OTL logfile created on: 28/03/2010 8:23:20 PM - Run 1 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\chris\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18882) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 49.00% Memory free 11.00 Gb Paging File | 9.00 Gb Available in Paging File | 85.00% Paging File free Paging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 4605 5000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 228.13 Gb Total Space | 48.83 Gb Free Space | 21.41% Space Free | Partition Type: NTFS Drive D: | 227.87 Gb Total Space | 216.69 Gb Free Space | 95.09% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: CHRIS-PC Current User Name: chris Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2010/03/28 17:51:09 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe PRC - [2010/03/28 09:23:22 | 000,176,128 | ---- | M] () -- C:\Windows\Snocab.exe PRC - [2010/03/04 20:11:18 | 003,233,168 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\Xfire.exe PRC - [2010/02/04 17:56:05 | 000,298,608 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe PRC - [2010/01/26 20:58:38 | 000,256,280 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe PRC - [2010/01/20 15:56:54 | 000,462,848 | ---- | M] (Stardock Corporation) -- C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe PRC - [2009/08/22 03:21:19 | 000,117,640 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/04/11 02:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2009/01/26 21:31:29 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2008/10/25 08:18:50 | 000,098,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE PRC - [2007/12/07 16:28:22 | 000,196,128 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvraidservice.exe PRC - [2007/10/11 14:53:22 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007/09/10 16:28:18 | 000,057,344 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe PRC - [2007/09/07 21:23:56 | 000,323,584 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe PRC - [2007/09/07 21:23:54 | 000,326,176 | ---- | M] () -- C:\Acer\Empowering Technology\SysMonitor.exe PRC - [2007/09/06 13:02:04 | 000,393,216 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRAgent.exe PRC - [2007/06/21 22:33:20 | 000,269,448 | ---- | M] (CyberLink) -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe PRC - [2007/04/25 20:34:30 | 000,457,512 | ---- | M] (HiTRSUT) -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe PRC - [2007/04/25 20:33:36 | 000,457,216 | ---- | M] (HiTRUST) -- C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe PRC - [2007/04/16 22:48:12 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe PRC - [2007/02/01 20:37:40 | 000,630,784 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010/03/28 17:51:09 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe MOD - [2010/03/04 20:11:26 | 000,942,480 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\xfire_toucan_41783.dll MOD - [2009/04/11 02:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll MOD - [2008/01/19 03:37:11 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wsock32.dll MOD - [2003/02/21 09:42:20 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr71.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010/03/11 09:12:23 | 000,332,720 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2009/08/22 03:21:19 | 000,117,640 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe -- (Norton Internet Security) SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/09/10 16:28:18 | 000,057,344 | ---- | M] (Acer Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService) SRV - [2007/06/21 22:33:20 | 000,269,448 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service) SRV - [2007/04/25 20:34:30 | 000,457,512 | ---- | M] (HiTRSUT) [Auto | Running] -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe -- (eDataSecurity Service) SRV - [2007/04/16 22:48:12 | 000,028,672 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe -- (AcerMemUsageCheckService) SRV - [2005/11/14 02:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.ca.acer.yahoo.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.ca.acer.yahoo.com IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.theglobeandmail.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/03/28 19:24:11 | 000,000,000 | ---D | M] [2010/02/09 19:40:17 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Mozilla\Firefox\extensions [2010/02/09 19:40:18 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Users\chris\AppData\Roaming\Mozilla\Firefox\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST) O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST) O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation) O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe () O4 - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe () O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files\Acer Registration\ACE1.exe (Leader Technologies) O4 - HKLM..\Run: [Acer Tour] File not found O4 - HKLM..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (Acer Inc.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Apanel] C:\ACERSW\config\SetApanel.cmd File not found O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (HiTRUST) O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NVRaidService] C:\Windows\System32\nvraidservice.exe (NVIDIA Corporation) O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [Acer Tour Reminder] File not found O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKCU..\Run: [WEK9EMDHI9] C:\Windows\Snocab.exe () O4 - Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ImpulseNow.lnk = C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe (Stardock Corporation) O4 - Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O4 - Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.) O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 216.211.26.14 216.211.26.15 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.132,93.188.166.139 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Acer03.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer03.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/02/06 10:33:25 | 000,000,073 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008/07/12 17:25:05 | 000,000,000 | ---D | M] - D:\Autorun -- [ NTFS ] O33 - MountPoints2\{59288b76-3b1a-11dd-b6b5-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{59288b76-3b1a-11dd-b6b5-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup\rsrc\Autorun.exe -- File not found O33 - MountPoints2\{59288b76-3b1a-11dd-b6b5-806e6f6e6963}\Shell\dinstall\command - "" = E:\Directx\dxsetup.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias [2008/08/24 15:23:47 | 000,000,000 | ---D | M] NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation) NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found OTL cannot create restorepoints on Vista OSs! [color=#E56717]========== Files/Folders - Created Within 14 Days ==========[/color] [2010/03/28 19:11:54 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Roaming\Malwarebytes [2010/03/28 19:11:50 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010/03/28 19:11:49 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010/03/28 19:11:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010/03/28 19:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010/03/28 19:09:28 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\chris\Desktop\mbam-setup.exe [2010/03/28 19:01:13 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT [2010/03/28 19:00:18 | 000,000,000 | ---D | C] -- C:\ERUNT [2010/03/28 18:24:25 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\chris\Desktop\erunt_setup.exe [2010/03/28 18:24:00 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Users\chris\Desktop\TFC.exe [2010/03/28 17:59:37 | 000,178,000 | ---- | C] (Kaspersky Lab) -- C:\Users\chris\Desktop\TDSSKiller.exe [2010/03/28 17:51:03 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe [2010/03/28 14:04:40 | 000,000,000 | ---D | C] -- C:\Windows\pss [2010/03/28 11:47:58 | 000,000,000 | R--D | C] -- C:\Program Files\Norton Support [2010/03/26 16:57:54 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Local\X-ray Anti-Cheat [2010/03/25 19:43:07 | 000,000,000 | ---D | C] -- C:\Users\chris\AppData\Local\WeGame [2010/03/22 20:36:14 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2007/12/01 15:44:27 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll [color=#E56717]========== Files - Modified Within 14 Days ==========[/color] [2010/03/28 20:26:13 | 004,194,304 | -HS- | M] () -- C:\Users\chris\ntuser.dat [2010/03/28 20:11:36 | 000,002,627 | ---- | M] () -- C:\Users\chris\Desktop\Microsoft Office Word 2007.lnk [2010/03/28 19:54:08 | 000,000,246 | -H-- | M] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job [2010/03/28 19:36:31 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2010/03/28 19:36:31 | 000,599,942 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010/03/28 19:36:31 | 000,105,448 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010/03/28 19:28:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010/03/28 19:24:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010/03/28 19:23:53 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010/03/28 19:23:53 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010/03/28 19:23:51 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010/03/28 19:23:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010/03/28 19:22:02 | 000,524,288 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms [2010/03/28 19:22:02 | 000,065,536 | -HS- | M] () -- C:\Users\chris\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2010/03/28 19:22:01 | 002,905,541 | -H-- | M] () -- C:\Users\chris\AppData\Local\IconCache.db [2010/03/28 19:11:53 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010/03/28 19:09:39 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\chris\Desktop\mbam-setup.exe [2010/03/28 19:00:19 | 000,000,519 | ---- | M] () -- C:\Users\chris\Desktop\NTREGOPT.lnk [2010/03/28 19:00:19 | 000,000,500 | ---- | M] () -- C:\Users\chris\Desktop\ERUNT.lnk [2010/03/28 18:24:28 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\chris\Desktop\erunt_setup.exe [2010/03/28 18:24:05 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\TFC.exe [2010/03/28 17:57:41 | 000,284,915 | ---- | M] () -- C:\Users\chris\Desktop\gmer.zip [2010/03/28 17:52:31 | 000,293,376 | ---- | M] () -- C:\Users\chris\Desktop\sf79pdy3.exe [2010/03/28 17:51:09 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\chris\Desktop\OTL.exe [2010/03/28 17:50:33 | 000,154,469 | ---- | M] () -- C:\Users\chris\Desktop\tdsskiller.zip [2010/03/28 17:49:57 | 000,067,654 | ---- | M] () -- C:\Users\chris\Documents\virus.docx [2010/03/28 09:24:12 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2010/03/28 09:23:22 | 000,176,128 | ---- | M] () -- C:\Windows\Snocab.exe [2010/03/28 09:23:11 | 000,176,128 | ---- | M] () -- C:\Windows\Snocaa.exe [2010/03/27 20:20:02 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{9BF4BBE6-07FF-4A8D-8436-98CCA54A559E}.job [2010/03/26 08:00:22 | 000,000,555 | ---- | M] () -- C:\Users\chris\Desktop\XrayAntiCheat - Shortcut.lnk [2010/03/25 19:42:51 | 000,000,460 | ---- | M] () -- C:\Users\Public\Desktop\WeGame.lnk [2010/03/25 19:42:51 | 000,000,460 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WeGame.lnk [2010/03/22 20:51:00 | 000,000,952 | ---- | M] () -- C:\Users\chris\Desktop\Bioshock - Shortcut.lnk [2010/03/22 10:43:42 | 000,178,000 | ---- | M] (Kaspersky Lab) -- C:\Users\chris\Desktop\TDSSKiller.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010/03/28 19:25:52 | 000,000,246 | -H-- | C] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job [2010/03/28 19:11:53 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010/03/28 19:00:19 | 000,000,519 | ---- | C] () -- C:\Users\chris\Desktop\NTREGOPT.lnk [2010/03/28 19:00:19 | 000,000,500 | ---- | C] () -- C:\Users\chris\Desktop\ERUNT.lnk [2010/03/28 17:57:39 | 000,284,915 | ---- | C] () -- C:\Users\chris\Desktop\gmer.zip [2010/03/28 17:52:28 | 000,293,376 | ---- | C] () -- C:\Users\chris\Desktop\sf79pdy3.exe [2010/03/28 17:50:32 | 000,154,469 | ---- | C] () -- C:\Users\chris\Desktop\tdsskiller.zip [2010/03/28 17:49:56 | 000,067,654 | ---- | C] () -- C:\Users\chris\Documents\virus.docx [2010/03/28 09:28:53 | 000,176,128 | ---- | C] () -- C:\Windows\Snocab.exe [2010/03/28 09:24:12 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/03/28 09:23:14 | 000,176,128 | ---- | C] () -- C:\Windows\Snocaa.exe [2010/03/26 08:00:22 | 000,000,555 | ---- | C] () -- C:\Users\chris\Desktop\XrayAntiCheat - Shortcut.lnk [2010/03/25 19:42:51 | 000,000,460 | ---- | C] () -- C:\Users\Public\Desktop\WeGame.lnk [2010/03/25 19:42:51 | 000,000,460 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WeGame.lnk [2010/03/22 20:51:00 | 000,000,952 | ---- | C] () -- C:\Users\chris\Desktop\Bioshock - Shortcut.lnk [2010/03/11 17:33:39 | 000,014,848 | ---- | C] () -- C:\Windows\System32\EuEpmGdi.dll [2010/03/11 17:33:38 | 000,014,216 | ---- | C] () -- C:\Windows\System32\epmntdrv.sys [2010/03/11 17:33:38 | 000,008,456 | ---- | C] () -- C:\Windows\System32\EuGdiDrv.sys [2010/03/04 20:11:22 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll [2010/02/24 18:10:04 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini [2009/09/17 17:39:21 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/05/13 18:21:48 | 000,003,985 | ---- | C] () -- C:\Users\chris\AppData\Local\springsettings.cfg [2009/04/23 08:05:46 | 000,023,888 | ---- | C] () -- C:\Users\chris\AppData\Roaming\UserTile.png [2008/10/28 17:40:48 | 000,173,552 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2008/10/07 17:22:46 | 000,000,331 | ---- | C] () -- C:\Windows\doom3.ini [2008/08/28 13:28:20 | 000,000,034 | ---- | C] () -- C:\Windows\Q3version.ini [2008/08/28 13:23:36 | 000,000,897 | ---- | C] () -- C:\Windows\Qiii.INI [2008/08/28 08:45:59 | 000,000,552 | ---- | C] () -- C:\Users\chris\AppData\Local\d3d8caps.dat [2008/08/24 10:36:53 | 000,001,681 | ---- | C] () -- C:\ProgramData\hpzinstall.log [2008/08/05 08:55:10 | 000,139,152 | ---- | C] () -- C:\Users\chris\AppData\Roaming\PnkBstrK.sys [2008/08/05 08:55:10 | 000,138,576 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2008/08/05 08:54:25 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini [2008/07/17 20:29:02 | 000,000,680 | ---- | C] () -- C:\Users\chris\AppData\Local\d3d9caps.dat [2008/06/28 18:49:58 | 000,015,630 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate [2008/06/15 19:51:51 | 000,012,288 | ---- | C] () -- C:\Users\chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/06/15 17:59:10 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini [2008/06/15 17:59:09 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini [2007/12/01 15:44:22 | 000,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll [2007/12/01 15:35:35 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll [2007/12/01 13:30:22 | 000,001,107 | ---- | C] () -- C:\Windows\generic.ini [2007/12/01 13:30:22 | 000,000,132 | ---- | C] () -- C:\Windows\Alaunch.ini [2007/12/01 13:30:20 | 000,140,320 | ---- | C] () -- C:\Windows\System32\drivers\nvstor32.sys [2007/05/15 20:06:58 | 000,071,208 | ---- | C] () -- C:\Windows\System32\PhysXLoader.dll [2007/04/25 20:33:22 | 000,266,240 | ---- | C] () -- C:\Windows\System32\NotesExtmngr.dll [2007/04/25 20:32:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\NotesActnMenu.dll [2007/04/25 20:32:46 | 000,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll [2007/04/25 20:31:00 | 000,028,672 | ---- | C] () -- C:\Windows\System32\BatchCrypto.dll [2007/04/25 20:30:52 | 000,073,728 | ---- | C] () -- C:\Windows\System32\APISlice.dll [2007/04/25 20:30:44 | 000,063,488 | ---- | C] () -- C:\Windows\System32\ShowErrMsg.dll [2007/04/14 16:57:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll [2007/04/14 16:57:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll [2007/04/14 16:57:06 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll [2007/04/14 16:57:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll [2006/12/25 19:44:48 | 000,022,016 | ---- | C] () -- C:\Windows\System32\MailFormat_U.dll [2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2001/12/26 20:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001/09/04 03:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001/07/30 20:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001/07/24 02:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll [color=#E56717]========== LOP Check ==========[/color] [2008/06/15 18:01:44 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Acer [2009/10/20 17:21:29 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Bioshock [2009/01/12 22:46:11 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Command & Conquer 3 Kane's Wrath [2009/01/07 20:19:01 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Command & Conquer 3 Tiberium Wars [2009/04/25 10:56:23 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\GetRightToGo [2008/11/14 17:56:38 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Groove Games [2009/07/15 17:43:09 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\iWin [2008/06/15 18:01:43 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Leadertech [2008/09/18 17:45:58 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\My Battle for Middle-earth Files [2008/07/17 16:35:10 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\My Battle for Middle-earth(tm) II Files [2009/03/11 17:12:39 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files [2009/04/23 08:05:46 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\PeerNetworking [2009/06/24 17:48:55 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Sierra [2009/06/24 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\springlobby [2009/05/13 18:21:47 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\springsettings [2009/07/14 16:55:00 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\Stardock [2010/02/14 12:12:37 | 000,000,000 | ---D | M] -- C:\Users\chris\AppData\Roaming\TS3Client [2010/03/28 19:22:04 | 000,032,526 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2010/03/27 20:20:02 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{9BF4BBE6-07FF-4A8D-8436-98CCA54A559E}.job [2010/03/28 19:54:08 | 000,000,246 | -H-- | M] () -- C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color] [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys [2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys [2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys [2008/01/19 03:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys [2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys [2006/11/02 05:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys [2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys [2009/04/11 02:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys [2008/01/19 03:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys [2008/01/19 03:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys [2006/11/02 05:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys [color=#A23BEC]< MD5 for: CNGAUDIT.DLL >[/color] [2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll [2006/11/02 05:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll [color=#A23BEC]< MD5 for: IASTORV.SYS >[/color] [2008/01/19 03:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys [2008/01/19 03:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys [2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys [2006/11/02 05:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] [2006/11/02 05:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll [2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll [2009/04/11 02:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll [2008/01/19 03:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll [color=#A23BEC]< MD5 for: NVRAID.SYS >[/color] [2008/01/19 03:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvraid.sys [2008/01/19 03:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvraid.sys [2006/11/02 05:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\drivers\nvraid.sys [2006/11/02 05:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvraid.sys [color=#A23BEC]< MD5 for: NVRD32.SYS >[/color] [2007/12/08 03:28:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) MD5=6F5BB0B40D251351A913B61BA9D64B3F -- C:\Windows\System32\drivers\nvrd32.sys [2007/12/08 03:28:10 | 000,131,616 | ---- | M] (NVIDIA Corporation) MD5=6F5BB0B40D251351A913B61BA9D64B3F -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_a5207023\nvrd32.sys [2007/09/11 19:19:20 | 000,123,424 | ---- | M] (NVIDIA Corporation) MD5=F2ABAB0C99237CE4E97478AF2E0438A0 -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_8225a48e\nvrd32.sys [color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color] [2006/11/02 05:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys [2006/11/02 05:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys [2008/01/19 03:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys [2008/01/19 03:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys [color=#A23BEC]< MD5 for: NVSTOR32.SYS >[/color] [2007/12/08 03:28:10 | 000,140,320 | ---- | M] (NVIDIA Corporation) MD5=689A2160B851F8BF88F20728FD2F30BD -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_a5207023\nvstor32.sys [2007/09/11 19:19:16 | 000,114,208 | ---- | M] (NVIDIA Corporation) MD5=8FFB327669B980549BD318D939A34F9B -- C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_4b699c67\nvstor32.sys [2007/09/11 19:19:18 | 000,114,208 | ---- | M] (NVIDIA Corporation) MD5=AFD01721DC3297E6715C5F472DD8BCCD -- C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_8225a48e\nvstor32.sys [2007/12/08 03:28:10 | 000,140,320 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\Windows\System32\drivers\nvstor32.sys [color=#A23BEC]< MD5 for: SCECLI.DLL >[/color] [2008/01/19 03:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll [2006/11/02 05:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll [2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll [2009/04/11 02:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll [color=#A23BEC]< %systemroot%\*. /mp /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [2009/03/08 07:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\dxtmsft.dll [2009/03/08 07:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\dxtrans.dll [2010/01/02 02:32:32 | 000,184,320 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\iepeers.dll [2009/04/11 02:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\rsaenh.dll [2009/04/11 02:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\SLC.dll [2009/04/11 02:28:25 | 000,443,392 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\win32spl.dll [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color] [2007/12/08 03:28:10 | 000,140,320 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\Windows\System32\drivers\nvstor32.sys [color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color] [2007/12/01 13:31:00 | 006,602,752 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2007/12/01 13:30:59 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2007/12/01 13:31:00 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2007/12/01 13:31:07 | 015,556,608 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2007/12/01 13:31:08 | 006,008,832 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV < End of report >