Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4290
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2010-07-07 18:51:09
mbam-log-2010-07-07 (18-51-09).txt
Scan type: Quick scan
Objects scanned: 134110
Time elapsed: 9 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-07 20:01:13
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mark\LOCALS~1\Temp\kxtdypoc.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xF5D16950]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF8007360, 0x24BB1D, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Webroot\Washer\WasherSvc.exe[288] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0008ED99 C:\Program Files\Webroot\Washer\WasherSvc.exe (Window Washer Engine/Webroot Software, Inc.)
.text C:\Program Files\Webroot\Washer\wwDisp.exe[2228] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0008F31D C:\Program Files\Webroot\Washer\wwDisp.exe (Window Washer Client Executable/Webroot Software, Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\FrontPage.Application@ Microsoft FrontPage Application
Reg HKLM\SOFTWARE\Classes\FrontPage.Application\CLSID
Reg HKLM\SOFTWARE\Classes\FrontPage.Application\CLSID@ {04DF1015-7007-11D1-83BC-006097ABE675}
Reg HKLM\SOFTWARE\Classes\FrontPage.Application\CurVer
Reg HKLM\SOFTWARE\Classes\FrontPage.Application\CurVer@ FrontPage.Application.4
---- EOF - GMER 1.0.15 ----
OTL logfile created on: 2010-07-07 20:03:58 - Run 1
OTL by OldTimer - Version 3.2.8.0 Folder = C:\Documents and Settings\Mark\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: | Country: | Language: | Date Format: yyyy-MM-dd
511.00 Mb Total Physical Memory | 208.00 Mb Available Physical Memory | 41.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 13.75 Gb Free Space | 36.91% Space Free | Partition Type: NTFS
Unable to calculate disk information.
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MARK-0
Current User Name: Mark
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010-07-07 20:01:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTL.exe
PRC - [2010-05-21 22:10:16 | 002,017,280 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010-03-26 11:16:04 | 000,093,320 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009-03-05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008-04-13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007-11-26 15:47:40 | 000,598,856 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Washer\WasherSvc.exe
PRC - [2007-11-26 15:47:30 | 001,206,600 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Washer\wwDisp.exe
PRC - [2007-03-19 08:58:47 | 000,537,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxctcoms.exe
PRC - [2007-03-19 08:58:20 | 000,082,864 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 5400 Series\ezprint.exe
PRC - [2007-03-19 08:58:17 | 000,291,760 | ---- | M] () -- C:\Program Files\Lexmark 5400 Series\lxctmon.exe
PRC - [2006-09-01 11:00:00 | 000,122,880 | ---- | M] (WinZip Computing LP) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2006-05-15 18:24:33 | 000,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2002-07-30 11:36:00 | 000,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
PRC - [2002-07-30 11:35:04 | 000,077,824 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
PRC - [2002-04-12 05:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brsvc01a.exe
PRC - [2001-12-13 05:01:00 | 000,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brss01a.exe
PRC - [2001-08-17 18:36:42 | 000,024,064 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\devldr32.exe
========== Modules (SafeList) ==========
MOD - [2010-07-07 20:01:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTL.exe
MOD - [2010-04-01 09:57:36 | 000,015,056 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2008-04-13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe -- (stllssvr)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\TEMP\004422~1.EXE -- (0044221272328183mcinstcleanup) McAfee Application Installer Cleanup (0044221272328183)
SRV - [2010-03-26 11:16:04 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2007-11-26 15:47:40 | 000,598,856 | ---- | M] (Webroot Software, Inc.) [Auto | Running] -- C:\Program Files\Webroot\Washer\WasherSvc.exe -- (wwEngineSvc)
SRV - [2007-03-19 08:58:47 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxctcoms.exe -- (lxct_device)
SRV - [2006-05-15 18:24:33 | 002,086,592 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
SRV - [2006-05-15 18:24:33 | 000,100,032 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2005-08-30 15:00:50 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2005-08-30 14:55:18 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2005-08-30 14:49:34 | 000,069,718 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2002-07-30 11:40:44 | 000,573,440 | ---- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe -- (Norton AntiVirus Server)
SRV - [2002-07-30 11:36:00 | 000,032,768 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2002-04-12 05:00:00 | 000,057,344 | ---- | M] (brother Industries Ltd) [Auto | Running] -- C:\WINDOWS\system32\brsvc01a.exe -- (Brother XP spl Service)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\PsSdk23.drv -- (PSSdk23)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\LV302AV.SYS -- (PID_08A0) QuickCam IM(PID_08A0)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lv302af.sys -- (pepifilter)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\Lvckap.sys -- (Lvckap)
DRV - File not found [File_System | Boot | Stopped] -- C:\WINDOWS\System32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010-05-28 04:00:00 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100528.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2010-05-28 04:00:00 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100528.002\NAVENG.SYS -- (NAVENG)
