Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malwarebytes reports attempted access to malicious ip's


  • Please log in to reply

#1
orranis19

orranis19

    New Member

  • Member
  • Pip
  • 5 posts
First off, I have done everything asked of me in the Malware and Spyware Cleaning Guide (TFC, Erunt, and SysRestore Point have all been executed).

Secondly, the copy of Malwarebytes on this computer has recently been upgraded to the paid-for version; when the IP protection was enabled it immediately started reporting that it was detecting and blocking regular attempts by this computer to access malicious IP addresses.

The virus/trojan and malware/adware scans turn up clean, but the reports keep on coming in.

Note: This computer is shared by a bunch of guys, but I try to keep tabs on what happens on it and what is installed, etc. and am in charge of routine maintenance. The computer receives heavy daily usage, though, and has ever since it became a shared computer about a year and a half ago.

Thank You in advance.



Here are the scan reports:



OTL log

OTL logfile created on: 11/19/2009 12:56:27 PM - Run 1
OTL by OldTimer - Version 3.1.6.0 Folder = C:\Documents and Settings\Everybody\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.07 Gb Available Physical Memory | 53.61% Memory free
3.84 Gb Paging File | 2.85 Gb Available in Paging File | 74.03% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 7.92 Gb Free Space | 10.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LIVINGROOM
Current User Name: Everybody
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/11/19 12:54:47 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Everybody\Desktop\OTL.exe
PRC - [2009/11/12 15:48:16 | 00,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe
PRC - [2009/11/11 18:11:40 | 00,921,072 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Everybody\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/11/11 18:11:40 | 00,921,072 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Everybody\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/10/08 12:13:54 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
PRC - [2009/10/08 11:31:44 | 00,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/09/23 12:33:42 | 01,141,200 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2009/09/23 11:17:22 | 00,358,600 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009/09/22 16:11:32 | 01,243,088 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2009/09/10 13:54:02 | 00,269,648 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2009/09/10 13:54:00 | 00,420,176 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2009/08/28 18:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/08/28 08:22:11 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/04/01 14:45:53 | 00,091,440 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PRC - [2009/03/05 15:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/05/21 16:26:10 | 00,451,896 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe
PRC - [2008/05/16 05:11:44 | 00,648,504 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2008/05/02 01:44:08 | 00,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/05/02 01:40:56 | 00,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/13 19:21:12 | 00,252,696 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxsrvc.exe
PRC - [2007/05/25 11:38:46 | 00,112,176 | ---- | M] (SingleClick Systems) -- C:\Program Files\Dell Network Assistant\hnm_svc.exe
PRC - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe


========== Modules (SafeList) ==========

MOD - [2009/11/19 12:54:47 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Everybody\Desktop\OTL.exe
MOD - [2009/10/08 12:14:02 | 00,451,856 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\TFEngine\TFWAH.dll
MOD - [2009/09/29 15:30:56 | 00,147,992 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\PCTGMhk.dll
MOD - [2009/09/09 21:54:58 | 00,155,184 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\smum32.dll
MOD - [2009/07/08 23:03:46 | 01,514,016 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nView.dll
MOD - [2008/07/25 11:17:20 | 00,635,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
MOD - [2008/05/02 01:42:50 | 00,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2008/04/13 19:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
MOD - [2008/04/13 19:11:53 | 00,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll


========== Win32 Services (SafeList) ==========

SRV - File not found -- -- (NVSvc)
SRV - [2009/10/23 11:38:31 | 00,194,032 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009/10/08 12:13:54 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2009/10/08 11:31:44 | 00,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2009/09/23 12:33:42 | 01,141,200 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdcoreservice)
SRV - [2009/09/23 11:17:22 | 00,358,600 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/09/21 15:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/09/10 13:54:02 | 00,269,648 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2009/08/28 18:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/08/28 08:21:59 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2009/02/25 19:03:34 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c997a5d3c64d1a)
SRV - [2008/12/27 19:25:25 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2008/12/19 10:40:23 | 00,202,352 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB)
SRV - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/22 01:25:46 | 00,094,208 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\IcdSptSv.exe -- (ICDSPTSV)
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state)
SRV - [2008/05/21 16:25:30 | 00,012,800 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -- (nmraapache)
SRV - [2008/05/16 05:11:44 | 00,648,504 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2008/05/02 01:42:06 | 00,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/04/13 19:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll -- (helpsvc)
SRV - [2008/03/21 08:09:01 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA)
SRV - [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc)
SRV - [2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc)
SRV - [2007/10/11 09:49:46 | 00,076,016 | ---- | M] () -- C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe -- (DellAMBrokerService)
SRV - [2007/05/25 11:38:46 | 00,112,176 | ---- | M] (SingleClick Systems) -- C:\Program Files\Dell Network Assistant\hnm_svc.exe -- (hnmsvc)
SRV - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2006/09/14 14:54:34 | 00,073,728 | ---- | M] (MicroVision Development, Inc.) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe -- (stllssvr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 80 E4 85 46 CC AA C9 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG8\Toolbar\Firefox\[email protected] [2009/07/02 11:29:21 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/01 21:49:13 | 00,000,000 | ---D | M]

[2009/08/29 14:48:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Mozilla\Extensions
[2009/04/10 07:05:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Mozilla\Extensions\[email protected]
[2009/07/08 00:52:57 | 00,001,497 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\avg_igeared.xml

