52:01 | 00,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2009/09/23 02:01:21 | 00,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2009/09/23 01:56:27 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2009/09/22 06:32:26 | 00,000,241 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/09/18 04:10:38 | 00,539,099 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\phn.dat
[2009/08/31 15:15:17 | 00,034,072 | ---- | C] () -- C:\Documents and Settings\Dennis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/26 16:53:57 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

========== LOP Check ==========

[2009/10/05 11:09:02 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/09/25 09:53:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/27 07:50:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/10/03 22:45:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/08/30 21:50:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/08/27 18:27:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/09/18 10:33:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hagel Technologies
[2009/09/26 20:32:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\inSpeak
[2009/09/30 16:40:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2009/10/02 07:27:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/10/04 05:54:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/10/04 01:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Norton
[2009/10/04 01:29:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/09/25 09:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/10/06 04:49:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/03 18:35:16 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Dennis\Application Data
[2009/08/27 18:32:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Ahead
[2009/09/24 18:43:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\FileZilla
[2009/09/26 21:27:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\inSpeak
[2009/09/24 15:37:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\IObit
[2009/09/17 21:45:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\iolo
[2009/08/30 22:23:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Leadertech
[2009/10/06 04:15:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\MailWasherPro
[2009/08/30 23:56:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\OpenOffice.org
[2009/09/24 13:52:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Paltalk
[2009/08/30 23:30:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\PCToolsFirewallPlus
[2009/09/30 23:07:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\QuickScan
[2009/09/28 22:33:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Steinberg
[2009/09/02 18:39:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Watchtower
[2009/09/23 02:01:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Windows Desktop Search
[2009/09/23 02:32:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dennis\Application Data\Windows Search
[2009/10/05 07:09:00 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/10/02 09:46:21 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 06:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/06 04:51:59 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/10/06 04:48:45 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/10/06 05:26:27 | 00,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{2270AF61-FFC4-4800-A450-FF3C27AC3774}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\eventlog.dll >
[2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll

< %systemroot%\system32\scecli.dll >
[2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\netlogon.dll >