DRV - [2010-05-21 22:10:16 | 000,068,168 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010-04-01 17:59:44 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010-04-01 17:59:44 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2008-04-13 14:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008-04-13 14:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008-04-13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-04-13 14:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008-04-13 14:36:41 | 000,063,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mf.sys -- (mf)
DRV - [2007-07-19 00:44:02 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007-07-19 00:39:16 | 001,278,104 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2006-10-22 12:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006-10-06 17:34:14 | 000,073,224 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2005-04-25 12:10:20 | 000,033,538 | ---- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Capt905c.sys -- (SQTECH905C)
DRV - [2003-09-25 22:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\GTNDIS5.sys -- (GTNDIS5)
DRV - [2003-03-14 05:04:20 | 000,061,952 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrSerWdm.sys -- (BrSerWDM)
DRV - [2002-06-19 20:57:14 | 000,029,184 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys -- (NAVAPEL)
DRV - [2002-06-19 20:57:12 | 000,218,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys -- (NAVAP)
DRV - [2001-08-17 15:12:22 | 000,010,368 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrUsbScn.sys -- (BrUsbScn)
DRV - [2001-08-17 15:12:20 | 000,011,008 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2001-08-17 15:12:12 | 000,002,944 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrFilt.sys -- (brfilt)
DRV - [2001-08-17 09:49:32 | 000,019,968 | ---- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mxnic.sys -- (mxnic)
DRV - [2001-08-17 09:28:02 | 000,907,456 | ---- | M] (Conexant) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys -- (HCF_MSFT)
DRV - [2001-08-17 08:19:34 | 000,036,480 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sfmanm.sys -- (sfman) Creative SoundFont Manager Driver (WDM)
DRV - [2001-08-17 08:19:28 | 000,006,912 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctlfacem.sys -- (emu10k1) Creative Interface Manager Driver (WDM)
DRV - [2001-08-17 08:19:26 | 000,283,904 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emu10k1m.sys -- (emu10k) Creative SB Live! (WDM)
DRV - [2001-08-17 08:19:20 | 000,003,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk)
DRV - [2001-01-02 23:53:30 | 000,019,677 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xbreader.sys -- (xbreader) MaxDrive XBox Driver (xbreader.sys)
DRV - [1999-09-10 07:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapp...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.co...-8&oe=UTF-8&q="
FF - prefs.js..browser.startup.homepage: "http://www.msn.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {dd3d7613-0246-469d-bc65-2a3cc1668adc}:0.7.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.1
FF - prefs.js..extensions.enabledItems: {27a03cf3-856f-46b8-91cb-7289f58c7e6e}:1.314
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.99
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010-06-04 20:38:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-07-07 15:35:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-07-07 15:35:10 | 000,000,000 | ---D | M]
[2008-10-21 07:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Mozilla\Extensions
[2010-07-07 18:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions
[2010-07-07 15:29:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}(2)
[2008-10-21 07:26:00 | 000,000,000 | ---D | M] (Finjan Secure Browsing) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{27a03cf3-856f-46b8-91cb-7289f58c7e6e}
[2010-07-07 18:23:14 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010-07-07 15:29:34 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2010-07-07 15:29:36 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2008-04-12 03:37:03 | 000,000,000 | ---D | M] (Fasterfox) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a66}
[2010-07-07 18:22:32 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010-07-07 15:29:34 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2)
[2010-07-07 18:21:36 | 000,000,000 | ---D | M] (BlockSite) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2010-07-07 15:29:35 | 000,000,000 | ---D | M] (BlockSite) -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}(2)
[2009-12-25 13:26:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\extensions\[email protected]
[2008-04-13 19:33:45 | 000,002,386 | ---- | M] () -- C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\t4gi9ylk.default\searchplugins\siteadvisor.xml
[2010-07-07 18:22:39 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007-11-28 16:55:19 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010-04-25 23:59:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-04-25 23:58:49 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2008-10-22 15:01:13 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 5400 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [Lexmark 5400 Series Fax Server] C:\Program Files\Lexmark 5400 Series\fm3032.exe ()
O4 - HKLM..\Run: [LXCTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxctmon.exe] C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing LP)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com...ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} http://musicmix.mess.../Medialogic.CAB (CMediaMix Object)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by140fd.bay14...es/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/b...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemreq.../sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zon...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} http://swgbetareg.st.../soesysinfo.cab (SOESysInfo Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zon...ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} http://gamedownload....GPlugin9USA.cab (HGPlugin9USA Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (hsaahdv.exe) - File not found