O1 HOSTS File: (351340 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 12068 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {438e3dc7-0e57-43dc-84a3-e9aadb631e6f} - No CLSID value found.
O2 - BHO: (Norton Safety Minder IE Plugin) - {4BBAEC75-CADD-4FFC-81A6-653233E73141} - C:\Program Files\Norton Online\AddOns\Norton Safety Minder\Engine\1.0.0.1078\IEplgin.dll File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\msn\Toolbar\3.0.0989.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Everybody\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -Mozilla\5.0_(Windows;_U;_Windows_NT_5.1;_en-US)_AppleWebKit\532.0_(KHTML,_like_Gecko)_Chrome\3.0.195.33_Safari\532.0 - File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.sy...eqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.71.230 68.87.73.246
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - c:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{350c08c9-ec98-11dc-a3b4-0012178f0794}\Shell - "" = AutoRun
O33 - MountPoints2\{350c08c9-ec98-11dc-a3b4-0012178f0794}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{98c6b044-f4f6-11dc-a3c9-0012178f0794}\Shell - "" = AutoRun
O33 - MountPoints2\{98c6b044-f4f6-11dc-a3c9-0012178f0794}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{98c6b045-f4f6-11dc-a3c9-0012178f0794}\Shell\AutoRun\command - "" = setupSNK.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/10 12:52:56 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (0)

========== Files/Folders - Created Within 14 Days ==========

[2009/11/19 12:54:45 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Everybody\Desktop\OTL.exe
[2009/11/18 12:19:08 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/11/12 15:27:10 | 00,059,664 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfSysMon.sys
[2009/11/12 15:27:10 | 00,051,984 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfFsMon.sys
[2009/11/12 15:27:10 | 00,033,552 | --S- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\TfNetMon.sys
[2009/11/12 15:23:51 | 00,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
[2009/11/12 15:23:50 | 01,636,304 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
[2009/11/12 15:23:50 | 00,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
[2009/11/11 09:03:00 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\AAntivirusUninstall
[2009/09/04 08:54:49 | 04,938,616 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.exe
[2009/08/30 21:04:58 | 14,675,947 | ---- | C] (Michal Marcinkowski ) -- C:\Program Files\soldat15.exe

========== Files - Modified Within 14 Days ==========

[2009/11/19 12:54:47 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Everybody\Desktop\OTL.exe
[2009/11/19 12:35:01 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/11/19 12:26:11 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/11/19 12:24:01 | 00,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2947370361-1799852149-3768663099-1006UA.job
[2009/11/19 11:51:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/11/19 11:10:29 | 00,241,361 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2009/11/19 11:10:22 | 00,000,386 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2009/11/19 11:08:31 | 00,000,446 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2009/11/19 11:08:26 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/11/19 11:06:10 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/19 11:05:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/19 11:05:52 | 21,455,66720 | -HS- | M] () -- C:\hiberfil.sys
[2009/11/19 01:49:20 | 19,922,944 | ---- | M] () -- C:\Documents and Settings\Everybody\ntuser.dat
[2009/11/19 01:49:20 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Everybody\ntuser.ini
[2009/11/18 21:42:08 | 00,002,207 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/11/18 21:24:02 | 00,000,942 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2947370361-1799852149-3768663099-1006Core.job
[2009/11/17 22:21:46 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/11/17 09:24:57 | 00,002,316 | ---- | M] () -- C:\Documents and Settings\Everybody\Desktop\Google Chrome.lnk
[2009/11/16 12:49:58 | 00,351,340 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/11/16 07:00:17 | 00,000,516 | ---- | M] () -- C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Everybody.job
[2009/11/15 23:29:37 | 00,025,396 | ---- | M] () -- C:\Documents and Settings\Everybody\Application Data\wklnhst.dat
[2009/11/15 13:23:20 | 00,000,038 | ---- | M] () -- C:\Documents and Settings\Everybody\jagex_runescape_preferences.dat
[2009/11/15 13:17:09 | 00,000,063 | ---- | M] () -- C:\Documents and Settings\Everybody\jagex_runescape_preferences2.dat
[2009/11/15 04:33:11 | 00,000,380 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2009/11/14 04:56:00 | 00,000,448 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2009/11/13 20:15:17 | 03,751,756 | -H-- | M] () -- C:\Documents and Settings\Everybody\Local Settings\Application Data\IconCache.db
[2009/11/12 15:49:04 | 00,000,000 | ---- | M] () -- C:\WINDOWS\vpd.properties
[2009/11/11 08:48:39 | 01,534,000 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 00,011,168 | -H-- | C] () -- C:\WINDOWS\System32\padetoba
[2009/11/12 15:23:51 | 01,152,470 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2009/11/12 15:23:51 | 00,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2009/11/12 15:23:51 | 00,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2009/11/12 15:23:51 | 00,000,880 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2009/11/12 15:23:51 | 00,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2009/11/12 15:19:30 | 00,000,516 | ---- | C] () -- C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Everybody.job
[2009/10/27 19:17:04 | 00,000,072 | ---- | C] () -- C:\WINDOWS\SCapPro.INI
[2009/09/02 20:30:41 | 00,161,792 | ---- | C] () -- C:\Program Files\6WeekAssignment(8_09).xls
[2009/08/31 20:43:52 | 00,024,267 | ---- | C] () -- C:\Program Files\EasyBalance3.rpl
[2009/08/31 20:40:26 | 00,000,385 | ---- | C] () -- C:\Program Files\stdout.txt
[2009/08/31 20:40:26 | 00,000,234 | ---- | C] () -- C:\Program Files\stderr.txt
[2009/08/31 20:39:34 | 00,024,267 | ---- | C] () -- C:\Program Files\EasyBalance.rpl
[2009/08/31 14:11:34 | 12,145,6239 | ---- | C] () -- C:\Program Files\PrintMusic2k8WinFull.zip
[2009/06/09 20:36:18 | 08,794,570 | ---- | C] () -- C:\Program Files\Toribash-3.8-beta2.zip
[2009/06/08 22:12:58 | 00,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2009/06/03 22:51:09 | 00,062,976 | ---- | C] () -- C:\WINDOWS\System32\drivers\ggocdeghnfva.sys
[2009/06/01 12:41:29 | 00,080,896 | ---- | C] () -- C:\Program Files\Read Me PrintMusic for Windows.rtf
[2009/04/30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/04/30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/04/30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/04/30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/03/04 22:59:18 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DVEdit.INI
[2009/03/04 22:44:02 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\mp3dec.dll
[2009/03/04 22:44:02 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\dsp_trc.dll
[2009/03/04 22:44:02 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\IcdSptSvps.dll
[2009/02/24 20:57:56 | 01,701,627 | ---- | C] () -- C:\Program Files\Toribash-Win32-0.6.rar
[2009/02/04 11:27:56 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/02/03 19:39:39 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\EagleNt.sys
[2009/01/25 13:20:06 | 00,000,066 | ---- | C] () -- C:\WINDOWS\SpeedGear.INI
[2008/12/29 11:06:05 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/12/18 14:37:07 | 00,138,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/12/11 03:04:26 | 00,000,129 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/10/25 11:13:08 | 03,497,130 | ---- | C] () -- C:\Program Files\Toribash 1.zip
[2008/10/07 08:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/08/19 07:52:59 | 00,049,030 | ---- | C] () -- C:\Program Files\a-minorthing4.MUS
[2008/08/15 22:10:27 | 00,045,984 | ---- | C] () -- C:\Program Files\Anotherthing.MUS
[2008/08/14 16:07:32 | 00,047,662 | ---- | C] () -- C:\Program Files\a-minorthing3.MUS
[2008/08/14 15:49:50 | 00,049,170 | ---- | C] () -- C:\Program Files\a-minorthing2.MUS
[2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/04/28 19:05:17 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/03/10 17:42:17 | 00,025,396 | ---- | C] () -- C:\Documents and Settings\Everybody\Application Data\wklnhst.dat
[2008/02/23 12:11:31 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2008/02/22 19:57:29 | 03,751,756 | -H-- | C] () -- C:\Documents and Settings\Everybody\Local Settings\Application Data\IconCache.db
[2008/02/22 19:57:29 | 00,057,384 | ---- | C] () -- C:\Documents and Settings\Everybody\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/02/22 19:57:29 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Everybody\Application Data\desktop.ini
[2008/02/19 09:26:17 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/19 09:22:59 | 00,000,859 | ---- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2008/02/19 09:21:41 | 00,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/02/19 09:19:34 | 00,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\aec.sys
[2008/02/19 09:01:32 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/02/19 09:00:26 | 00,001,124 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/02/17 19:45:59 | 00,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2007/11/23 11:57:10 | 00,000,132 | ---- | C] () -- C:\Documents and Settings\Everybody\Local Settings\Application Data\fusioncache.dat
[2007/11/21 15:41:26 | 00,047,104 | ---- | C] () -- C:\WINDOWS\System32\KMVIDC32.DLL
[2007/06/14 14:23:25 | 00,000,044 | ---- | C] () -- C:\WINDOWS\liveup.ini
[2007/06/03 14:17:43 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/06/03 13:52:36 | 00,000,067 | ---- | C] () -- C:\Documents and Settings\Everybody\Application Data\Setup.txt
[2007/06/02 19:47:14 | 00,011,913 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/05/22 19:14:58 | 00,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/04/08 19:34:01 | 00,001,074 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2007/03/27 02:55:48 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/03/02 17:02:11 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007/02/10 21:33:56 | 00,000,073 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/02/05 17:03:44 | 00,000,059 | ---- | C] () -- C:\WINDOWS\KA.INI
[2007/02/03 19:37:55 | 00,000,604 | ---- | C] () -- C:\WINDOWS\Thps3.INI
[2007/01/23 20:10:32 | 00,074,752 | ---- | C] () -- C:\WINDOWS\System32\jst.dll
[2007/01/23 20:10:32 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\PMLJNI.dll
[2007/01/23 20:08:21 | 00,000,783 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2007/01/23 20:08:12 | 00,192,512 | R--- | C] () -- C:\WINDOWS\System32\HPB1320V.DLL
[2007/01/23 20:06:38 | 00,012,124 | ---- | C] () -- C:\WINDOWS\hplj1320.ini
[2006/12/12 11:24:42 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/11/18 11:26:51 | 00,000,090 | ---- | C] () -- C:\WINDOWS\wa.INI
[2006/11/07 04:25:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/10/07 13:22:47 | 00,000,018 | ---- | C] () -- C:\WINDOWS\gfact.ini
[2006/10/03 16:25:08 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006/09/18 18:37:45 | 00,000,544 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006/09/16 23:36:50 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/09/12 20:52:07 | 00,000,037 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2006/06/29 14:58:52 | 00,030,808 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/06/29 14:53:56 | 00,026,489 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 00,029,779 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/04/18 15:39:28 | 00,026,040 | ---- | C] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/02/22 18:43:03 | 00,000,181 | ---- | C] () -- C:\WINDOWS\civ.ini
[2005/12/20 20:16:22 | 00,038,912 | ---- | C] () -- C:\Documents and Settings\Everybody\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/10/09 19:02:13 | 00,136,448 | ---- | C] () -- C:\WINDOWS\RMTOOLS.DLL
[2005/10/09 18:19:33 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/09/03 10:14:52 | 00,001,896 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2005/03/01 19:21:47 | 00,000,101 | ---- | C] () -- C:\WINDOWS\upst.ini
[2005/03/01 19:21:47 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2005/02/05 08:29:17 | 00,286,208 | ---- | C] () -- C:\WINDOWS\System32\CNCS232.DLL
[2004/12/27 23:20:39 | 00,000,074 | ---- | C] () -- C:\WINDOWS\MPLAYER.INI
[2004/09/23 12:54:25 | 00,000,488 | ---- | C] () -- C:\WINDOWS\Cmousecc.ini
[2004/09/23 12:32:42 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/09/22 18:04:22 | 00,000,042 | ---- | C] () -- C:\WINDOWS\FDMount.ini
[2004/09/14 06:10:47 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/08/10 13:12:05 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:41 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/10 12:51:28 | 00,001,115 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/10 12:51:26 | 00,000,254 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/07/31 05:17:12 | 00,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[1999/01/22 13:46:58 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1997/06/13 20:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[1980/01/01 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2009/10/27 19:08:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACASystems
[2008/02/23 12:47:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2008/12/25 00:07:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\America's Army Deploy Client
[2008/09/02 09:48:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Armagetron
[2009/07/02 11:29:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/03/28 08:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2009/02/04 11:32:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2008/02/23 12:49:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2009/04/11 15:05:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lue
[2008/02/23 12:48:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2008/12/16 17:32:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/01/26 16:28:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/08/05 19:08:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2008/09/21 15:38:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices
[2008/02/19 09:23:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2009/06/15 02:17:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2008/02/23 11:07:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spearit
[2009/04/30 12:03:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Stardock
[2008/02/19 09:24:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/11/19 12:48:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/10/17 11:20:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2009/05/20 17:00:48 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{5CB3B214-2971-41B4-93F5-3344A403F942}
[2009/09/25 14:35:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/13 18:06:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{EA77F737-0FEA-4800-BD99-D6AF1051C7A9}
[2008/03/20 11:23:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\.BitTornado
[2009/10/27 19:08:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\ACASystems
[2009/03/04 20:27:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\acccore
[2008/04/03 20:07:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Aim
[2009/04/12 15:29:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Ambient Design
[2008/09/03 11:04:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Armagetron
[2009/05/13 20:04:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\AVGTOOLBAR
[2008/02/29 14:15:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\bang
[2009/03/27 22:23:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\BitDefender
[2009/10/19 19:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\BitTorrent
[2009/05/12 21:52:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Blitware
[2008/06/12 16:46:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Cakewalk
[2009/02/04 11:33:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\DAEMON Tools
[2009/10/20 09:21:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\DAEMON Tools Lite
[2009/02/04 11:33:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\DAEMON Tools Pro
[2009/10/15 19:08:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Damdai
[2009/04/10 07:05:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Days of Wonder, Inc
[2009/11/19 13:00:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\DNA
[2008/02/23 13:42:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\FileOpen
[2008/05/07 17:28:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Flickr
[2009/06/15 13:19:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\FrostWire
[2009/07/24 07:56:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\GarageGames
[2009/05/12 21:39:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\GetRightToGo
[2008/02/23 13:42:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\GlobalSCAPE
[2009/10/23 14:21:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\gtk-2.0
[2008/12/25 09:53:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\iWin
[2008/02/23 13:42:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Jasc
[2008/02/24 14:48:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Kensington
[2009/04/01 14:46:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Leadertech
[2008/02/23 13:42:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\LimeWire
[2008/02/23 13:42:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\LucasArts
[2009/11/11 23:21:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\NoNameScript
[2008/02/23 13:43:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\pdf995
[2009/08/05 18:28:24 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Everybody\Application Data\SecuROM
[2008/02/23 13:43:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Sierra
[2008/02/23 13:43:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Simple Star
[2008/02/23 13:43:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Soldat
[2009/11/12 15:49:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Sony
[2008/02/23 11:07:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Spearit
[2008/10/17 20:09:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\SporeCreatureCreator
[2009/04/29 22:53:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Stardock
[2008/03/10 17:42:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\Template
[2009/06/08 23:32:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\TrojanHunter
[2008/05/23 23:07:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\ubi.com
[2008/07/27 13:01:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Everybody\Application Data\uTorrent
[2004/08/04 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/11/14 04:56:00 | 00,000,448 | ---- | M] () -- C:\WINDOWS\Tasks\Driver Robot.job
[2009/11/19 11:08:31 | 00,000,446 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/11/19 11:10:22 | 00,000,386 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Startup.job
[2009/11/15 04:33:11 | 00,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2009/11/19 11:06:10 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/11/18 16:35:05 | 00,032,536 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2006/10/24 16:33:24 | 00,010,920 | ---- | M] () -- C:\aolconnfix.exe
[2005/10/31 10:56:00 | 00,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
[2007/05/30 21:16:52 | 11,661,343 | ---- | M] (Nabi Studios Pte Ltd ) -- C:\Toribash-Setup.exe

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004/08/04 05:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\i386\eventlog.dll
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2004/08/04 05:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004/08/04 05:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\i386\scecli.dll
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2004/08/04 05:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004/08/04 05:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\i386\netlogon.dll
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2004/08/04 05:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
[2007/06/13 19:25:14 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\drivers\storage\R158515\iastor.sys
[2007/06/13 19:25:14 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\i386\iastor.sys
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2007/06/13 19:25:14 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\system32\drivers\iastor.sys

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2006/08/28 02:02:10 | 00,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\i386\atapi.sys
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2006/08/27 21:02:10 | 00,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2006/08/27 21:02:10 | 00,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006/08/27 21:02:10 | 00,095,872 | ---- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2004/08/03 23:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[3 C:\i386\*.tmp files -> C:\i386\*.tmp -> ]
[2004/08/03 23:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >

========== Alternate Data Streams ==========

@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 209 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:260575F1
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA5F15C4
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >



OTL Extra log

OTL Extras logfile created on: 11/19/2009 12:56:27 PM - Run 1
OTL by OldTimer - Version 3.1.6.0 Folder = C:\Documents and Settings\Everybody\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.07 Gb Available Physical Memory | 53.61% Memory free
3.84 Gb Paging File | 2.85 Gb Available in Paging File | 74.03% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 7.92 Gb Free Space | 10.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LIVINGROOM
Current User Name: Everybody
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [UsagePieChart] -- "C:\Program Files\showman522\ShowMan.exe" "%1" (SatSignal Software, Edinburgh)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 
"FirewallDisableNotify" = 
"AntiVirusOverride" = 
"FirewallOverride" = 
"AntiVirusDisableNotify" = 
"UpdatesDisableNotify" = 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"58137:TCP" = 58137:TCP:*:Enabled:Pando Media Booster
"58137:UDP" = 58137:UDP:*:Enabled:Pando Media Booster
"11123:TCP" = 11123:TCP:*:Enabled:bit
"48593:TCP" = 48593:TCP:*:Enabled:bit1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- (Microsoft Corporation)
"C:\Program Files\Combat Arms\CombatArms.exe" = C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- File not found
"C:\Program Files\Combat Arms\Engine.exe" = C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe -- File not found
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant -- (SingleClick Systems)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- (Microsoft Corporation)
"C:\Program Files\Combat Arms\CombatArms.exe" = C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- File not found
"C:\Program Files\Combat Arms\Engine.exe" = C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe -- File not found
"C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe:*:Enabled:McAfee Data Backup -- File not found
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant Messenger -- (America Online, Inc.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Disabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Disabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Steam\steamapps\patbillydave\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\patbillydave\team fortress 2\hl2.exe:*:Enabled:hl2 -- ()
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Disabled:Nexon Game Manager -- (Nexon)
"C:\Documents and Settings\Everybody\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Everybody\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Disabled:Octoshape add-in for Adobe Flash Player -- (Octoshape ApS)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Documents and Settings\Everybody\Local Settings\Apps\2.0\LP0DNRN5.QYD\BG89LYMV.E7V\2dff..tion_fcdf29b345c9098a_0001.0000_89b83da73a004bb4\2DF FreePlay Client.exe" = C:\Documents and Settings\Everybody\Local Settings\Apps\2.0\LP0DNRN5.QYD\BG89LYMV.E7V\2dff..tion_fcdf29b345c9098a_0001.0000_89b83da73a004bb4\2DF FreePlay Client.exe:*:Enabled:2DF FreePlay Client -- (Damdai)
"C:\Documents and Settings\Everybody\Application Data\Damdai\2DF\FreePlay\freeplay_emu.exe" = C:\Documents and Settings\Everybody\Application Data\Damdai\2DF\FreePlay\freeplay_emu.exe:*:Enabled:2DF FreePlay Emulator -- (Damdai)
"C:\Program Files\Steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe" = C:\Program Files\Steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe:*:Enabled:Dawn of War: Dark Crusade -- (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\borderlands\Binaries\Borderlands.exe" = C:\Program Files\Steam\steamapps\common\borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands -- (Take-Two Interactive Software, Inc.)
"C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service -- (Pure Networks, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01686CA9-4D35-4E47-8972-62DA13636230}" = wnetlibs_x64fre
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{033422AD-6B52-41E8-91D4-54E8B80B1046}" = pnpportssample
"{038B21A5-68D9-4782-ABCD-660B4BEB0B40}" = toolindex
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{057D31FC-6271-469A-8E15-21D4B0B5755F}" = powermanagement_x86fre
"{063DB9D3-0D42-4F79-BF5D-1D763F45BA5B}" = wmisamples
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0DAD533A-83DB-48CE-A5F2-DF1D38F8B74C}" = bussamples
"{1723AD37-415A-4C0E-8B71-450D13D5C105}" = pfd_x86fre
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A342AEC-58F4-4037-9489-102433DCBC63}" = libs_ia64fre
"{1D74D07B-04D0-4831-93AD-9207020A18A4}" = hidsampleinput
"{1F5885BB-39F2-409C-85A0-64B0C7C38930}" = WDFCoinstaller
"{2165C62D-E7A3-4865-85F3-4B111981E40D}" = networklibraries_x86fre
"{23AD72A1-9852-4EFD-AD0A-A8099126E723}" = generaltools_x86fre
"{2624186E-5EEF-4C4D-A347-AF18DDB4ABB9}" = setuptools_x86fre
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26BADB95-D4AC-4D89-AC22-2B42D0D9A2B3}" = avstreamtools_ia64fre
"{27B4FCA3-E8D1-4104-B0E4-DCC3BCE4D482}" = networklibraries_x64fre
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{2883E3C1-9631-4272-BBCD-50A1CB4AA7DD}" = bluetoothsamples
"{2918D1A5-2310-41FA-8BA5-CF1281057ADE}" = chkinftool_x86fre
"{2C8C7917-7858-404B-A3AF-1F987D330FC9}" = wpdtools_ia64fre
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{2F7A1BD9-3417-4C2B-B9BD-7EDBA396928B}" = tracingtool_ia64fre
"{300A2961-B2B5-4889-9CB9-5C2A570D08AD}" = Debugging Tools for Windows (x86)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3373979A-467D-4379-9388-A96285952C35}" = debugfiles_ia64chk
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{35DD84A7-A025-4A14-9F00-1C6FD35964FE}" = fireflysample
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36D6A0E9-2183-4E68-B119-53AFB58C720F}" = avstreamtools_x86fre
"{38571A40-8C98-4259-8A6D-72D6DD4B8A4D}" = vistalibs_x64fre
"{39230AAE-B0D1-471C-80C4-88513D10EEEB}" = eventsample
"{3EC7B1B2-FCC7-49A2-A26D-689967381BD8}" = installhelp
"{3F9BCCF8-381B-468D-8F68-A8349DA84DDF}" = pnptools_x64fre
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4335C58D-1C3D-4763-AD53-CAAB2B12FFAC}" = wdftools_ia64fre
"{43D8FFB0-D770-40CE-B1A8-9815E60A55E5}" = wpdtools_x86fre
"{44B978F7-85C6-4FA0-9F78-47A2927CC68E}" = streammediasamples
"{44B996C5-43E5-42D4-A908-AF561D752860}" = generaltools_ia64fre
"{46AA557A-5FD6-4E7C-814D-EB9B631957A0}" = biometrictools_x64fre
"{46DBB2AC-755B-4C9E-BD1D-A626335A54AA}" = wdtfbinaries_x86fre
"{47D386FF-5ECC-4C9F-AD45-87108CF4E315}" = sensorsamples
"{49DAB8D1-8B62-4B16-914A-BC3FE1E54578}" = printtools_x86fre
"{49E10896-178F-4873-99CA-CBF8D5A36912}" = WinUSBCoinstaller
"{4A556772-F346-4635-A431-A926D4CD9857}" = toastersample
"{4A688B59-2DC3-44CE-ADC7-35F21228C815}" = offreg_ia64fre
"{4B89EF08-D841-435A-B8F1-65C35B0B5AF6}" = imagingtools_x64fre
"{4C61F890-A12B-43EF-9601-5D650398B2D0}" = wsdtool_x86fre
"{50722478-ECEA-478E-954F-406AE79BAB4D}" = bluetoothtools_ia64fre
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{518B31F6-32E9-44AD-B9CC-CF50B61882B5}" = ioctlsample
"{55A75679-02D1-4C8C-85CA-B4E4DF4D775F}" = MSM32Installer
"{569E65CF-852D-4ED5-9E58-FDDC2CCABB93}" = buildsamples
"{570D7957-E9D2-4FA5-8528-4D41AAE7E63B}" = evntdrvsample
"{578B6EF9-119B-4FB8-8377-7DAFA9588B97}" = Network Magic
"{57BF6A29-CE9A-4F78-BDE9-6D5035C6E0A9}" = pcidrvsample
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}" = PrintScreen
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5A31A1E5-2783-4323-A309-3E69E1F907DE}" = networksamples
"{5A71AC0E-4A93-4035-B569-05B3819FC67B}" = ifssamples
"{5B2029A4-1854-42BC-96B6-4ACE5F5414BD}" = ArtRage 2 Starter Edition
"{5C035DB3-707C-4AE3-8905-1243722F08E3}" = audiosamples
"{5C96C03F-55B3-4E46-BAA0-C7902B6FB85A}" = biometricsamples
"{5D1DCDB1-07D6-4364-8979-5FE22D367746}" = sideshowsamples
"{5D761A68-29B2-41F8-B7CD-2513E814A707}" = networklibraries_ia64fre
"{5E51812E-A6D0-409E-B1EA-B1FD43C80555}" = pnptools_ia64fre
"{6121961F-E3DB-4FDE-8171-ADB3ECC193EE}" = modemtools
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{627E1741-C496-4F5A-966C-44D36813537F}" = wpdsamples
"{649427F9-A3FC-4FEA-A02D-911C9CE19D25}" = printtools_ia64fre
"{665FD1F5-429D-461A-B907-7D93640C8223}" = debugfiles_x86chk
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{685E23B5-2DF0-4EE5-BABA-2069DE538A82}" = wdtfbinaries_ia64fre
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69F2A489-9E90-4496-8A4D-8FEB92EF171A}" = buildtools_x86fre
"{6B60AD21-45E0-4313-9AFC-9B3CC8E55703}" = dfx_x64fre
"{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}" = Digital Voice Editor 3
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74475003-8910-4823-87ED-F094353B1005}" = wsdtool_x64fre
"{7611774D-8260-406F-ACD6-0A99A1651394}" = avstreamtools_x64fre
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.8.0
"{77C2838B-7D80-4D62-A803-FECDD1E5B6F5}" = setuptools_ia64fre
"{7A8407A6-FF2C-4F11-A1B6-A8A8D565D49C}" = bluetoothtools_x64fre
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C7D6EC8-F8CC-4B13-AF27-0A9D51EE4E40}" = MSN Toolbar
"{7E7197A1-12F9-4F6E-AB04-360CDA028129}" = wnetlibs_x86fre
"{7F04B272-E0DD-47E7-8B55-D97483DB0EBD}" = hp LaserJet 1160/1320 series
"{7F3D9BFE-C111-4C0C-A48A-FC1994A7CF65}" = avstreamsamples
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{82FE48EE-EE92-47DD-A091-09859AFDB9F4}" = setuptools_x64fre
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{8591B657-7E88-4F6B-8692-D1D349B41007}" = hidsamples
"{86260670-8D83-4D8B-9700-F8FFBE543CDE}" = dfx_ia64fre
"{8677F519-3C05-4B00-B044-7B2C2C85A0E7}" = wnetlibs_ia64fre
"{869C97B1-F0D7-4BAD-A9EA-D3570E263BBB}" = debugfiles_x64chk
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B054713-F95E-4796-AAD9-8E7C722BBB01}" = drvtools_x64fre
"{8D1806B4-3C72-4A78-B996-8E289C14E442}" = tracingtool_x64fre
"{8F29AC41-2F2F-44DB-B0CF-019A3FB46AC5}" = generalsamples
"{8FCCB620-0DA6-4934-BC31-DFAF2120E05D}" = sdv
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90DDD531-211B-4AD3-8FD9-5232560DA43A}" = DSF-KitSetup
"{91E5AEF7-0900-4F39-90FF-BE851678F4B6}" = umdfsamples
"{922B99C1-31B9-4F1D-88A2-9A85BC46639B}" = storagesamples
"{929A6BDE-CD62-4675-A21E-E5445510BBD7}" = smartcardsamples
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{977CA34F-C283-4D05-8542-AC662725CCBB}" = dsfsamples
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A053D29-6342-4C1B-A672-CBB050330A43}" = pnptools_x86fre
"{9A1F531D-2D99-4AC5-B3C0-4A170FB29BB4}" = printsamples
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A8BFFDA-8D1A-4EFE-B094-A91DA1800BF4}" = wdftools_x64fre
"{9BE2669E-2BD8-4164-A8B5-C904C864B403}" = WA Update v3.50 beta2
"{9EBDAF91-DADA-47CE-94F2-F5B004007934}" = System Requirements Lab
"{A010731F-1C97-46AC-90F6-ED4317E07B3B}" = wsdtool_ia64fre
"{A0F35F58-92D6-45B1-BDDC-F040164649C3}" = offreg_x86fre
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A371D068-447D-4F55-A76E-F8CDA3106F9D}" = infsample_x64fre
"{A3DCA1EE-26CC-4A75-8EB1-8E1ED29B43D8}" = drvtools_ia64fre
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A59173CF-4088-4B8B-86F7-D3C41BFB6174}" = readme
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A952B5BC-7E21-4887-BDDB-1DD7CA4A3E32}" = irsamples
"{A9FBCEFE-BE08-414F-94E9-73EAA250A408}" = dfx_x86fre
"{AA84CF9E-C9F3-44F9-AA0E-A4D11094493C}" = imagingtools_x86fre
"{AAA7840C-46D6-4A8E-A038-BA9C71F09276}" = drvtools_x86fre
"{AAAC51A0-F5E6-4CFA-9B95-ECC7356179F7}" = imagingtools_ia64fre
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AFBB6CE4-511B-429D-B17D-B4769B7DEACF}" = wdftools_x86fre
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3661910-E16E-4181-9796-C1D0067E25C9}" = libs_x86fre
"{B3DDFD4D-4407-4026-AE4B-44751BB64916}" = vistalibs_x86fre
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6304C7F-D163-413E-8885-AF1B9FB98B15}" = vistalibs_ia64fre
"{B6EEF368-30EC-4933-8125-CF43BD9761EE}" = powermanagement_x64fre
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BBCA1D1E-B174-4893-ADE9-D4260EE4F82F}" = buildtools_ia64fre
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{BF9B074D-2996-4AF2-9EF9-A97A08C5FFC6}" = powermanagement_ia64fre
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C315B497-5951-4C61-899A-719E5EFB17F2}" = pfd_x64fre
"{C47C0038-F848-457A-A39E-13973CB00697}" = hid_inputsamples
"{C672FC53-2E63-4710-BED0-EA284C82A5A8}" = wdtfbinaries_x64fre
"{C7966AB3-A8D9-48D5-B7DF-922674C40098}" = Device Simulation Framework 1.0.1
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform
"{CAF58314-999E-4AF7-9C9D-A7E56441EBBA}" = tools_ia64fre
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CD60D3A3-D92B-4D1C-BB99-47F2A5888C5C}" = biometrictools_x86fre
"{CE235A83-9029-46B3-8D69-C42A5FE8CEDE}" = swtuner
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB6CF1B-8284-431B-9154-56FB8C169A4C}" = tools_x86fre
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{CFB21146-6EE0-4266-8B21-8DE44B20A653}" = oacr_x86fre
"{D3259FB5-2AC3-441C-8436-B2D4C528945C}" = portiosample
"{D54049D3-256C-4E19-AAE9-861F6B00BF29}" = AGEIA GAME System Software
"{D5985823-1BF6-450C-BCE4-06A4DA9ADBCD}" = tracingtool_x86fre
"{D59B41FE-EB48-4DA3-8FBF-2B96C1B1A07D}" = generaltools_x64fre
"{D7FACF67-9DA7-4956-8C3D-D795E9A14435}" = displaysamples
"{D845AAE3-D117-44A9-9D56-A5F44668CBEB}" = bluetoothtools_x86fre
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DA66418B-7675-430B-8A64-EC1EEB8263B9}" = libs_x64fre
"{DA70AAFD-4284-461B-964E-03EC47CDF46F}" = offreg_x64fre
"{DD64D531-DA4A-4E4A-AB7D-AFA6B10BC16F}" = infsample_x86fre
"{E1E2F769-EE57-4EC0-8A46-72A02E07B3FC}" = toastermetadatapackagesample
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E8118290-F0C6-4A50-9F7F-9AEE0BA75F95}" = setupsamples
"{E8DA3989-2D46-4579-9921-C71B98141DA4}" = pfd_ia64fre
"{E9CCAC74-0F67-43E7-8AF9-271FA24DBADD}" = usbsamples
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EAD221A4-2D08-43B7-AF6D-4BF47346FA13}" = wxplibs_x86fre
"{EB67012E-DDC4-4EF1-A2B4-FEE83AEC0718}" = infsample_ia64fre
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F3C25FC4-C627-433E-833C-00ABF09F29B2}" = tools_x64fre
"{F539FAA1-2930-4DFA-BD11-22D33FD5B262}" = wpdtools_x64fre
"{FB38811C-F4D5-4321-9359-9476799D6192}" = cancelsample
"{FB84F20C-F804-455A-8E91-E4AE288C30C7}" = buildtools_x64fre
"{FDAF0D3F-770D-4686-8EAE-491A3E2571B6}" = printtools_x64fre
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"{FF74F06A-2AB5-422F-B354-6525AC657904}" = headers
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM Ad Hack_is1" = AIM Ad Hack
"AOL Instant Messenger" = AOL Instant Messenger
"AVG8Uninstall" = AVG Free 8.5
"Belarc Advisor" = Belarc Advisor 8.1
"BFGC" = Big Fish Games Client
"Browser Defender_is1" = Browser Defender 2.0.6.10
"CDisplay_is1" = CDisplay 1.8
"C-evo" = C-evo
"DivX Content Uploader" = DivX Content Uploader
"ERUNT_is1" = ERUNT 1.1j
"Finale PrintMusic 2008" = Finale PrintMusic 2008
"FL Studio 5" = FL Studio 5
"GamersFirst LIVE!" = GamersFirst LIVE!
"GeoWarfare" = GeoWarfare
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"IAPlayer" = InstantAction.com Plug-Ins
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Impulse" = Impulse
"jv16 PowerTools 2009_is1" = jv16 PowerTools 2009
"KitSetup Registration {B4285279-1846-49B4-B8FD-B9EAF0FF17DA}:{676E6B70-5659-5459-5B5F-6063635E5F61}" = Microsoft Windows Driver Kit 7.0.0.7600
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"mIRC" = mIRC
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNHandWriting" = MSN HandWriting (Messenger Plus! Plugins)
"MU Online Toolbar" = MU Online Toolbar
"Network MagicUninstall" = Network Magic
"NewLive All To WMA Converter_is1" = NewLive All To WMA Converter 1.0
"NFR" = Nasty File Remover v0.71 (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Out Of The World_is1" = Out Of The World v.2.0
"Precision" = EVGA Precision 1.3.1
"RegCure" = RegCure 2.0.0.0
"Registry Mechanic_is1" = Registry Mechanic 5.0
"SearchAssist" = SearchAssist
"Shockwave" = Shockwave
"Sins of a Solar Empirev1.15" = Sins of a Solar Empire
"Soldat patch 1.3.1-1.4_is1" = Soldat 1.4.0
"Soldat_is1" = Soldat 1.5.0
"Spyware Doctor" = Spyware Doctor 7.0
"Steam App 440" = Team Fortress 2
"Steam App 4580" = Dawn of War: Dark Crusade
"SystemRequirementsLab" = System Requirements Lab
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WETCable" = Windows Easy Transfer
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.6
"WinGTK-2_is1" = GTK+ 2.10.6-1 runtime environment
"WinRAR archiver" = WinRAR archiver
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Zoombinis Island Odyssey" = Zoombinis Island Odyssey

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"AAntivirus" = Alpha Antivirus
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"NoNameScript" = NNScript
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/24/2009 8:35:39 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 8:35:40 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 8:36:05 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 8:36:06 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 8:36:07 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 8:36:07 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application nmapp.exe, version 4.5.7228.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/24/2009 2:38:23 PM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application tb.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/25/2009 3:43:47 PM | Computer Name = LIVINGROOM | Source = Application Error | ID = 1000
Description = Faulting application itunes.exe, version 9.0.1.8, faulting module
quicktimestreaming.qtx, version 7.64.17.73, fault address 0x000906c1.

Error - 9/26/2009 10:22:21 AM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application WksWP.exe, version 8.5.818.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/26/2009 2:25:36 PM | Computer Name = LIVINGROOM | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The MBAMService service terminated unexpectedly. It has done this
1 time(s).

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The Browser Defender Update Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The PC Tools Auxiliary Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The Pure Networks Platform Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 11/18/2009 10:29:14 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The Advanced Networking Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 11/18/2009 10:31:01 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 11/18/2009 10:36:27 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Display Driver Service service failed to start due to the
following error: %%3

Error - 11/19/2009 12:07:27 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Display Driver Service service failed to start due to the
following error: %%3


< End of report >



PC Tools Spyware Doctor (the paid-for version)

No infections or threats detected.



Mbam log

Malwarebytes' Anti-Malware 1.41
Database version: 3192
Windows 5.1.2600 Service Pack 3

11/18/2009 12:30:47 PM
mbam-log-2009-11-18 (12-30-47).txt

Scan type: Quick Scan
Objects scanned: 126361
Time elapsed: 8 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



RootRepeal log

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/19 12:52
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB47F3000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xB85E6000 Size: 8192 File Visible: No Signed: -
Status: -

Name: PCI_PNP7022
Image Path: \Driver\PCI_PNP7022
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x953C7000 Size: 49152 File Visible: No Signed: -
Status: -

Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: spzv.sys
Image Path: spzv.sys
Address: 0xB7DF7000 Size: 1052672 File Visible: No Signed: -
Status: -

SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "TfSysMon.sys" at address 0xb7c17a1c

#: 047 Function Name: NtCreateProcess
Status: Hooked by "PCTCore.sys" at address 0xb7c42cdc

#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "PCTCore.sys" at address 0xb7c42ece

#: 063 Function Name: NtDeleteKey
Status: Hooked by "TfSysMon.sys" at address 0xb7c17c10

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "TfSysMon.sys" at address 0xb7c17cb6

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spzv.sys" at address 0xb7e16ca4

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spzv.sys" at address 0xb7e17032

#: 119 Function Name: NtOpenKey
Status: Hooked by "TfSysMon.sys" at address 0xb7c1790c

#: 160 Function Name: NtQueryKey
Status: Hooked by "spzv.sys" at address 0xb7e1710a

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spzv.sys" at address 0xb7e16f8a

#: 192 Function Name: NtRenameKey
Status: Hooked by "PCTCore.sys" at address 0xb7c62d30

#: 247 Function Name: NtSetValueKey
Status: Hooked by "TfSysMon.sys" at address 0xb7c17e52

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "TfSysMon.sys" at address 0xb7c19b30

==EOF==

Edited by orranis19, 19 November 2009 - 01:04 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP