Thanks in advance for your help. Here is my situation.
Problem:
I have apparently been infected with some sort of malware. There are three main symptoms:
- Inappropriate advertisements for Vimax and other similar products appear in the adspace of many different web pages.
- My virus scanning software (McAfee VirusScan) has been disabled and I am unable to start it.
- Occasionally, when doing a Google search, I will click on a link but will be redirected to pages advertising various adult-themed products.
What I have done so far:
- Booted in Safe Mode and ran several different virus removal tools including McAfee VirusScan and Malwarebytes. Initially they found a removed about 20 infections. Now they no longer find infections, but the symptoms continue to persist.
- Ran ATF Cleaner
- Ran Windows Update
- Made a valid restore point
- Backed up my registry with ERUNT
- Ran virus scan software again
- I have rebooted my computer multiple times during this process
- In short, I have followed all of the instructions I have been able to find on this forum and others. Although the steps have been somewhat successful, the major symptoms outlined above still remain.
Possible cause of infection:
I am not sure. I do not download movies or pirated software in any form. However, my roommates do use my computer on occasion. They do not think they downloaded anything harmful, but it's impossible to tell for sure.
System setup:
Windows Vista, SP1, fully updated.
McAfee VirusScan (software provided by the university I attend)
Firefox 3.0 is default browser, though I do use the most recent version of IE on occasion.
Anything else you need to know about my setup?
My level of technical knowledge is intermediate-advanced. I'm not stupid when it comes to receiving instruction about how to work with a computer, but I don't have a deep level of knowledge about specific procedures such as editing the registry.
My log files are posted below as requested. Thanks in advance for your help!!!
Steve
Rooter.txt
Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1
C:\ [Fixed] - NTFS - (Total:295304 Mo/Free:1311 Mo)
D:\ [Fixed] - NTFS - (Total:9938 Mo/Free:344 Mo)
E:\ [CD-Rom] (Total:2652 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
J:\ [Removable] (Total:0 Mo/Free:0 Mo)
04/18/2009 Sat|22:27
----------------------\\ Processes..
--Locked-- [System Process]
--Locked-- System
---------- \SystemRoot\System32\smss.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\wininit.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\services.exe
---------- C:\Windows\system32\lsass.exe
---------- C:\Windows\system32\lsm.exe
---------- C:\Windows\system32\winlogon.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\AUDIODG.EXE
---------- C:\Windows\system32\SLsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\spoolsv.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\Dwm.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\Explorer.EXE
---------- C:\Windows\system32\taskeng.exe
---------- C:\Program Files\Google\Update\GoogleUpdate.exe
---------- C:\Program Files\Windows Defender\MSASCui.exe
---------- C:\Windows\zHotkey.exe
---------- C:\Windows\ModPS2Key.exe
---------- C:\Windows\sttray.exe
---------- C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
---------- C:\Program Files\Lexmark 2400 Series\ezprint.exe
---------- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
---------- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
---------- C:\Windows\713xRMT.exe
---------- C:\Program Files\Logitech\QuickCam\Quickcam.exe
---------- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Windows\ehome\ehtray.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
---------- C:\Program Files\Windows Media Player\wmpnscfg.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\ehome\ehmsas.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
---------- C:\Program Files\LSI SoftModem\agrsmsvc.exe
---------- C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
---------- C:\Program Files\Bonjour\mDNSResponder.exe
---------- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
---------- C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
---------- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
---------- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
---------- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
---------- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
---------- C:\Windows\system32\mfevtps.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\SearchIndexer.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
---------- C:\Windows\system32\WUDFHost.exe
---------- C:\Program Files\McAfee\Common Framework\McTray.exe
---------- C:\Windows\system32\lxcrcoms.exe
---------- C:\Windows\System32\mobsync.exe
---------- C:\Program Files\Windows Media Player\wmpnetwk.exe
---------- C:\Windows\system32\SearchProtocolHost.exe
---------- C:\Windows\system32\SearchFilterHost.exe
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Windows\servicing\TrustedInstaller.exe
---------- \\?\C:\Windows\system32\wbem\WMIADAP.EXE
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Windows\system32\DllHost.exe
---------- C:\Windows\system32\DllHost.exe
---------- C:\Users\Steve\Downloads\Rooter.exe
---------- C:\Windows\system32\cmd.exe
---------- C:\Windows\system32\conime.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.85,85.255.112.180
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.85,85.255.112.180
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.85,85.255.112.180
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{45BC915F-F40D-4B11-A0E0-26D5F7452FE1}]