O20 - HKLM Winlogon: UserInit - (ddjfihw.exe) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Mark\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mark\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\WINDOWS\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 90 Days ==========
[2010-07-07 20:01:33 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTL.exe
[2010-07-07 18:31:26 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-07-07 18:31:22 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-07-07 18:30:52 | 006,153,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark\Desktop\mbam-setup.exe
[2010-07-07 18:30:15 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\TFC.exe
[2010-07-05 18:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010-07-05 17:05:50 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-04-15 09:45:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2008-01-21 20:18:49 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctinpa.dll
[2008-01-21 20:18:49 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\LXCThcp.dll
[2008-01-21 20:18:48 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctiesc.dll
[2008-01-21 20:18:47 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctserv.dll
[2008-01-21 20:18:47 | 000,991,232 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctusb1.dll
[2008-01-21 20:18:47 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctprox.dll
[2008-01-21 20:18:46 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpmui.dll
[2008-01-21 20:18:46 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctlmpm.dll
[2008-01-21 20:18:46 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpplc.dll
[2008-01-21 20:18:44 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcthbn3.dll
[2008-01-21 20:18:42 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomc.dll
[2008-01-21 20:18:42 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomm.dll
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010-07-07 20:01:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTL.exe
[2010-07-07 18:55:06 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-07-07 18:55:03 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-07-07 18:53:48 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-07-07 18:53:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-07-07 18:52:20 | 007,856,128 | ---- | M] () -- C:\Documents and Settings\Mark\ntuser.dat
[2010-07-07 18:52:20 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Mark\ntuser.ini
[2010-07-07 18:52:13 | 006,389,182 | -H-- | M] () -- C:\Documents and Settings\Mark\Local Settings\Application Data\IconCache.db
[2010-07-07 18:31:29 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-07-07 18:30:58 | 006,153,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark\Desktop\mbam-setup.exe
[2010-07-07 18:30:16 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\TFC.exe
[2010-07-07 15:37:39 | 000,153,176 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-07-07 13:53:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010-06-27 23:05:17 | 000,060,702 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\17869_292487092188_525562188_4522587_3814356_n.jpg
[2010-06-23 03:09:00 | 000,441,432 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-06-23 03:09:00 | 000,071,176 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-06-13 23:17:40 | 000,321,876 | ---- | M] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Phase Three.mht
[2010-06-13 23:15:54 | 000,139,400 | ---- | M] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Food List for Phase 2.mht
[2010-06-13 23:15:12 | 000,132,623 | ---- | M] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Food List for Phase 1.mht
[2010-06-13 22:29:02 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Mark\My Documents\Benifits of Speaking In Tongues!.doc
[2010-06-12 03:26:42 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010-05-31 19:35:15 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010-05-09 16:42:44 | 000,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-04-29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-04-29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-04-25 04:07:57 | 000,029,696 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\Name Jacob Ryan Church.doc
[2010-04-22 22:56:07 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\Mark\My Documents\Name Jacob Ryan Church.doc
[2010-04-21 05:58:11 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\In House Dog Training Contract.doc
[2010-04-14 22:44:28 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mark\Application Data\index.html
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010-07-07 18:31:29 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-06-27 23:05:14 | 000,060,702 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\17869_292487092188_525562188_4522587_3814356_n.jpg
[2010-06-13 23:17:40 | 000,321,876 | ---- | C] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Phase Three.mht
[2010-06-13 23:15:53 | 000,139,400 | ---- | C] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Food List for Phase 2.mht
[2010-06-13 23:15:09 | 000,132,623 | ---- | C] () -- C:\Documents and Settings\Mark\My Documents\South Beach Diet Food List for Phase 1.mht
[2010-06-01 10:43:26 | 007,856,128 | ---- | C] () -- C:\Documents and Settings\Mark\ntuser.dat
[2010-04-22 22:58:22 | 000,029,696 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\Name Jacob Ryan Church.doc
[2010-04-21 19:45:14 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\Mark\My Documents\Name Jacob Ryan Church.doc
[2010-04-14 22:44:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mark\Application Data\index.html
[2010-04-13 15:10:35 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\In House Dog Training Contract.doc