< %systemroot%\system32\cngaudit.dll >

< %systemroot%\system32\sceclt.dll >

< %systemroot%\ntelogon.dll >

< %systemroot%\system32\logevent.dll >

========== Alternate Data Streams ==========

@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

OTL Extras logfile created on: 10/6/2009 5:37:34 AM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Documents and Settings\Dennis\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 43.35% Memory free
3.84 Gb Paging File | 2.67 Gb Available in Paging File | 69.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 58.43 Gb Free Space | 78.41% Space Free | Partition Type: NTFS
Drive D: | 34.32 Gb Total Space | 32.35 Gb Free Space | 94.28% Space Free | Partition Type: NTFS
Drive E: | 196.02 Gb Total Space | 21.37 Gb Free Space | 10.90% Space Free | Partition Type: NTFS
Drive F: | 2.54 Gb Total Space | 2.51 Gb Free Space | 98.68% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CLIFTHOUSE
Current User Name: Dennis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "D:\Program Files\Microsoft FrontPage\bin\fpeditor.exe" (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Dogpile Toolbar\TroubleShooter.exe" = C:\Program Files\Dogpile Toolbar\TroubleShooter.exe:*:Enabled:Dogpile Toolbar (Helper) -- File not found
"C:\Program Files\Dogpile Toolbar\ToolbarUpdate.exe" = C:\Program Files\Dogpile Toolbar\ToolbarUpdate.exe:*:Enabled:Dogpile Toolbar (Update) -- File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"D:\Program Files\AVG\AVGLS\avgupd.exe" = D:\Program Files\AVG\AVGLS\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"D:\Program Files\AVG\AVGLS\avgnsx.exe" = D:\Program Files\AVG\AVGLS\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Logitech\Logitech Vid\Vid.exe" = C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid -- (Logitech Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 15
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{5BF2B19D-9C79-492A-8969-F059F06A627F}" = Print to Fax
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6E710E82-6D67-4889-9DCF-9D07587628C5}" = FL Studio Creative Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9E2514D9-DC24-4634-B348-61F3EF0F1628}" = Sound Blaster Audigy 2 ZS
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint Plus
"{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DE5BFF9C-84D1-4B09-9C20-54633044CB85}" = Watchtower Library 2008 - English
"{E622080F-9A8F-4A33-87DF-0AF2A73B4896}" = iNTERNET Turbo
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F61DD673-0030-4BB2-A382-7E57E97F1033}" = Nero 7 Essentials
"2002 Games" = 2002 Games
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AI RoboForm" = AI RoboForm (All Users)
"AudioCS" = Creative Audio Console
"Avg8LsUninstall" = AVG LinkScanner® 8.5
"Avira AntiVir Desktop" = Avira AntiVir Premium
"Belarc Advisor" = Belarc Advisor 8.1
"Cablenut" = Cablenut 4.08
"CDRW Drive Update" = Creative CD Burner Drive Update
"CleanUp!" = CleanUp!
"CNXT_MODEM_PCI_HSF" = PCI Soft Voice SoftRing Modem with SmartCP
"ColorMania_is1" = ColorMania 2.6
"Creative MediaSource DVD-Audio Player" = Creative MediaSource DVD-Audio Player
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Cubasis VST 4" = Cubasis VST 4
"DriverAgent_is1" = DriverAgent by eSupport.com
"dumeter3_is1" = DU Meter
"ERUNT_is1" = ERUNT 1.1j
"FaxTalk Communicator 4.5" = FaxTalk Communicator 4.5
"FrontPage v3.0" = Microsoft FrontPage 98
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Image Composer" = Microsoft Image Composer 1.5
"in_cdg" = CD+G Disc Player Plug-In for Winamp
"inSpeak_is1" = inSpeak build 525
"Karaoke Song List Creator Professional KJ Edition" = Karaoke Song List Creator Professional KJ Edition
"KaraokeDX" = Karaoke for DirectX (remove only)
"LameACM" = Lame ACM MP3 Codec
"Lexmark X6100 Series" = Lexmark X6100 Series
"lvdrivers_12.0" = Logitech Webcam Software Driver Package
"MailWasher Free_is1" = MailWasher Free
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NAV" = Norton AntiVirus
"NirSoft ShellExView" = NirSoft ShellExView
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PalTalk8.2" = PaltalkScene
"PC Tools Firewall Plus" = PC Tools Firewall Plus 5.0
"Resume Pro 3.0" = Resume Pro 3.0
"Samantha Swift and the Golden Touch" = Samantha Swift and the Golden Touch
"SpywareGuard_is1" = SpywareGuard v2.2
"SysInfo" = Creative System Information
"TClockEx v1.3_is1" = TClockEx v1.3
"WaveLab Lite" = WaveLab Lite
"WaveStudio 7" = Creative WaveStudio 7
"Winamp" = Winamp
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Widget Engine" = Yahoo! Widgets
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"FileZilla Client" = FileZilla Client 3.2.7.1

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/2/2009 8:12:02 AM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/2/2009 8:24:02 AM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/2/2009 9:21:20 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/2/2009 9:45:28 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application glbd3.tmp, version 8.1.2.0, faulting module unknown,
version 0.0.0.0, fault address 0x7342611a.

Error - 10/3/2009 8:37:07 AM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application dwpdownloader.exe, version 0.0.0.0, faulting
module unknown, version 0.0.0.0, fault address 0x7342611a.

Error - 10/3/2009 4:13:07 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/4/2009 5:33:59 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application pcpoptimize.exe, version 1.5.10.9, faulting module
pcpoptimize.exe, version 1.5.10.9, fault address 0x000010f1.

Error - 10/4/2009 5:37:22 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application pcpoptimize.exe, version 1.5.10.9, faulting module
pcpoptimize.exe, version 1.5.10.9, fault address 0x000010f1.

Error - 10/4/2009 6:02:11 PM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/5/2009 11:55:31 AM | Computer Name = CLIFTHOUSE | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

[ System Events ]
Error - 10/6/2009 4:46:03 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The LightScribeService Direct Disc Labeling Service service terminated
unexpectedly. It has done this 1 time(s).

Error - 10/6/2009 4:46:03 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/6/2009 4:46:03 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The McAfee SiteAdvisor Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 10/6/2009 4:46:03 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The iolo FileInfoList Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 10/6/2009 4:46:03 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The iolo System Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/6/2009 4:46:10 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly.
It has done this 1 time(s).

Error - 10/6/2009 4:46:10 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The PC Tools Firewall Plus service terminated unexpectedly. It has
done this 1 time(s).

Error - 10/6/2009 4:46:10 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The WMDM PMSP Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/6/2009 4:46:14 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 10/6/2009 4:46:14 AM | Computer Name = CLIFTHOUSE | Source = Service Control Manager | ID = 7034
Description = The NMIndexingService service terminated unexpectedly. It has done
this 1 time(s).


< End of report >

That's everything. I wish I could say I am looking forward to working with your team again, but I have to say, this is really getting to be an obnoxious chore trying to keep my system clean. It just decreases my productivity and stresses me out. I do really appreciate the time your team takes to help all of us out and extend my sincere thanks in advance of your help and support! ~MinstrelGeek

Just a quick update. I found the Extras.Txt file for OTL in a different folder than I was expecting it to be in so I copied/pasted right after the OTL.Txt file. I hope this all helps because the problem is beginning to get worse. I tried downloading Ewido Anti-Malware 4.0 and when I went to install it, Avira caught at least one virus that was attached to the installer. Who knows if it missed anymore. Anyway, thanks again in advance for all your help.~MinstrelGeek

Edited by MinstrelGeek, 07 October 2009 - 03:04 AM.

  • 0

Advertisements


#2
MinstrelGeek

MinstrelGeek

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Well, I can see that everybody wants to jump on this issue all at once, so after spending over 36 hours straight with only 5 hours of sleep, I've got some good news and some bad news. The bad news is, I posted in the right location in the first place. This was a WIN XP issue and not a virus/spyware issue! The more and more I researched the problem in search engines, the more I started thinking along the lines of a corrupted program. Here's the good news... to solve the problem I went through every program that starts on boot in the msconfig applet, un-installing and re-installing them one by one until the problem stopped. When I removed Internet Explorer 8 and reverted back to IE7, I noticed a change. The OS booted without the "Explorer has generated errors..." message for the first time in days! Unfortunately, when I re-started again, it was back. So, I un-installed Logitech's Express Go! webcam and drivers along with the new VID program, and reverted back to the old qc1180 drivers, knowing full well that these drivers worked perfectly before I upgraded to the newest version. This didn't change the situation any, but at least I know these drivers work without any glitches. The next step was the clincher. I upgraded my OpenOffice suite to version 3.1.1 and when I rebooted it was like the sun coming out on a rainy, dreary day! No pop-up error boxes, no DrWatson messages, NO EXPLORER SHUTDOWN-RESTART! I don't know if it was that new upgrade for OpenOffice, the reverting back to IE7, or a combination of all these changes, all I know is the issue with the Explorer generating errors, the DrWatson pop-up boxes, and semi-constant frozen desktops are cured! I believe we can close this thread. Thanks for letting me resolve this on my own. I guess it is like the old saying goes, "Experience is the best teacher." ~MinstrelGeek

Edited by MinstrelGeek, 07 October 2009 - 05:12 PM.

  • 0

#3
MinstrelGeek

MinstrelGeek

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Hi again GeekTeam!
Well, now I know why no one was jumping on this topic to try and help to resolve it. Could it be that it is such a complex issue that nobody has the correct solution? I say this because as per my previous answer to my own post, you can just disregard it! The problem has returned. Another thing I have noticed to add to the dilemma, Whenever I try to open the task manager using the keyboard short "Ctrl-Alt-Del" it won't open the applet, neither will "Ctrl-Shift-Esc". The only way to open it is to right-click the task bar and select the menu bar for "Task Manager". This is not really a major problem, just that it adds to the whole scenario of issues that I've been experiencing. I have since gone back to IE8 since it doesn't seem to have been the culprit to begin with. If anyone has any input on this issue at all, I'm open to any suggestions... as for me, back to the drawing board, I'm off to visit The Hair Club for Men... believe you me, I need it!

Update: Good news to anyone following this thread. 50% of the problem I was experiencing is solved. I located the source of the crash that caused Windows Explorer to pop-up the "Explorer.exe has generated errors and needs to be shut down... yada yada yada" window. It was a program called "Spyware Guard" that was causing the shell extention issue in Windows Explorer. Hmmm, now where have I seen that program before... Oh, yeah! Right here as an offering for Spybot protection from some of our Geekstogo Staff. It's so nice to find an actual solution for a change, instead of being part of the problem! If anyone has the same problem I highly recommend the cure, the program is called "ShellExView", by Nirsoft, and can be readily found on the internet and the company's main website (you know how to find it). Now, I will continue working on the disabled "Ctrl-Alt-Del" and "Ctrl-Shift-Esc" task manager issue, while I still have some hair left!
~ MinstrelGeek

Update2: This issue can be marked "closed". The "Ctrl-Alt-Delete" was a problem with either a "stuck" key(s) or malfunctioning keyboard and had nothing to do with Virus or Spyware disabling the shortcut keys. It is like a weight has been lifted off my back, and I still have half a head of hair too! Case CLOSED!~MinstrelGeek

Edited by MinstrelGeek, 11 October 2009 - 05:39 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP