First, thank you all enormously for so kindly and generously volunteering your time and expertise to provide your amazing service to the community. You are truly wonderful and caring people, unsung heroes of the Internet. I--and countless others--am so deeply grateful to you for your vital assistance!
Yesterday my Windows XP laptop was attacked by the truly vicious Defense Center malware. A combination of Malwarebytes and Microsoft Security Essentials has seemed to beat the infestation into submission.
But I still have the lingering problem--seemingly similar to that reported in other postings--of finding my Google search results redirected through a Web site called traffic-essentials.com to random ad-based search sites.
I have no idea how to remove this problem, and so I appeal to you all for a moment of your time and your wisdom. I followed your Malware and Spyware Cleaning Guide, and I have posted the results of its various diagnostics below for your inspection. I also ran GooredFix and TDSSKiller, to no avail.
Possibly of interest, the computer also became insanely slow as it was running GMER, and my Microsoft Security Essentials seemed to have disabled itself when I restarted.
Thank you so enormously, and I am very much looking forward to getting this issue resolved!
With all my deepest appreciation for you, and all my very best wishes,
NeoLux
MBAM:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4192
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6/13/2010 2:46:20 AM
mbam-log-2010-06-13 (02-46-20).txt
Scan type: Quick scan
Objects scanned: 137877
Time elapsed: 12 minute(s), 32 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-13 15:39:02
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JEREMY~1\LOCALS~1\Temp\pxtdapow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAF2D0620]
---- Kernel code sections - GMER 1.0.15 ----
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xB988A900]
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}@LeaseObtainedTime 1276425482
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}@T1 1276468682
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}@T2 1276501082
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}@LeaseTerminatesTime 1276511882
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}@DhcpRetryTime 43197
Reg HKLM\SYSTEM\CurrentControlSet\Services\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}\Parameters\Tcpip@LeaseObtainedTime 1276425482
Reg HKLM\SYSTEM\CurrentControlSet\Services\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}\Parameters\Tcpip@T1 1276468682
Reg HKLM\SYSTEM\CurrentControlSet\Services\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}\Parameters\Tcpip@T2 1276501082
Reg HKLM\SYSTEM\CurrentControlSet\Services\{D5ADD9FF-F202-4ED5-A28C-94C13E1933C6}\Parameters\Tcpip@LeaseTerminatesTime 1276511882
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\JeremyNew\Local Settings\Temporary Internet Files\Content.IE5\DOBLRDV1\ping_tssm[1].htm 5 bytes
---- EOF - GMER 1.0.15 ----
OTL:
OTL logfile created on: 6/13/2010 4:15:20 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\JeremyNew\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 40.89 Gb Free Space | 36.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: -
Current User Name: JeremyNew
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/06/13 02:28:40 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTL.exe
PRC - [2010/06/07 10:13:53 | 002,403,568 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2010/02/21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/12/09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/09/29 09:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/07/20 11:51:52 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/08/19 18:14:28 | 000,135,168 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\Toshiba\Power Management\CePMTray.exe
PRC - [2004/07/13 21:51:04 | 000,892,928 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2004/07/07 15:16:24 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2004/06/23 05:07:58 | 000,036,960 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
PRC - [2004/06/16 16:44:06 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2004/06/14 05:00:08 | 000,638,976 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\Toshiba\E-KEY\CeEKey.exe
PRC - [2004/05/14 10:29:50 | 000,712,704 | ---- | M] (Dritek System Inc.) -- C:\Program Files\EzButton\EzButton.EXE
PRC - [2004/05/13 14:46:02 | 000,053,248 | ---- | M] () -- c:\Toshiba\Ivp\Swupdate\swupdtmr.exe
PRC - [2004/03/14 20:17:54 | 000,053,248 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\Toshiba\TouchPad\TPTray.exe
PRC - [2004/02/03 14:47:06 | 001,089,589 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\Touch and Launch\PadExe.exe
PRC - [2003/10/20 09:39:26 | 000,159,744 | ---- | M] (TOSHIBA Corporation) -- C:\Toshiba\Ivp\ISM\pinger.exe
PRC - [2003/09/05 03:24:46 | 000,065,536 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2003/05/23 13:38:26 | 000,106,496 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe
PRC - [2003/03/14 11:38:12 | 000,155,648 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\RAMASST.exe
PRC - [2001/12/13 00:01:00 | 000,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\BRSS01A.EXE
PRC - [2001/11/23 00:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\BRSVC01A.EXE
========== Modules (SafeList) ==========
MOD - [2010/06/13 02:28:40 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTL.exe
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (Asynaeos)
SRV - [2009/12/09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/09/29 09:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2009/07/20 11:51:52 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008/10/05 01:48:37 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2004/07/07 15:16:24 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2004/06/23 05:07:58 | 000,036,960 | ---- | M] (COMPAL ELECTRONIC INC.) [Auto | Running] -- C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe -- (CeEPwrSvc)
SRV - [2004/06/16 16:44:06 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2004/05/13 14:46:02 | 000,053,248 | ---- | M] () [Auto | Running] -- c:\Toshiba\Ivp\Swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2003/05/23 13:38:26 | 000,106,496 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
SRV - [2003/04/01 23:08:30 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\IcdSptSv.exe -- (ICDSPTSV)
SRV - [2001/11/23 00:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) [Auto | Running] -- C:\WINDOWS\system32\BRSVC01A.EXE -- (Brother XP spl Service)
========== Driver Services (SafeList) ==========
DRV - [2010/06/11 20:39:03 | 000,054,016 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\afyd.sys -- (glcao)
DRV - [2010/05/10 11:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/12/02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2009/06/03 23:05:00 | 001,570,240 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2009/05/07 20:57:48 | 001,351,104 | ---- | M] (TamoSoft) [CommView] Atheros AR5008 Wireless Network Adapter Service [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ts_athw.sys -- (TS_AR5416)
DRV - [2008/01/21 13:58:46 | 000,558,624 | ---- | M] (TamoSoft) [CommView] Atheros Wireless Network Adapter Service [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007/03/07 16:51:00 | 000,009,464 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2007/03/07 16:51:00 | 000,009,336 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cdr4_xp.sys -- (Cdr4_xp)
DRV - [2005/09/23 23:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2004/09/02 15:51:08 | 000,004,224 | ---- | M] (Compal Electronic Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hkdrv.sys -- (EPOWER)
DRV - [2004/08/19 14:03:08 | 000,005,248 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ECioctl.sys -- (SrvcEPECioctl)
DRV - [2004/08/10 13:55:11 | 000,015,890 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2004/08/03 15:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/30 15:05:08 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSIOMngr.sys -- (SrvcSSIOMngr)
DRV - [2004/07/30 15:05:06 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TPIOMngr.sys -- (SrvcTPIOMngr)
DRV - [2004/07/30 15:05:04 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EPIOMngr.sys -- (SrvcEPIOMngr)
DRV - [2004/07/30 15:05:04 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EKIOMngr.sys -- (SrvcEKIOMngr)
DRV - [2004/07/12 13:48:08 | 000,036,480 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESD7SK.sys -- (ESDCR)
DRV - [2004/07/12 13:48:02 | 000,330,624 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESM7SK.sys -- (ESMCR)
DRV - [2004/06/25 10:37:22 | 000,058,240 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\EMS7SK.sys -- (EMSCR)
DRV - [2004/06/21 16:53:20 | 000,626,204 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/05/08 20:38:06 | 000,101,833 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/04/21 23:11:06 | 000,729,088 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/02/24 11:08:52 | 000,400,384 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2004/02/20 15:00:44 | 001,265,388 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/01/30 10:32:32 | 000,090,480 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2004/01/12 17:05:58 | 000,017,497 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2003/10/15 17:48:00 | 000,082,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2003/10/15 17:48:00 | 000,006,000 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2003/10/15 17:47:00 | 000,051,040 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2003/09/19 15:45:48 | 000,021,248 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2003/08/13 15:27:22 | 000,065,280 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnic51.sys -- (RTL8023)
DRV - [2003/06/11 08:53:22 | 000,006,867 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tbiosdrv.sys -- (TBiosDrv)
DRV - [2003/04/23 15:06:40 | 000,013,174 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atisgkaf.sys -- (caboagp)
DRV - [2003/01/29 14:35:00 | 000,012,032 | ---- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)
DRV - [2002/11/28 22:23:24 | 000,039,048 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IcdUsb2.sys -- (ICDUSB2) Sony IC Recorder (P)
DRV - [2001/08/17 05:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:1038
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 1038
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/22 15:31:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/12 01:22:32 | 000,000,000 | ---D | M]
[2010/04/19 22:34:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Mozilla\Extensions
[2010/06/12 19:10:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Mozilla\Firefox\Profiles\z8kam7zy.default\extensions
[2010/04/21 21:43:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\JeremyNew\Application Data\Mozilla\Firefox\Profiles\z8kam7zy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/12 19:10:13 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 01:22:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/06/10 06:15:38 | 000,000,765 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 84.16.244.58 www.google.com
O1 - Hosts: 84.16.244.58 us.search.yahoo.com
O1 - Hosts: 84.16.244.58 uk.search.yahoo.com
O1 - Hosts: 84.16.244.58 search.yahoo.com
O1 - Hosts: 84.16.244.58 www.google.com.br
O1 - Hosts: 84.16.244.58 www.google.it
O1 - Hosts: 84.16.244.58 www.google.es
O1 - Hosts: 84.16.244.58 www.google.co.jp
O1 - Hosts: 84.16.244.58 www.google.com.mx
O1 - Hosts: 84.16.244.58 www.google.ca
O1 - Hosts: 84.16.244.58 www.google.com.au
O1 - Hosts: 84.16.244.58 www.google.nl
O1 - Hosts: 84.16.244.58 www.google.co.za
O1 - Hosts: 84.16.244.58 www.google.be
O1 - Hosts: 84.16.244.58 www.google.gr
O1 - Hosts: 84.16.244.58 www.google.at
O1 - Hosts: 84.16.244.58 www.google.se
O1 - Hosts: 84.16.244.58 www.google.ch
O1 - Hosts: 84.16.244.58 www.google.pt
O1 - Hosts: 84.16.244.58 www.google.dk
O1 - Hosts: 84.16.244.58 www.google.fi
O1 - Hosts: 84.16.244.58 www.google.ie
O1 - Hosts: 84.16.244.58 www.google.no
O1 - Hosts: 84.16.244.58 www.google.de
O1 - Hosts: 84.16.244.58 www.google.fr
O1 - Hosts: 2 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\Toshiba\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\Toshiba\Power Management\CePMTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [PadTouch] C:\Program Files\Toshiba\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPNF] C:\Program Files\Toshiba\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/09 17:08:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1c331bb1-4a79-11d9-aa25-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{1c331bb1-4a79-11d9-aa25-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1c331bb1-4a79-11d9-aa25-806d6172696f}\Shell\AutoRun\command - "" = D:\INSTALL.EXE -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = comfile] -- Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/09 17:07:46 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mjpg - C:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 90 Days ==========
[2010/06/13 02:28:40 | 000,572,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTL.exe
[2010/06/12 15:35:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Desktop\GooredFix Backups
[2010/06/12 15:35:14 | 000,070,858 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\JeremyNew\Desktop\GooredFix.exe
[2010/06/12 03:21:30 | 000,998,736 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\JeremyNew\Desktop\123awesome.exe
[2010/06/12 03:19:01 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/06/12 03:16:20 | 000,518,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTM.exe
[2010/06/12 03:04:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\SUPERAntiSpyware.com
[2010/06/12 03:04:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/06/12 03:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/06/12 02:44:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010/06/12 01:54:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/06/12 01:45:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/06/12 01:44:00 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/06/12 01:23:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/12 00:23:56 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\TFC.exe
[2010/06/10 03:31:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/10 03:31:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/10 03:03:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\dpevcaity
[2010/06/10 03:02:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Update
[2010/05/27 23:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/05/18 19:06:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\My Documents\My Skype Content
[2010/05/07 14:01:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\Skype
[2010/05/07 14:01:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\My Documents\My Skype Pictures
[2010/05/07 14:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\Skype
[2010/04/22 14:11:09 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010/04/22 14:09:30 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/04/22 14:09:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/22 14:08:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/04/22 14:08:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Apple
[2010/04/22 14:08:15 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/04/22 14:08:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/22 00:23:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Desktop\fleXcroll_SampleStyles
[2010/04/21 17:34:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Pendulo Studios
[2010/04/21 05:53:03 | 000,000,000 | ---D | C] -- C:\Program Files\Pendulo Studios
[2010/04/20 00:58:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\My Documents\Downloads
[2010/04/19 23:41:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\My Documents\InstantCDDVD
[2010/04/19 23:41:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Pinnacle
[2010/04/19 22:33:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Mozilla
[2010/04/19 22:33:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\Mozilla
[2010/04/19 22:33:35 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/04/19 18:49:30 | 000,000,000 | ---D | C] -- C:\ATI
[2010/04/19 17:14:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\DivX
[2010/04/19 15:38:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\proDAD
[2010/04/19 15:38:04 | 000,000,000 | ---D | C] -- C:\Program Files\proDAD
[2010/04/19 15:37:45 | 000,049,152 | ---- | C] (Canopus Co., Ltd.) -- C:\WINDOWS\System32\CvoAPI.dll
[2010/04/19 15:36:46 | 000,000,000 | ---D | C] -- C:\Program Files\Boris FX, Inc
[2010/04/19 15:31:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2010/04/19 15:30:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Pinnacle
[2010/04/19 15:30:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\Downloaded Installations
[2010/04/19 15:30:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2010/04/19 15:28:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Yahoo!
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Studio 12
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Program Files\Pinnacle
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Pinnacle
[2010/04/19 15:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\My Projects
[2010/04/19 15:17:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/04/15 02:21:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Desktop\journey2_data
[2010/04/12 03:45:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/04/12 03:00:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Desktop\TurboTax 2009 Home & Business + eFile
[2010/04/04 22:03:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Desktop\iMST
[2010/04/04 18:48:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\IsolatedStorage
[2010/04/04 16:04:17 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010/04/04 16:03:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\Application Data\uTorrent
[2010/04/04 00:54:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\JeremyNew\My Documents\JIPHOTOS
[2010/03/31 21:48:21 | 000,000,000 | ---D | C] -- C:\Program Files\PHP
[2010/03/31 17:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Abitec
[2010/03/31 17:40:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2010/03/18 21:31:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\custom matrices
[2010/03/18 21:31:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\C2MP
[2010/03/18 21:02:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2010/03/18 21:02:14 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2010/03/18 20:53:32 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2004/08/19 14:00:02 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\ECioctl.dll
========== Files - Modified Within 90 Days ==========
[2010/06/13 16:13:49 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/13 15:49:05 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/06/13 15:49:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/06/13 02:28:40 | 000,572,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTL.exe
[2010/06/12 17:32:00 | 000,243,474 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_04a_10.02.15_HOW_TO_REHEARSE.pdf
[2010/06/12 17:29:27 | 009,323,248 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_02_15_SECOND_PRINCIPLE.pdf
[2010/06/12 16:13:18 | 009,437,184 | ---- | M] () -- C:\Documents and Settings\JeremyNew\NTUSER.DAT
[2010/06/12 16:13:18 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\JeremyNew\ntuser.ini
[2010/06/12 15:35:18 | 000,070,858 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\JeremyNew\Desktop\GooredFix.exe
[2010/06/12 14:49:41 | 000,259,048 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 04:21:48 | 000,000,649 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/12 04:20:10 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/12 04:06:33 | 000,508,318 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/12 04:06:33 | 000,445,938 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/12 04:06:33 | 000,072,978 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/12 03:42:00 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/06/12 03:16:20 | 000,518,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\OTM.exe
[2010/06/12 03:15:10 | 000,000,103 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\fix.reg
[2010/06/12 03:03:01 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/12 02:49:53 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/06/12 02:49:53 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/06/12 02:06:53 | 000,000,073 | ---- | M] () -- C:\WINDOWS\data6.set
[2010/06/12 02:04:00 | 002,643,702 | -H-- | M] () -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\IconCache.db
[2010/06/12 01:54:20 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/06/12 01:53:23 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/12 01:44:07 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\NTREGOPT.lnk
[2010/06/12 01:44:07 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\ERUNT.lnk
[2010/06/12 01:15:54 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Gtaviri.dat
[2010/06/12 01:04:32 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Hlazu.bin
[2010/06/12 00:23:56 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JeremyNew\Desktop\TFC.exe
[2010/06/12 00:15:02 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\prvlcl.dat
[2010/06/12 00:12:49 | 000,062,382 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_06_IN_THE_LOOP.pdf
[2010/06/12 00:12:23 | 000,070,774 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10c_10_SC4P_SHIT_MY_DAD_SAYS_Henry_Revised_(A.Rose).pdf
[2010/06/12 00:12:11 | 000,114,110 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10b_10_SC1P_SHIT_MY_DAD_SAYS_full_script.pdf
[2010/06/12 00:12:05 | 000,021,954 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10a_10_SC1P_SHIT_MY_DAD_SAYS_bd.pdf
[2010/06/11 20:39:03 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\afyd.sys
[2010/06/11 16:58:37 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\rkill.com
[2010/06/11 16:55:00 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\rkill.exe
[2010/06/07 15:41:32 | 000,050,882 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Anniversary Party Scene.pdf
[2010/06/03 04:12:35 | 000,109,182 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_09a_10_SC4P_UNTITLED_PETER_KNIGHT_Full_Script.pdf
[2010/06/03 04:12:29 | 000,048,318 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_09a_10_SC4P_UNTITLED_PETER_KNIGHT_Gracie_(K.Cassidy).pdf
[2010/06/03 04:12:16 | 000,034,830 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_08b_YOU_SEND_ME.pdf
[2010/06/03 04:12:12 | 000,033,883 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_08a_SUDDENLY_SUSAN.pdf
[2010/06/03 04:10:45 | 000,260,220 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\How_to_make_a_post_on_the_submissions_blog_5.pdf
[2010/05/31 10:41:00 | 000,998,736 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\JeremyNew\Desktop\123awesome.exe
[2010/05/29 22:09:13 | 000,020,582 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\stan_lee.jpg
[2010/05/29 22:08:06 | 000,021,799 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\sc0000b304.jpg
[2010/05/29 22:02:22 | 000,135,735 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\2481043297_1f12ed170a.jpg
[2010/05/29 22:01:17 | 000,008,396 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\stan-lees-autograph-paying-200X200.jpg
[2010/05/27 23:43:34 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/05/27 15:30:49 | 000,029,809 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\policySummary.xhtml
[2010/05/26 00:44:28 | 000,029,910 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\csi_greg_nobler.pdf
[2010/05/26 00:28:36 | 000,065,417 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Conner.pdf
[2010/05/26 00:26:28 | 000,032,933 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Jesse_Male_Teen.pdf
[2010/05/20 18:32:46 | 000,506,843 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\High School Confidential.pdf
[2010/05/19 17:54:40 | 000,090,708 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Attachment_Agreement.pdf
[2010/05/18 21:03:18 | 000,022,021 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\744px-Flag_of_Zaire_svg.png
[2010/05/18 19:52:39 | 041,408,878 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Go Your Own Way.mp4
[2010/05/18 19:45:45 | 025,692,766 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Lost in Translation.mp4
[2010/05/14 18:10:00 | 010,898,208 | ---- | M] () -- C:\9.CAP
[2010/05/14 18:09:12 | 021,641,631 | ---- | M] () -- C:\8.CAP
[2010/05/14 18:09:02 | 100,833,828 | ---- | M] () -- C:\7.CAP
[2010/05/14 18:08:41 | 100,833,828 | ---- | M] () -- C:\6.CAP
[2010/05/14 18:08:25 | 100,833,828 | ---- | M] () -- C:\5.CAP
[2010/05/14 18:07:59 | 021,648,792 | ---- | M] () -- C:\4.CAP
[2010/05/14 18:07:35 | 173,865,783 | ---- | M] () -- C:\3.CAP
[2010/05/14 18:06:51 | 099,026,483 | ---- | M] () -- C:\2.CAP
[2010/05/14 18:06:22 | 010,023,933 | ---- | M] () -- C:\1.CAP
[2010/05/14 01:42:32 | 092,798,895 | ---- | M] () -- C:\18.CAP
[2010/05/14 01:36:54 | 100,833,828 | ---- | M] () -- C:\17.CAP
[2010/05/14 01:35:37 | 021,648,792 | ---- | M] () -- C:\16.CAP
[2010/05/14 01:34:37 | 074,839,324 | ---- | M] () -- C:\15.CAP
[2010/05/14 01:32:58 | 099,026,483 | ---- | M] () -- C:\14.CAP
[2010/05/14 01:31:49 | 010,023,933 | ---- | M] () -- C:\13.CAP
[2010/05/14 00:10:14 | 000,024,030 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\plasticface.jpg
[2010/05/13 00:43:01 | 000,035,442 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\30869_1271009344766_1515840782_31453790_3292506_n.jpg
[2010/05/12 19:59:01 | 090,398,965 | ---- | M] () -- C:\38.CAP
[2010/05/12 19:57:43 | 238,532,363 | ---- | M] () -- C:\37.CAP
[2010/05/12 19:56:39 | 139,348,838 | ---- | M] () -- C:\19.CAP
[2010/05/12 19:55:21 | 040,684,980 | ---- | M] () -- C:\21.CAP
[2010/05/12 19:21:21 | 261,799,901 | ---- | M] () -- C:\22.CAP
[2010/05/12 19:19:42 | 162,119,826 | ---- | M] () -- C:\23.CAP
[2010/05/12 19:17:38 | 063,087,002 | ---- | M] () -- C:\24.CAP
[2010/05/12 19:15:50 | 045,265,554 | ---- | M] () -- C:\25.CAP
[2010/05/12 19:14:10 | 242,848,345 | ---- | M] () -- C:\26.CAP
[2010/05/12 19:12:37 | 143,768,448 | ---- | M] () -- C:\27.CAP
[2010/05/12 19:11:38 | 099,239,089 | ---- | M] () -- C:\20.CAP
[2010/05/12 02:10:41 | 000,000,134 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Mark Wheeler.vcf
[2010/05/09 18:20:12 | 000,026,198 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Daddy Issues.pdf
[2010/05/09 18:18:23 | 000,022,417 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Interrogation.pdf
[2010/05/09 17:00:55 | 000,037,240 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\naked-girl+-101-4.jpg
[2010/05/07 19:44:38 | 000,057,792 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/05/07 14:01:50 | 000,000,692 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/05/05 23:42:43 | 034,415,956 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Full GDL for YouTube Part II.mp4
[2010/05/05 21:44:02 | 167,704,179 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Full GDL for YouTube Part I.mp4
[2010/05/05 20:26:52 | 000,003,823 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Raw GDL footage with intro and splices.mpg.scn
[2010/05/05 20:19:55 | 000,000,349 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/05/05 19:53:23 | 000,006,844 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\JI on Showbiz Tonight.cos2
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/27 21:53:49 | 000,418,353 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\DeltStandard.doc
[2010/04/23 00:26:50 | 000,003,711 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Edited GDL.mpg.scn
[2010/04/23 00:14:56 | 815,405,056 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Raw GDL footage with intro and splices.mpg
[2010/04/22 22:31:08 | 000,222,763 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy for YouTube.jpg
[2010/04/22 22:29:25 | 001,060,141 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy flip to B&W for YouTube.jpg
[2010/04/22 14:10:03 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/21 18:39:32 | 000,162,227 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Directory Listing for Mr_ Wolff Klabin.mht
[2010/04/21 17:33:31 | 000,012,288 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/21 05:53:10 | 000,000,940 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RUNAWAY - A TWIST OF FATE.lnk
[2010/04/20 00:20:43 | 000,000,459 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\HCONF_AUDITION.scn
[2010/04/19 22:33:42 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/04/19 20:33:31 | 000,000,897 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Pinnacle Studio 12.lnk
[2010/04/19 19:45:00 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/04/19 19:45:00 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2010/04/19 16:39:08 | 000,076,080 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/19 15:33:22 | 000,001,890 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Pinnacle Instant DVD Recorder.lnk
[2010/04/15 08:04:54 | 000,030,208 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Just a New York girl.doc
[2010/04/15 03:51:46 | 000,057,761 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\journey2.aup
[2010/04/15 03:41:35 | 000,043,323 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\journey2.aup.bak
[2010/04/13 13:04:54 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 04:22:48 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/04/12 00:48:47 | 000,034,406 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Jeremy sings!.jpg
[2010/04/10 14:27:13 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\jeremy.doc
[2010/04/10 14:26:50 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Now I understand what.doc
[2010/04/04 21:44:20 | 000,785,931 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\I-FAKER_Desktop_Pro.rar
[2010/04/04 16:25:18 | 507,142,144 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\TurboTax 2009
[2010/04/04 16:04:20 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ĩTorrent.lnk
[2010/04/03 21:26:34 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\In active and meaningful discussions.doc
[2010/04/02 01:05:32 | 000,023,927 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Monique in conference room.pdf
[2010/03/20 22:38:20 | 000,838,383 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy flip.jpg
[2010/03/19 16:09:53 | 000,818,453 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy.jpg
[2010/03/19 16:01:24 | 000,700,235 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Brighter Jeremy.jpg
[2010/03/19 03:10:48 | 000,014,125 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\Jeremy sings.jpg
[2010/03/18 20:31:04 | 014,187,589 | ---- | M] () -- C:\Documents and Settings\JeremyNew\Desktop\HCONF_AUDITION.mp4
========== Files Created - No Company Name ==========
[2010/06/13 02:53:31 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\gmer.exe
[2010/06/12 17:31:59 | 000,243,474 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_04a_10.02.15_HOW_TO_REHEARSE.pdf
[2010/06/12 17:28:51 | 009,323,248 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_02_15_SECOND_PRINCIPLE.pdf
[2010/06/12 03:15:09 | 000,000,103 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\fix.reg
[2010/06/12 03:03:01 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/12 01:59:51 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/12 01:54:19 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/06/12 01:44:07 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\NTREGOPT.lnk
[2010/06/12 01:44:07 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\ERUNT.lnk
[2010/06/12 01:39:01 | 000,000,073 | ---- | C] () -- C:\WINDOWS\data6.set
[2010/06/12 00:26:23 | 000,021,954 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10a_10_SC1P_SHIT_MY_DAD_SAYS_bd.pdf
[2010/06/12 00:12:49 | 000,062,382 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_06_IN_THE_LOOP.pdf
[2010/06/12 00:12:23 | 000,070,774 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10c_10_SC4P_SHIT_MY_DAD_SAYS_Henry_Revised_(A.Rose).pdf
[2010/06/12 00:12:11 | 000,114,110 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk3_10b_10_SC1P_SHIT_MY_DAD_SAYS_full_script.pdf
[2010/06/11 20:39:03 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\afyd.sys
[2010/06/11 16:58:27 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\rkill.com
[2010/06/11 16:54:48 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\rkill.exe
[2010/06/10 03:04:08 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Gtaviri.dat
[2010/06/10 03:04:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Hlazu.bin
[2010/06/07 15:36:55 | 000,050,882 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Anniversary Party Scene.pdf
[2010/06/03 04:12:34 | 000,109,182 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_09a_10_SC4P_UNTITLED_PETER_KNIGHT_Full_Script.pdf
[2010/06/03 04:12:29 | 000,048,318 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_09a_10_SC4P_UNTITLED_PETER_KNIGHT_Gracie_(K.Cassidy).pdf
[2010/06/03 04:12:16 | 000,034,830 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_08b_YOU_SEND_ME.pdf
[2010/06/03 04:12:12 | 000,033,883 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\wk2_08a_SUDDENLY_SUSAN.pdf
[2010/06/03 04:11:06 | 000,260,220 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\How_to_make_a_post_on_the_submissions_blog_5.pdf
[2010/05/29 22:10:13 | 000,008,396 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\stan-lees-autograph-paying-200X200.jpg
[2010/05/29 22:09:58 | 000,021,799 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\sc0000b304.jpg
[2010/05/29 22:09:40 | 000,135,735 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\2481043297_1f12ed170a.jpg
[2010/05/29 22:09:27 | 000,020,582 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\stan_lee.jpg
[2010/05/27 23:31:01 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/05/27 15:30:49 | 000,029,809 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\policySummary.xhtml
[2010/05/26 00:44:28 | 000,029,910 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\csi_greg_nobler.pdf
[2010/05/26 00:31:47 | 000,065,417 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Conner.pdf
[2010/05/26 00:31:36 | 000,032,933 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Jesse_Male_Teen.pdf
[2010/05/20 18:32:46 | 000,506,843 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\High School Confidential.pdf
[2010/05/18 21:03:27 | 000,022,021 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\744px-Flag_of_Zaire_svg.png
[2010/05/18 19:52:39 | 041,408,878 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Go Your Own Way.mp4
[2010/05/18 19:45:45 | 025,692,766 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Lost in Translation.mp4
[2010/05/14 18:10:00 | 010,898,208 | ---- | C] () -- C:\9.CAP
[2010/05/14 18:09:11 | 021,641,631 | ---- | C] () -- C:\8.CAP
[2010/05/14 18:08:52 | 100,833,828 | ---- | C] () -- C:\7.CAP
[2010/05/14 00:10:17 | 000,024,030 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\plasticface.jpg
[2010/05/13 00:39:08 | 000,035,442 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\30869_1271009344766_1515840782_31453790_3292506_n.jpg
[2010/05/12 02:10:41 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Mark Wheeler.vcf
[2010/05/09 18:21:23 | 000,022,417 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Interrogation.pdf
[2010/05/09 18:21:16 | 000,026,198 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Daddy Issues.pdf
[2010/05/09 17:03:22 | 000,037,240 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\naked-girl+-101-4.jpg
[2010/05/07 19:44:38 | 000,057,792 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/05/07 14:01:50 | 000,000,692 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/05/05 23:32:39 | 034,415,956 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Full GDL for YouTube Part II.mp4
[2010/05/05 20:46:30 | 167,704,179 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Full GDL for YouTube Part I.mp4
[2010/05/05 20:26:52 | 000,003,823 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Raw GDL footage with intro and splices.mpg.scn
[2010/05/05 19:53:22 | 000,006,844 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\JI on Showbiz Tonight.cos2
[2010/04/27 21:53:49 | 000,418,353 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\DeltStandard.doc
[2010/04/23 00:26:50 | 000,003,711 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Edited GDL.mpg.scn
[2010/04/23 00:11:57 | 815,405,056 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Raw GDL footage with intro and splices.mpg
[2010/04/22 22:36:10 | 003,833,913 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\JI on Showbiz Tonight.wmv
[2010/04/22 22:31:08 | 000,222,763 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy for YouTube.jpg
[2010/04/22 22:29:23 | 001,060,141 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy flip to B&W for YouTube.jpg
[2010/04/22 14:11:31 | 000,002,187 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/22 14:10:02 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/21 18:39:30 | 000,162,227 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Directory Listing for Mr_ Wolff Klabin.mht
[2010/04/21 05:53:10 | 000,000,940 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RUNAWAY - A TWIST OF FATE.lnk
[2010/04/20 00:20:42 | 000,000,459 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\HCONF_AUDITION.scn
[2010/04/19 22:33:42 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/04/19 19:45:00 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/04/19 19:45:00 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2010/04/19 15:37:45 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BFXSrcFilter.ax
[2010/04/19 15:37:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Graffiti5.2Pin.ini
[2010/04/19 15:33:22 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Pinnacle Instant DVD Recorder.lnk
[2010/04/19 15:27:08 | 000,000,897 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Pinnacle Studio 12.lnk
[2010/04/19 15:19:15 | 000,000,349 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/04/15 02:21:13 | 000,057,761 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\journey2.aup
[2010/04/15 02:21:13 | 000,043,323 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\journey2.aup.bak
[2010/04/12 15:12:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/12 03:37:04 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/04/10 14:27:13 | 000,028,672 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\jeremy.doc
[2010/04/10 14:26:50 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Now I understand what.doc
[2010/04/08 18:54:47 | 000,034,406 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Jeremy sings!.jpg
[2010/04/08 04:26:23 | 000,030,208 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Just a New York girl.doc
[2010/04/04 21:44:09 | 000,785,931 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\I-FAKER_Desktop_Pro.rar
[2010/04/04 16:05:35 | 507,142,144 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\TurboTax 2009
[2010/04/04 16:04:20 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ĩTorrent.lnk
[2010/04/02 01:05:32 | 000,023,927 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Monique in conference room.pdf
[2010/04/01 17:36:05 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\In active and meaningful discussions.doc
[2010/03/26 02:27:24 | 000,090,708 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Attachment_Agreement.pdf
[2010/03/20 22:38:19 | 000,838,383 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy flip.jpg
[2010/03/19 16:05:20 | 000,818,453 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Color Jeremy.jpg
[2010/03/19 16:01:24 | 000,700,235 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Brighter Jeremy.jpg
[2010/03/19 03:10:47 | 000,014,125 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\Jeremy sings.jpg
[2010/03/18 20:31:04 | 014,187,589 | ---- | C] () -- C:\Documents and Settings\JeremyNew\Desktop\HCONF_AUDITION.mp4
[2010/03/02 17:00:00 | 004,555,278 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2010/03/02 17:00:00 | 001,449,935 | ---- | C] () -- C:\WINDOWS\System32\ffmpegmt.dll
[2010/03/02 17:00:00 | 000,882,688 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/03/02 17:00:00 | 000,877,385 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2010/03/02 17:00:00 | 000,556,491 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2010/03/02 17:00:00 | 000,336,384 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2010/03/02 17:00:00 | 000,324,096 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/03/02 17:00:00 | 000,248,320 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/03/02 17:00:00 | 000,216,576 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2010/03/02 17:00:00 | 000,169,984 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2010/03/02 17:00:00 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2010/03/02 17:00:00 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/03/02 17:00:00 | 000,121,856 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2010/03/02 17:00:00 | 000,116,736 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2010/03/02 17:00:00 | 000,100,864 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2010/03/02 17:00:00 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2010/03/02 17:00:00 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/02/01 13:50:32 | 000,000,156 | ---- | C] () -- C:\WINDOWS\Kpcms.ini
[2010/02/01 13:50:10 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
[2009/11/14 11:37:08 | 000,154,112 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2009/11/14 11:33:38 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2009/11/14 11:11:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2009/11/14 11:11:42 | 000,150,016 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2009/11/14 11:11:42 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2009/11/14 11:11:40 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2009/11/14 11:11:40 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2009/11/14 11:11:38 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2009/11/14 11:11:32 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 11:11:32 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2009/07/06 02:13:24 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\AVERM.dll
[2009/07/06 02:13:24 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll
[2009/06/07 09:24:04 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/02/05 08:22:29 | 000,000,026 | ---- | C] () -- C:\WINDOWS\FPKPMSV.INI
[2009/01/10 15:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2008/11/06 09:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/02 19:33:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DVEdit.INI
[2008/11/02 19:29:54 | 000,000,072 | ---- | C] () -- C:\WINDOWS\SCapPro.INI
[2008/11/02 19:29:05 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\trc.dll
[2008/11/02 19:28:41 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\dsp_trc.dll
[2008/11/02 19:28:41 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\IcdSptSvps.dll
[2008/10/05 01:51:46 | 000,000,040 | ---- | C] () -- C:\WINDOWS\RUNAWAY2.INI
[2008/09/19 23:59:01 | 000,000,058 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2008/09/19 23:59:01 | 000,000,040 | ---- | C] () -- C:\WINDOWS\opt_1440.ini
[2008/09/19 23:59:00 | 000,000,447 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2008/09/19 23:58:59 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2008/09/19 23:58:58 | 000,000,052 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2008/09/18 02:45:17 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2008/09/17 11:34:48 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/09/17 11:34:22 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/10/13 02:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2007/01/26 02:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007/01/26 02:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2004/08/19 14:03:08 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\ECioctl.sys
[2004/08/16 13:43:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CeEKey.INI
[2004/08/10 15:37:33 | 000,000,921 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2004/08/10 15:35:16 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/08/10 15:35:16 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/08/10 15:35:16 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/08/10 15:35:16 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/08/10 15:35:16 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/08/10 15:35:16 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/08/10 15:10:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2004/08/10 15:09:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CePMTray.INI
[2004/08/10 13:57:26 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2004/08/10 13:57:26 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2004/08/10 13:57:26 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2004/08/10 13:57:26 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2004/08/10 13:34:04 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/08/10 13:23:21 | 000,006,867 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2004/08/09 17:37:33 | 000,356,352 | ---- | C] () -- C:\WINDOWS\System32\EMCRI.dll
[2004/08/09 17:17:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/08/09 17:12:23 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/09 17:04:24 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/09 16:32:25 | 000,000,384 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/04/21 22:58:26 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2008/10/30 03:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACASystems
[2008/10/30 00:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AnyCapture
[2008/09/18 02:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Final Draft
[2008/09/18 02:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2009/07/06 02:03:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/04/21 17:34:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pendulo Studios
[2010/04/19 15:32:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/04/19 15:21:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2010/04/19 20:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2010/04/19 15:21:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Studio 12
[2008/10/05 02:02:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/11 11:07:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Update
[2008/10/30 03:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\ACASystems
[2008/09/18 01:01:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Azureus
[2009/02/05 08:13:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Downloaded Installations
[2008/09/18 01:01:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Ethereal
[2008/09/18 01:01:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\FileOpen
[2008/09/18 01:01:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Final Draft
[2010/05/29 22:11:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\FrostWire
[2009/07/06 02:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\GetRightToGo
[2008/09/18 01:01:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\InterTrust
[2008/09/18 01:01:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\InterVideo
[2009/02/05 08:22:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Kinko's
[2008/09/18 01:01:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Learn2.com
[2009/07/06 02:03:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\NCH Swift Sound
[2008/09/18 00:55:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\PGP
[2010/04/19 15:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\proDAD
[2008/09/18 00:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Template
[2008/09/18 00:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\toshiba
[2008/09/18 00:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\uqm
[2010/04/19 05:02:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\uTorrent
[2008/09/18 00:54:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\JeremyNew\Application Data\Viewpoint
[2010/06/13 16:13:49 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/05/14 18:06:22 | 010,023,933 | ---- | M] () -- C:\1.CAP
[2010/02/10 15:20:32 | 196,670,167 | ---- | M] () -- C:\10.CAP
[2010/02/10 15:26:16 | 098,176,462 | ---- | M] () -- C:\11.CAP
[2010/02/10 15:27:49 | 170,227,453 | ---- | M] () -- C:\12.CAP
[2010/05/14 01:31:49 | 010,023,933 | ---- | M] () -- C:\13.CAP
[2010/05/14 01:32:58 | 099,026,483 | ---- | M] () -- C:\14.CAP
[2010/05/14 01:34:37 | 074,839,324 | ---- | M] () -- C:\15.CAP
[2010/05/14 01:35:37 | 021,648,792 | ---- | M] () -- C:\16.CAP
[2010/05/14 01:36:54 | 100,833,828 | ---- | M] () -- C:\17.CAP
[2010/05/14 01:42:32 | 092,798,895 | ---- | M] () -- C:\18.CAP
[2010/05/12 19:56:39 | 139,348,838 | ---- | M] () -- C:\19.CAP
[2010/05/14 18:06:51 | 099,026,483 | ---- | M] () -- C:\2.CAP
[2010/05/12 19:11:38 | 099,239,089 | ---- | M] () -- C:\20.CAP
[2010/05/12 19:55:21 | 040,684,980 | ---- | M] () -- C:\21.CAP
[2010/05/12 19:21:21 | 261,799,901 | ---- | M] () -- C:\22.CAP
[2010/05/12 19:19:42 | 162,119,826 | ---- | M] () -- C:\23.CAP
[2010/05/12 19:17:38 | 063,087,002 | ---- | M] () -- C:\24.CAP
[2010/05/12 19:15:50 | 045,265,554 | ---- | M] () -- C:\25.CAP
[2010/05/12 19:14:10 | 242,848,345 | ---- | M] () -- C:\26.CAP
[2010/05/12 19:12:37 | 143,768,448 | ---- | M] () -- C:\27.CAP
[2010/02/08 16:48:08 | 097,755,755 | ---- | M] () -- C:\28.CAP
[2010/02/08 16:50:58 | 098,191,220 | ---- | M] () -- C:\29.CAP
[2010/05/14 18:07:35 | 173,865,783 | ---- | M] () -- C:\3.CAP
[2010/02/08 16:52:00 | 098,254,376 | ---- | M] () -- C:\30.CAP
[2010/02/08 16:54:16 | 098,214,040 | ---- | M] () -- C:\31.CAP
[2010/02/09 02:04:10 | 098,564,322 | ---- | M] () -- C:\32.CAP
[2010/02/09 02:05:32 | 183,741,523 | ---- | M] () -- C:\33.CAP
[2010/02/10 15:15:30 | 098,139,361 | ---- | M] () -- C:\34.CAP
[2010/02/10 15:16:49 | 116,770,602 | ---- | M] () -- C:\35.CAP
[2010/02/10 15:18:14 | 098,339,057 | ---- | M] () -- C:\36.CAP
[2010/05/12 19:57:43 | 238,532,363 | ---- | M] () -- C:\37.CAP
[2010/05/12 19:59:01 | 090,398,965 | ---- | M] () -- C:\38.CAP
[2010/05/14 18:07:59 | 021,648,792 | ---- | M] () -- C:\4.CAP
[2010/05/14 18:08:25 | 100,833,828 | ---- | M] () -- C:\5.CAP
[2010/05/14 18:08:41 | 100,833,828 | ---- | M] () -- C:\6.CAP
[2010/05/14 18:09:02 | 100,833,828 | ---- | M] () -- C:\7.CAP
[2010/05/14 18:09:12 | 021,641,631 | ---- | M] () -- C:\8.CAP
[2010/05/14 18:10:00 | 010,898,208 | ---- | M] () -- C:\9.CAP
[2010/02/09 02:38:34 | 001,754,724 | ---- | M] () -- C:\aircrack-ng.exe
[2004/08/09 17:08:24 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/06/12 02:49:53 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2004/08/09 17:08:24 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/03/25 10:38:00 | 001,100,288 | ---- | M] () -- C:\cygcrypto-0.9.8.dll
[2008/06/12 10:35:00 | 001,872,884 | ---- | M] (Red Hat) -- C:\cygwin1.dll
[2009/03/01 18:42:00 | 000,066,048 | ---- | M] () -- C:\cygz.dll
[2004/08/09 17:08:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2004/08/10 14:43:33 | 000,000,835 | -H-- | M] () -- C:\IPH.PH
[2010/06/10 06:44:50 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2004/08/09 17:08:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2005/11/12 14:00:00 | 000,344,064 | ---- | M] (Microsoft Corporation) -- C:\msvcr70.dll
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/18 06:17:14 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2008/04/23 17:54:02 | 059,473,816 | ---- | M] () -- C:\OurFunVacation.mpg
[2008/04/23 17:54:06 | 000,000,619 | ---- | M] () -- C:\OurFunVacation.mpg.scn
[2010/06/13 15:48:57 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/06/11 20:38:25 | 000,000,377 | ---- | M] () -- C:\rkill.log
[2010/06/12 03:27:34 | 000,038,192 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_12.06.2010_03.27.19_log.txt
[2010/06/12 15:36:41 | 000,037,256 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_12.06.2010_15.36.28_log.txt
[2010/06/12 15:44:40 | 000,037,278 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_12.06.2010_15.44.26_log.txt
[2010/06/12 15:56:09 | 000,037,256 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_12.06.2010_15.55.56_log.txt
[2010/06/12 16:17:49 | 000,037,256 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_12.06.2010_16.17.37_log.txt
[2007/10/01 22:02:00 | 000,053,248 | ---- | M] () -- C:\wzcook.exe
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2001/12/13 00:01:00 | 000,027,836 | ---- | M] (Brother Industries ,Ltd ) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\BRPP2KA.DLL
[2008/07/06 05:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004/08/09 09:58:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/09 09:58:00 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/09 09:58:00 | 000,880,640 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 17:12:08 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 17:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\aircrack-ng.exe:SummaryInformation
@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
< End of report >
Extras:
OTL Extras logfile created on: 6/13/2010 4:15:20 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\JeremyNew\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 40.89 Gb Free Space | 36.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: -
Current User Name: JeremyNew
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.js [@ = JSFile] -- C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.com [@ = comfile] -- Reg Error: Key error. File not found
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
jsfile [open] -- "C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- File not found
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- (FrostWire Group)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- File not found
"C:\Program Files\Final Draft 7\Final Draft.exe" = C:\Program Files\Final Draft 7\Final Draft.exe:*:Enabled:Final Draft -- (Final Draft Inc.)
"C:\Program Files\FiSTiNG4FUN\Commview for Wifi\CommViewWiFi\WEPdecoder.exe" = C:\Program Files\FiSTiNG4FUN\Commview for Wifi\CommViewWiFi\WEPdecoder.exe:*:Enabled:WEP key recovery -- (TamoSoft)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:ĩTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager -- (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio -- (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi -- (Pinnacle Systems)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1485ABFA-12D7-4107-9148-54EE30CDBA67}" = Samsung USB Driver (MCCI 4.16)
"{262BF2CD-601D-4F43-919C-4B00B1D1F338}" = Boris Graffiti
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 20
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{49188E15-9B2E-4913-9107-A5D01821AC68}" = TouchPad On/Off Utility
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5B30AA25-BF39-4BE4-8FEE-51938BAB214D}" = TurboTax 2008 wcaiper
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{5EB90C06-964F-4195-B83E-BD7E55C88415}" = Pinnacle Video Driver
"{68D368EE-F5AC-4402-BD45-B454B5453FE1}" = SRS WOW XT Plug-In for Windows Media Player for Toshiba version 1.0.2
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}" = Digital Voice Editor 3
"{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{9860A9CF-7E71-43AC-888F-0B4D3EA212D1}" = Roxio Burn Engine
"{9AC200C3-A4C8-401C-A5A8-202BE888B165}" = TOSHIBA Fax Extension
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A67BB21E-D419-45BB-AB86-7D87D14BBCE2}" = Safari
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0 Professional - English, Franįais, Deutsch
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AD961D56-DCEE-415C-978C-62317C206826}" = Commview for Wifi
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{BA561482-C49D-4687-A61C-96236C1688F0}" = ArcSoft Software Suite
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}" = Pinnacle Instant DVD Recorder
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cb7d100f-d1e8-46d7-93fc-f5c838c928c4}" = Nero 9 Essentials
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D041EB9E-890A-4098-8F94-51DA194AC72A}" = Pinnacle Studio 12
"{D1860E6E-520E-4380-8433-E58E8F88B473}" = Pinnacle Studio 12 Ultimate Plugins
"{D2A03D7A-5803-48DD-BA43-AAE5DED2CB19}" = TOSHIBA Hotkey Utility
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{E1B2DF7C-A176-4A1D-9D32-3CEC5037A524}" = Apple Application Support
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EDF04509-B350-4EAB-BE77-5F2C87C33B35}_is1" = MPEG Video Wizard DVD 4.0.4.114 (06/2009)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F16086C2-21CD-42CE-9EC8-2E5302D010B2}" = TOSHIBA Power Management Utility
"{F1B8DB67-D30E-4FF9-A85F-3CEE51825AA2}" = SMSC IrCC V5.1.3600.3 SP1
"{F69B66A8-61C9-424C-AFA1-7EC6093AC5AD}" = TOSHIBA Software Upgrades
"{F6C405D2-C50D-4D10-B89E-73A233A14D74}" = Toshiba Registration
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FC12A400-77D8-430A-90A6-3DC74DF78F55}" = I-Faker Desktop Pro
"Active@ KillDisk FREE Suite" = Active@ KillDisk FREE Suite
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe PageMaker 7.0" = Adobe PageMaker 7.0
"Alabaster" = Alabaster
"All ATI Software" = ATI - Software Uninstall Utility
"Allok Video to 3GP Converter_is1" = Allok Video to 3GP Converter 6.2.0603
"AT&T Connection Services Software" = AT&T Connection Services Manager
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"DVDGenie" = DVD Genie (remove only)
"ERUNT_is1" = ERUNT 1.1j
"EzButton" = Easy Button
"FrostWire" = FrostWire 4.17.0
"GenoPro" = GenoPro
"GenoPro Beta" = GenoPro Beta
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1485ABFA-12D7-4107-9148-54EE30CDBA67}" = Samsung USB Driver (MCCI 4.16)
"InstallShield_{49188E15-9B2E-4913-9107-A5D01821AC68}" = TouchPad On/Off Utility
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"InstallShield_{68D368EE-F5AC-4402-BD45-B454B5453FE1}" = SRS WOW XT Plug-In for Windows Media Player for Toshiba version 1.0.2
"InstallShield_{D2A03D7A-5803-48DD-BA43-AAE5DED2CB19}" = TOSHIBA Hotkey Utility
"InstallShield_{F16086C2-21CD-42CE-9EC8-2E5302D010B2}" = TOSHIBA Power Management Utility
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.5
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Mpeg Video Wizard DVD" = MPEG Video Wizard DVD 4.0.4.111 (12/2008)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notebook_Maximizer" = Notebook Maximizer
"Ogg Codecs" = Ogg Codecs 0.81.15562
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"RUNAWAY: A TWIST OF FATE (en)" = RUNAWAY: A TWIST OF FATE (English)
"Skype_is1" = Skype 2.5
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TOSHIBA Access" = TOSHIBA Access
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"uTorrent" = ĩTorrent
"WavePad" = WavePad Sound Editor
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/16/2010 9:32:23 PM | Computer Name = - | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/22/2010 8:05:38 PM | Computer Name = - | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00009e32.
Error - 1/22/2010 8:05:47 PM | Computer Name = - | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 1/22/2010 8:08:42 PM | Computer Name = - | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/22/2010 8:08:48 PM | Computer Name = - | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
Error - 1/22/2010 8:12:11 PM | Computer Name = - | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00009e32.
Error - 1/22/2010 8:12:21 PM | Computer Name = - | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 1/22/2010 8:12:31 PM | Computer Name = - | Source = Application Error | ID = 1001
Description = Fault bucket 223121472.
Error - 1/22/2010 8:14:07 PM | Computer Name = - | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00009e32.
Error - 1/22/2010 8:14:10 PM | Computer Name = - | Source = Application Error | ID = 1001
Description = Fault bucket 1228329324.
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