NameServer REG_SZ 85.255.112.85,85.255.112.180
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{45BC915F-F40D-4B11-A0E0-26D5F7452FE1}]
NameServer REG_SZ 85.255.112.85,85.255.112.180
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{45BC915F-F40D-4B11-A0E0-26D5F7452FE1}]
NameServer REG_SZ 85.255.112.85,85.255.112.180
==> WAREOUT <==
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - 04/18/2009 Sat|22:28
----------------------\\ Scan completed at 22:28
OTListIt.txt
OTListIt logfile created on: 4/18/2009 10:29:23 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Steve\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.38 Gb Total Space | 113.28 Gb Free Space | 39.28% Space Free | Partition Type: NTFS
Drive D: | 9.71 Gb Total Space | 4.34 Gb Free Space | 44.68% Space Free | Partition Type: NTFS
Drive E: | 2.59 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: COMPY
Current User Name: Steve
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Windows\system32\AUDIODG.EXE (Microsoft Corporation)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\zHotkey.exe ()
PRC - C:\Windows\ModPS2Key.exe (Chicony)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Lexmark 2400 Series\lxcrmon.exe ()
PRC - C:\Program Files\Lexmark 2400 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Windows\713xRMT.exe ()
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Windows\ehome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe ()
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Windows\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Windows\system32\lxcrcoms.exe ( )
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - \?\C:\Windows\system32\wbem\WMIADAP.EXE File not found
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Windows\system32\conime.exe (Microsoft Corporation)
PRC - C:\Users\Steve\Downloads\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AgereModemAudio [Auto | Running]) -- C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati External Event Utility [Auto | Running]) -- C:\Windows\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (bckwfs [Auto | Running]) -- C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe ()
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c9b80066ee597c [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LVPrcSrv [Auto | Running]) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (lxcr_device [On_Demand | Running]) -- C:\Windows\system32\lxcrcoms.exe ( )
SRV - (McAfeeEngineService [Auto | Running]) -- C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe (McAfee, Inc.)
SRV - (McAfeeFramework [Auto | Running]) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McShield [Auto | Stopped]) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager [Auto | Running]) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation)
SRV - (mfevtp [Unknown | Running]) -- C:\Windows\system32\mfevtps.exe (McAfee, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (3xHybrid [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\3xHybrid.sys (NXP Semiconductors Germany GmbH)
DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (atikmdag [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (bckd [System | Running]) -- C:\Windows\system32\drivers\bckd.sys ()
DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (iaStorV [Boot | Running]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\Windows\system32\Drivers\LVPr2Mon.sys ()
DRV - (LVRS [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVUSBSta [On_Demand | Running]) -- C:\Windows\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVUVC [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (mfeapfk [On_Demand | Stopped]) -- C:\Windows\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfeavfk [On_Demand | Stopped]) -- C:\Windows\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Stopped]) -- C:\Windows\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [Boot | Running]) -- C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdet [On_Demand | Stopped]) -- C:\Windows\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik [System | Running]) -- C:\Windows\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) -- C:\Windows\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) -- C:\Windows\system32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tbhsd [On_Demand | Stopped]) -- C:\Windows\system32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usbbus [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (WsAudio_DeviceS(1) [On_Demand | Stopped]) -- C:\Windows\system32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.foxnews.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/27 18:37:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA\FIREFOX\COMPONENTS [2009/04/18 13:08:21 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA\FIREFOX\PLUGINS [2009/03/29 08:15:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\PROGRAM FILES\MOZILLA\THUNDERBIRD\COMPONENTS [2009/04/18 13:08:21 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA\THUNDERBIRD\PLUGINS [2009/03/29 08:15:43 | 00,000,000 | ---D | M]
[2009/02/27 18:24:14 | 00,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\mozilla\Extensions
[2009/02/27 18:24:14 | 00,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/05 10:40:05 | 00,000,000 | ---D | M] -- C:\Users\Steve\AppData\Roaming\mozilla\Firefox\Profiles\pibymdh4.default\extensions
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s ()
O4 - HKLM..\Run: [LaunchList] "C:\Program Files\Pinnacle\Studio 8\LaunchList.exe" File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [LXCRCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey (McAfee, Inc.)
O4 - HKLM..\Run: [ModPS2] ModPS2Key.exe (Chicony)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [ShowWnd] ShowWnd.exe ()
O4 - HKLM..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TV Card Remote Control Device Monitor] C:\Windows\713xRMT.exe ()
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [googletalk] C:\Users\Steve\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart (Google)
O4 - HKCU..\Run: [Power2GoExpress] File not found
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKCU..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.85,85.255.112.180
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{45BC915F-F40D-4B11-A0E0-26D5F7452FE1}\\NameServer = 85.255.112.85,85.255.112.180
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O33 - MountPoints2\{c3032282-0c46-11de-aa4f-0019d139ee82}\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
O33 - MountPoints2\K\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[3 C:\Windows\*.tmp files]
[2009/04/18 22:27:33 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/18 22:26:38 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/04/18 22:26:38 | 00,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/18 22:26:36 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/18 22:26:35 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/04/18 22:26:34 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/18 22:22:00 | 02,389,464 | -H-- | C] () -- C:\Users\Steve\AppData\Local\IconCache.db
[2009/04/18 22:16:07 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/04/18 22:15:27 | 00,000,733 | ---- | C] () -- C:\Users\Steve\Desktop\NTREGOPT.lnk
[2009/04/18 22:15:27 | 00,000,714 | ---- | C] () -- C:\Users\Steve\Desktop\ERUNT.lnk
[2009/04/18 22:15:26 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/18 18:59:18 | 00,081,984 | ---- | C] () -- C:\Windows\System32\bdod.bin
[2009/04/18 17:52:12 | 00,001,874 | ---- | C] () -- C:\Users\Steve\Desktop\HijackThis.lnk
[2009/04/18 17:52:12 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/04/18 17:33:58 | 00,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2009/04/18 17:20:44 | 00,000,850 | ---- | C] () -- C:\Windows\System32\ProductTweaks.xml
[2009/04/18 17:20:44 | 00,000,385 | ---- | C] () -- C:\Windows\System32\user_gensett.xml
[2009/04/18 13:43:41 | 00,000,680 | ---- | C] () -- C:\Users\Steve\AppData\Local\d3d9caps.dat
[2009/04/18 13:25:56 | 00,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\GetRightToGo
[2009/04/18 13:04:59 | 00,000,000 | ---D | C] -- C:\Windows\System32\logs
[2009/04/18 13:04:52 | 00,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\BitDefender
[2009/04/18 13:04:15 | 00,000,000 | ---D | C] -- C:\ProgramData\BitDefender
[2009/04/18 13:04:15 | 00,000,000 | ---D | C] -- C:\Program Files\BitDefender
[2009/04/18 13:04:13 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/04/18 13:03:10 | 00,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2009/04/18 13:02:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender
[2009/04/18 09:31:17 | 00,000,000 | ---D | C] -- C:\Windows\Minidump
[2009/04/18 09:30:52 | 21,928,7319 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2009/04/18 00:35:02 | 00,000,000 | ---D | C] -- C:\RECYCLER
[2009/04/18 00:20:55 | 00,000,000 | ---D | C] -- C:\Program Files\PixiePack Codec Pack
[2009/04/18 00:17:08 | 00,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\WinRAR
[2009/04/18 00:16:56 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009/04/15 22:59:15 | 00,000,000 | ---D | C] -- C:\ProgramData\RapidSolution
[2009/04/15 22:59:15 | 00,000,000 | ---D | C] -- C:\Program Files\RapidSolution
[2009/04/15 22:56:05 | 00,016,640 | ---- | C] (Wondershare) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys
[2009/04/15 21:03:42 | 01,454,626 | ---- | C] () -- C:\Users\Steve\Desktop\2008IR22.pdf
[2009/04/15 21:03:32 | 00,107,503 | ---- | C] () -- C:\Users\Steve\Desktop\2008IR22__INST.pdf
[2009/04/15 08:45:12 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winhttp.dll
[2009/04/15 08:45:09 | 00,562,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcprx.dll
[2009/04/15 08:45:08 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xolehlp.dll
[2009/04/15 08:45:02 | 03,599,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2009/04/15 08:45:02 | 03,547,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009/04/15 08:45:02 | 00,551,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpcss.dll
[2009/04/15 08:45:01 | 00,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelinesvc.exe
[2009/04/15 08:45:00 | 00,183,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdohlp.dll
[2009/04/15 08:45:00 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasrecst.dll
[2009/04/15 08:45:00 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasads.dll
[2009/04/15 08:45:00 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iasdatastore.dll
[2009/04/15 08:45:00 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\printfilterpipelineprxy.dll
[2009/04/15 08:45:00 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iashost.exe
[2009/04/15 08:44:57 | 01,255,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll
[2009/04/15 08:44:57 | 00,888,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kernel32.dll
[2009/04/15 08:44:56 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll
[2009/04/15 08:44:56 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amxread.dll
[2009/04/15 08:44:56 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\apilogen.dll
[2009/04/15 08:44:52 | 03,580,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/04/15 08:44:50 | 06,068,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/04/15 08:44:50 | 01,166,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/04/15 08:44:49 | 00,827,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/04/15 08:44:49 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/04/15 08:44:48 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/04/15 08:44:48 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/04/15 08:44:48 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2009/04/15 08:44:48 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/04/15 08:44:48 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/04/15 08:44:47 | 01,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/04/15 08:44:47 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/04/15 08:44:47 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2009/04/15 08:44:47 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll
[2009/04/15 08:44:47 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/04/12 16:02:57 | 01,044,480 | ---- | C] (eHelp Corporation.) -- C:\Windows\System32\ROBOEX32.DLL
[2009/04/12 16:02:57 | 00,000,000 | ---D | C] -- C:\Program Files\DesignPro
[2009/04/09 21:44:04 | 00,000,000 | ---D | C] -- C:\Users\Steve\AppData\Roaming\Google
[2009/04/08 16:26:15 | 15,066,05056 | ---- | C] () -- C:\Users\Steve\Desktop\HanaYoriDango_Final.avi
[2009/04/08 00:13:42 | 00,000,880 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachine.job
[2009/04/08 00:13:29 | 00,000,000 | ---D | C] -- C:\Users\Steve\AppData\Local\Google
[2009/04/08 00:13:11 | 00,000,000 | ---D | C] -- C:\ProgramData\Google Updater
[2009/04/08 00:13:10 | 00,000,868 | ---- | C] () -- C:\Windows\tasks\Google Software Updater.job
[2009/04/08 00:13:09 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/04/05 02:37:42 | 00,000,000 | ---D | C] -- C:\Program Files\KeyHoleTV
[2009/04/05 00:53:10 | 00,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2009/03/13 15:29:14 | 00,000,023 | ---- | C] () -- C:\Windows\VBCTL3D.INI
[2009/03/13 15:27:47 | 00,581,872 | ---- | C] () -- C:\Windows\System32\wodCertificate.dll
[2009/03/13 15:27:37 | 00,631,768 | ---- | C] () -- C:\Windows\System32\brgrt.dll
[2009/03/08 00:01:47 | 00,000,000 | ---- | C] () -- C:\Windows\vstudio.INI
[2009/03/07 23:45:43 | 00,000,906 | ---- | C] () -- C:\Windows\Ulead32.ini
[2009/03/07 23:45:43 | 00,000,259 | ---- | C] () -- C:\Windows\vidwiz.ini
[2009/03/07 23:45:43 | 00,000,026 | ---- | C] () -- C:\Windows\dswplug.ini
[2009/03/07 23:45:43 | 00,000,011 | ---- | C] () -- C:\Windows\Msdevctl.ini
[2009/03/05 00:39:26 | 00,176,235 | ---- | C] () -- C:\Windows\System32\Primomonnt.dll
[2009/03/04 23:25:22 | 00,000,158 | ---- | C] () -- C:\Windows\matlab.ini
[2009/02/28 17:19:33 | 00,237,568 | ---- | C] () -- C:\Windows\System32\rmc_rtspdl.dll
[2009/02/28 15:37:43 | 00,004,468 | ---- | C] () -- C:\Windows\cool.ini
[2009/02/28 10:33:03 | 00,081,110 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2009/02/28 02:09:13 | 00,000,165 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2009/02/28 01:48:00 | 00,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/28 00:12:39 | 00,303,104 | ---- | C] () -- C:\Windows\System32\lxcrcoin.dll
[2009/02/28 00:11:06 | 00,040,960 | ---- | C] () -- C:\Windows\System32\LXPRMON.DLL
[2009/02/28 00:11:06 | 00,032,768 | ---- | C] () -- C:\Windows\System32\LXPMONUI.DLL
[2009/02/28 00:10:12 | 01,183,744 | ---- | C] ( ) -- C:\Windows\System32\lxcrserv.dll
[2009/02/28 00:10:12 | 00,995,328 | ---- | C] ( ) -- C:\Windows\System32\lxcrusb1.dll
[2009/02/28 00:10:12 | 00,233,472 | ---- | C] () -- C:\Windows\System32\LXCRinst.dll
[2009/02/28 00:10:11 | 00,536,576 | ---- | C] ( ) -- C:\Windows\System32\lxcrlmpm.dll
[2009/02/28 00:10:11 | 00,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxcrprox.dll
[2009/02/28 00:10:11 | 00,114,688 | ---- | C] ( ) -- C:\Windows\System32\lxcrpplc.dll
[2009/02/28 00:10:10 | 00,610,304 | ---- | C] ( ) -- C:\Windows\System32\lxcrcomc.dll
[2009/02/28 00:10:10 | 00,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxcrcomm.dll
[2009/02/27 23:50:41 | 00,532,544 | ---- | C] () -- C:\Windows\PIC.dll
[2009/02/27 23:50:41 | 00,024,576 | ---- | C] () -- C:\Windows\HKNTDLL.dll
[2009/02/04 05:00:08 | 00,011,264 | ---- | C] () -- C:\Windows\System32\atimuixx.dll
[2009/01/13 19:39:06 | 00,072,992 | ---- | C] () -- C:\Windows\System32\drivers\bckd.sys
[2008/12/16 22:58:54 | 00,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2008/12/16 22:50:56 | 00,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLgFT.dll
[2008/11/06 12:37:32 | 03,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\Windows\System32\dtu100.dll.manifest
[2008/11/06 12:34:00 | 00,000,416 | ---- | C] () -- C:\Windows\System32\dpl100.dll.manifest
[2008/11/06 12:33:02 | 00,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008/06/18 14:59:56 | 00,007,680 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2008/04/28 13:13:33 | 00,000,310 | ---- | C] () -- C:\Windows\primopdf.ini
[2007/06/23 04:44:50 | 00,009,760 | ---- | C] () -- C:\Windows\System32\34CoInstaller.dll
[2007/02/05 21:05:26 | 00,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006/11/22 15:16:18 | 00,003,612 | ---- | C] () -- C:\Windows\ReaderString.ini
[2006/11/21 11:50:06 | 00,000,037 | ---- | C] () -- C:\Windows\sunkist.ini
[2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/02/02 23:01:44 | 00,393,216 | ---- | C] ( ) -- C:\Windows\System32\lxcriesc.dll
[2006/02/02 22:59:12 | 00,409,600 | ---- | C] ( ) -- C:\Windows\System32\lxcrinpa.dll
[2006/01/23 02:43:48 | 00,065,536 | ---- | C] () -- C:\Windows\System32\lxcrcaps.dll
[2006/01/22 13:47:36 | 00,684,032 | ---- | C] () -- C:\Windows\System32\lxcrdrs.dll
[2005/12/20 12:54:04 | 00,061,440 | ---- | C] () -- C:\Windows\System32\lxcrcnv4.dll
[2005/07/08 04:11:22 | 00,040,960 | ---- | C] () -- C:\Windows\System32\lxcrvs.dll
[2005/01/03 12:10:44 | 00,319,488 | ---- | C] () -- C:\Windows\System32\DLXAPI32.DLL
========== Files - Modified Within 30 Days ==========
[3 C:\Windows\*.tmp files]
[2009/04/18 22:30:38 | 00,704,434 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/04/18 22:30:38 | 00,595,748 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/04/18 22:30:38 | 00,105,078 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/04/18 22:26:38 | 00,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/18 22:25:50 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2009/04/18 22:23:14 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/18 22:23:14 | 00,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/18 22:23:12 | 00,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachine.job
[2009/04/18 22:23:11 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/04/18 22:23:09 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/04/18 22:23:05 | 00,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2009/04/18 22:22:00 | 02,389,464 | -H-- | M] () -- C:\Users\Steve\AppData\Local\IconCache.db
[2009/04/18 22:19:36 | 00,081,984 | ---- | M] () -- C:\Windows\System32\bdod.bin
[2009/04/18 22:15:27 | 00,000,733 | ---- | M] () -- C:\Users\Steve\Desktop\NTREGOPT.lnk
[2009/04/18 22:15:27 | 00,000,714 | ---- | M] () -- C:\Users\Steve\Desktop\ERUNT.lnk
[2009/04/18 21:36:03 | 00,000,680 | ---- | M] () -- C:\Users\Steve\AppData\Local\d3d9caps.dat
[2009/04/18 17:52:12 | 00,001,874 | ---- | M] () -- C:\Users\Steve\Desktop\HijackThis.lnk
[2009/04/18 17:20:44 | 00,000,850 | ---- | M] () -- C:\Windows\System32\ProductTweaks.xml
[2009/04/18 17:20:44 | 00,000,385 | ---- | M] () -- C:\Windows\System32\user_gensett.xml
[2009/04/18 12:09:28 | 00,006,545 | ---- | M] () -- C:\Users\Steve\AppData\Roaming\PrimoPDFSet.xml
[2009/04/18 09:31:16 | 21,928,7319 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2009/04/15 21:03:44 | 01,454,626 | ---- | M] () -- C:\Users\Steve\Desktop\2008IR22.pdf
[2009/04/15 21:03:33 | 00,107,503 | ---- | M] () -- C:\Users\Steve\Desktop\2008IR22__INST.pdf
[2009/04/14 00:12:10 | 00,082,944 | ---- | M] () -- C:\Users\Steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/13 14:52:14 | 00,016,640 | ---- | M] (Wondershare) -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys
[2009/04/13 08:36:33 | 01,642,424 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/04/12 16:31:20 | 00,076,512 | ---- | M] () -- C:\Users\Steve\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/04/12 16:06:05 | 00,682,197 | ---- | M] () -- C:\Users\Steve\Documents\Campus Cops.ncor
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/03/30 22:26:25 | 00,073,376 | ---- | M] () -- C:\Users\Steve\AppData\Roaming\GDIPFONTCACHEV1.DAT
< End of report >
Extras.txt
OTListIt Extras logfile created on: 4/18/2009 10:29:23 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Steve\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.38 Gb Total Space | 113.28 Gb Free Space | 39.28% Space Free | Partition Type: NTFS
Drive D: | 9.71 Gb Total Space | 4.34 Gb Free Space | 44.68% Space Free | Partition Type: NTFS
Drive E: | 2.59 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: COMPY
Current User Name: Steve
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla\Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F28237D-8AA8-45A5-86CF-F771BFD47EF7}" = Catalyst Control Center Core Implementation
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13
"{2CC982C0-7EAE-11D4-ACC3-0050568AD318}" = Avery DesignPro
"{32A3A4F4-B792-11D6-A78A-00B0D0160120}" = Java SE Development Kit 6 Update 12
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{42705D0C-0DF6-804C-D718-57C53F733C32}" = ccc-utility
"{43545ABC-41F6-40E2-B0FF-B4735003A7CC}" = Catalyst Control Center Graphics Full Existing
"{45A8F574-2F1C-3696-B803-746965390DBB}" = Catalyst Control Center HydraVision Full
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{53EF6570-21A4-47ED-A40A-E6470A5677A3}" = Studio 8
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{548EAC70-EE00-11DD-908C-005056806466}" = Google Earth
"{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{6395D480-9F3B-4930-8204-B91C8882F967}" = Stata 10
"{6772B9B1-ACAE-ECF8-9C6F-DAD5A3C1A001}" = Skins
"{68CC21AD-B6EC-4DB8-954D-F27AD0D9A83F}" = TV Expert
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7066F2DB-5032-4B6F-A8E7-A6F946043438}" = Adobe Setup
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7DD0FFB0-387C-EF62-1591-41C05FE60642}" = Catalyst Control Center Graphics Previews Common
"{7E1B2F63-CB3E-F73A-AE05-CD452BB23023}" = ATI Catalyst Install Manager
"{80E8BC6A-5061-0188-A628-6DD17A5ED0A2}" = Catalyst Control Center InstallProxy
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90D43604-FAC9-62BD-186C-6F5692CBD48E}" = Catalyst Control Center Graphics Previews Vista
"{90D4CD58-6CA9-2B7E-21FF-1145A9E3A1DD}" = ccc-core-static
"{930B2432-43D4-11D5-9871-00C04F8EEB39}" = Macromedia Fireworks MX
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A638557B-1F13-40A0-9627-C892FBCA6960}" = McAfee Agent
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1041-7B44-A91000000001}" = Adobe Reader 9.1 - Japanese
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}" = PixiePack Codec Pack
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BB81360F-041C-4CF7-B15E-71380D154244}" = Adobe Setup
"{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CABD1344-150F-8A13-FE4F-64D18C6962AD}" = Catalyst Control Center Graphics Full New
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD3E2AB0-305C-84D6-4C6E-20BFC33C3ECA}" = Catalyst Control Center Graphics Light
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{D5C92012-A0A0-53E1-4A18-8DCC4463CA34}" = CCC Help English
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E24A7D40-D12E-4A11-8DEC-7BB21BE4614D}" = Wolfram Notebook Indexer 1.1
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"{F1D93F5B-881F-49E3-BA56-B4B8FA991059}" = Adobe Encore CS3 Library
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FC10C290-6E4D-4C6B-A8B3-33700C21F9E6}" = Mathematica 5.2 for Students
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = PS2 Multimedia Keyboard Driver
"{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_32fdd767b4383606e8168e834af5d90" = Adobe Premiere Pro CS3
"Adobe_54503dca4c8f2a99b3c8c810699cd75" = Adobe Encore CS3
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"Aspell" = Aspell Data
"Aspell6-Dictionary-en" = Aspell 0.6 Dictionary (Language: en)
"Avidemux 2.4" = Avidemux 2.4
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Blue Coat K9 Web Protection" = Blue Coat® K9 Web Protection 4.0.288
"BREE5" = Brownstone Equation Editor 5
"camcodec" = CamStudio Lossless Codec
"CamStudio" = CamStudio
"Collectorz.com Book Collector" = Collectorz.com Book Collector
"Cool Edit 96" = Cool Edit 96
"Core FTP LE 1.3c" = Core FTP LE 1.3c
"Diploma" = Diploma
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ERUNT_is1" = ERUNT 1.1j
"ffdshow_is1" = ffdshow [rev 2744] [2009-03-05]
"Google Updater" = Google Updater
"Gradebook" = Gradebook
"GSview 4.9" = GSview 4.9
"HijackThis" = HijackThis 2.0.2
"HUFFYUV" = Huffyuv AVI lossless video codec (Remove Only)
"ImTOO AVI MPEG Converter" = ImTOO AVI MPEG Converter
"InstallShield_{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"InstallShield_{FC10C290-6E4D-4C6B-A8B3-33700C21F9E6}" = Mathematica 5.2 for Students
"InstallShield_{FFB278E6-2945-4FF0-8F3F-268CDD09FCF6}" = Adobe OnLocation CS3
"KeyHoleTV" = KeyHoleTV
"Lexmark 2400 Series" = Lexmark 2400 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"LyX" = LyX 1.6.1-1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabR2007a" = MATLAB R2007a
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MiKTeX 2.7" = MiKTeX 2.7
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"Mozilla Thunderbird (2.0.0.21)" = Mozilla Thunderbird (2.0.0.21)
"PrimoPDF4.1.0.9" = PrimoPDF
"PROSet" = Intel® PRO Network Connections Drivers
"SHAZAM Standard Edition" = SHAZAM Standard Edition
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SubtitleWorkshop" = Subtitle Workshop 2.51
"TeXnicCenter_is1" = TeXnicCenter Version 1.0 Stable RC1
"V CAST Music with Rhapsody" = V CAST Music with Rhapsody
"WinRAR archiver" = WinRAR archiver
"XEmacs_is1" = XEmacs 21.4.21
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/18/2009 7:00:46 PM | Computer Name = COMPY | Source = McLogEvent | ID = 5004
Description = Could not contact Filter Driver. Error = 0x7d1 : The specified driver
is invalid.
Error - 4/18/2009 7:04:27 PM | Computer Name = COMPY | Source = EventSystem | ID = 4609
Description =
Error - 4/18/2009 7:07:04 PM | Computer Name = COMPY | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module CEVideoEncoder.dll, version 1.7.13.7301, time stamp
0x45e6b50a, exception code 0xc0000005, fault offset 0x0000cc1e, process id 0x65c,
application start time 0x01c9c07a4b385d45.
Error - 4/18/2009 10:13:49 PM | Computer Name = COMPY | Source = McLogEvent | ID = 5004
Description = Could not contact Filter Driver. Error = 0x7d1 : The specified driver
is invalid.
Error - 4/18/2009 10:17:20 PM | Computer Name = COMPY | Source = SPP | ID = 16387
Description =
Error - 4/18/2009 10:17:20 PM | Computer Name = COMPY | Source = System Restore | ID = 8193
Description =
Error - 4/18/2009 10:19:30 PM | Computer Name = COMPY | Source = SPP | ID = 16387
Description =
Error - 4/18/2009 10:19:30 PM | Computer Name = COMPY | Source = System Restore | ID = 8193
Description =
Error - 4/18/2009 10:21:28 PM | Computer Name = COMPY | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.36.0.0, time stamp 0x2a425e19,
faulting module mbam.exe, version 1.36.0.0, time stamp 0x2a425e19, exception code
0x80000003, fault offset 0x00009a94, process id 0xbdc, application start time 0x01c9c0958ba22e8a.
Error - 4/18/2009 10:23:40 PM | Computer Name = COMPY | Source = McLogEvent | ID = 5004
Description = Could not contact Filter Driver. Error = 0x7d1 : The specified driver
is invalid.
[ Media Center Events ]
Error - 3/2/2009 1:14:08 AM | Computer Name = COMPY | Source = ehRecvr | ID = 4
Description =
Error - 3/5/2009 9:00:41 PM | Computer Name = COMPY | Source = ehRecvr | ID = 3
Description =
[ System Events ]
Error - 4/18/2009 7:04:32 PM | Computer Name = COMPY | Source = DCOM | ID = 10005
Description =
Error - 4/18/2009 7:05:04 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7001
Description =
Error - 4/18/2009 7:05:04 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7001
Description =
Error - 4/18/2009 7:05:04 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7001
Description =
Error - 4/18/2009 7:05:04 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7026
Description =
Error - 4/18/2009 10:13:26 PM | Computer Name = COMPY | Source = HTTP | ID = 15016
Description =
Error - 4/18/2009 10:14:58 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7000
Description =
Error - 4/18/2009 10:20:07 PM | Computer Name = COMPY | Source = DCOM | ID = 10010
Description =
Error - 4/18/2009 10:23:11 PM | Computer Name = COMPY | Source = HTTP | ID = 15016
Description =
Error - 4/18/2009 10:24:48 PM | Computer Name = COMPY | Source = Service Control Manager | ID = 7000
Description =
< End of report >
Edited by stekun, 19 April 2009 - 12:26 PM.