[2008-07-20 14:52:30 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2008-02-11 09:39:26 | 000,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008-02-11 09:39:18 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008-02-08 13:53:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
[2008-01-21 20:29:14 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxctvs.dll
[2008-01-21 20:29:10 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\lxctcoin.dll
[2008-01-21 20:28:27 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxctdrs.dll
[2008-01-21 20:28:27 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxctcaps.dll
[2008-01-21 20:28:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxctcnv4.dll
[2008-01-21 20:27:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lxctpmon.dll
[2008-01-21 20:27:22 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXCTFXPU.DLL
[2008-01-21 20:18:49 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\LXCTinst.dll
[2008-01-21 20:18:44 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\lxctgrd.dll
[2008-01-09 15:01:48 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007-12-29 20:14:23 | 000,000,084 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini
[2007-08-13 17:33:32 | 000,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
[2007-07-27 14:49:02 | 000,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
[2007-07-27 14:49:02 | 000,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
[2007-07-20 17:38:46 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2007-07-20 17:38:45 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007-07-20 17:38:45 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007-07-20 17:38:45 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2007-07-18 23:54:18 | 000,058,163 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007-07-14 06:45:33 | 000,000,032 | ---- | C] () -- C:\WINDOWS\tdlp32.ini
[2007-07-14 06:37:16 | 000,000,032 | ---- | C] () -- C:\WINDOWS\ampl32.ini
[2007-04-28 11:58:25 | 000,000,519 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007-04-07 20:17:06 | 000,000,051 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI
[2007-03-12 16:44:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006-10-22 12:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-10-22 12:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-10-22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-10-22 12:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-10-22 12:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006-10-07 13:14:28 | 000,001,005 | ---- | C] () -- C:\WINDOWS\DVDFabGold.INI
[2006-10-07 11:51:20 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006-10-06 18:23:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2006-06-16 00:34:30 | 000,000,214 | ---- | C] () -- C:\WINDOWS\CS_MD_T.ini
[2006-03-08 16:12:23 | 000,000,480 | ---- | C] () -- C:\WINDOWS\ytite.dll
[2006-03-08 14:34:56 | 000,000,611 | ---- | C] () -- C:\WINDOWS\fijyn.dll
[2006-03-06 18:03:50 | 000,000,059 | ---- | C] () -- C:\WINDOWS\XUnleashed.ini
[2005-12-29 15:54:59 | 000,002,158 | ---- | C] () -- C:\WINDOWS\System32\tmmute.ini
[2005-12-05 19:25:22 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
[2005-12-05 12:37:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
[2005-08-11 16:57:53 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005-07-30 01:51:14 | 000,009,738 | ---- | C] () -- C:\WINDOWS\cfgmgr52.ini
[2005-07-30 01:27:18 | 000,000,045 | ---- | C] () -- C:\WINDOWS\AHDDGIN.ini
[2004-12-14 11:20:59 | 000,000,463 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2004-12-14 11:20:59 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2004-12-14 11:20:59 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2004-12-14 11:20:31 | 000,002,188 | ---- | C] () -- C:\WINDOWS\BRMFBIDI.INI
[2004-09-22 23:35:17 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003-07-28 15:19:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2003-07-28 15:19:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2002-09-05 16:12:26 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\X3Dview.dll
[2002-07-30 11:33:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[1999-07-23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999-07-23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999-01-27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1999-01-22 14:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1997-06-13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2008-01-21 20:26:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\5400 Series
[2006-10-06 17:28:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2007-05-15 16:47:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2006-10-10 18:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2007-07-20 00:48:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2008-02-12 07:03:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sony
[2006-03-04 17:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009-07-12 17:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008-07-28 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Walgreens
[2007-02-09 18:08:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2006-11-02 18:17:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\~0
[2009-03-02 13:15:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\5400 Series
[2005-12-28 11:45:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Aim
[2009-08-27 15:06:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\ICAClient
[2009-11-21 14:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\MoveFab
[2008-05-08 11:31:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\MP3Rocket
[2006-11-02 18:45:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\MSNInstaller
[2006-11-02 18:13:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Seven Zip
[2008-02-12 19:05:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Sony
[2010-02-23 03:16:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\SystemRequirementsLab
[2006-03-06 02:42:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Ulead Systems
[2009-08-16 13:00:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Vso
[2010-01-02 00:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\W Photo Studio
[2008-07-28 16:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\W Photo Studio Viewer
[2008-07-28 16:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mark\Application Data\Walgreens
[2010-07-07 13:53:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009-07-16 09:11:03 | 000,005,754 | ---- | M] () -- C:\aaw7boot.log
[2007-09-20 05:56:24 | 002,066,944 | ---- | M] () -- C:\AppleSoftwareUpdate.msi
[2005-08-03 11:24:28 | 001,852,554 | RHS- | M] () -- C:\avg7db_f.dat.install_backup
[2005-08-03 10:41:13 | 012,283,633 | ---- | M] () -- C:\avg7qt.dat.install_backup
[2007-07-20 17:43:12 | 000,015,970 | ---- | M] () -- C:\avi_log.txt
[2006-10-06 17:12:52 | 000,000,210 | ---- | M] () -- C:\Boot.bak
[2008-10-21 13:11:06 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004-12-17 02:08:02 | 000,033,280 | ---- | M] () -- C:\chapter_8_section_1.doc
[2004-08-03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2004-09-21 13:21:40 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009-08-16 12:47:29 | 012,709,616 | ---- | M] (Fengtao Software Inc. ) -- C:\DVDFab6040.exe
[2007-07-20 00:35:03 | 000,018,224 | ---- | M] () -- C:\dvdfabexpress_burn.log
[2008-03-08 15:07:55 | 000,038,171 | ---- | M] () -- C:\dvdfab_burn.log
[2009-03-02 13:15:09 | 000,000,000 | ---- | M] () -- C:\faxendPdoc.log
[2005-06-20 04:03:34 | 000,000,185 | ---- | M] () -- C:\Install.log
[2004-09-21 13:21:40 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2005-12-24 17:07:40 | 000,000,497 | -H-- | M] () -- C:\IPH.PH
[2008-10-24 10:28:38 | 000,009,267 | ---- | M] () -- C:\JavaRa.log
[2006-10-12 17:24:00 | 000,001,415 | ---- | M] () -- C:\log.txt
[2007-07-29 17:51:18 | 000,002,371 | ---- | M] () -- C:\logfile
[2010-04-01 04:55:22 | 000,000,147 | ---- | M] () -- C:\lxct.log
[2004-09-21 13:21:40 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-04 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008-08-08 11:10:31 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010-07-07 18:53:35 | 803,753,984 | -HS- | M] () -- C:\pagefile.sys
[2006-10-06 17:34:15 | 000,016,846 | ---- | M] () -- C:\PkgClnup.log
[2004-09-25 14:21:46 | 006,811,656 | ---- | M] (Adobe Systems, Inc. ) -- C:\psa201se_us.exe
[2007-07-20 00:48:51 | 000,000,056 | -HS- | M] () -- C:\redir.sys
[2005-10-13 08:52:02 | 000,002,292 | ---- | M] () -- C:\Rescued document.txt
[2004-12-17 02:08:43 | 000,020,992 | ---- | M] () -- C:\Science is an organized way of using evidence to learn about the natural world.doc
[2006-03-16 16:38:55 | 000,000,367 | ---- | M] () -- C:\session.log
[2008-01-29 03:41:15 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008-01-29 03:42:03 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008-01-29 03:43:49 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2008-01-30 09:17:07 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2008-01-30 22:06:00 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2008-01-31 07:34:20 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2008-01-31 07:34:43 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2008-01-31 07:34:59 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2008-02-01 10:59:28 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2008-02-01 11:00:00 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2008-02-01 11:00:19 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2008-02-01 11:04:59 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2008-02-02 10:51:20 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008-02-02 10:51:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008-02-02 10:55:24 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008-02-02 10:56:01 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008-02-02 10:56:33 | 000,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2008-01-29 03:38:52 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008-01-29 03:39:23 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008-01-29 03:40:46 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008-01-29 03:41:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008-01-29 03:42:03 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008-01-29 03:43:49 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2008-01-30 09:17:07 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2008-01-30 22:06:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2008-01-31 07:34:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2008-01-31 07:34:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2008-01-31 07:34:59 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2008-02-01 10:59:27 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2008-02-01 11:00:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2008-02-01 11:00:19 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2008-02-01 11:04:59 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2008-02-02 10:51:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008-02-02 10:51:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008-02-02 10:55:24 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008-02-02 10:56:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008-02-02 10:56:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008-01-29 03:38:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008-01-29 03:39:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008-01-29 03:40:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2005-08-06 04:02:34 | 000,000,104 | ---- | M] () -- C:\stats.mst
[2005-03-29 11:20:00 | 000,028,160 | ---- | M] () -- C:\student_notes_for_chapter_18.doc
[2004-09-25 14:12:17 | 000,016,095 | ---- | M] () -- C:\Webapp.pdf
[2007-01-24 22:53:54 | 000,000,150 | ---- | M] () -- C:\YServer.txt
[2006-10-06 17:44:14 | 000,023,499 | -H-- | M] () -- C:\_NavCClt.Log
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004-09-21 13:21:00 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2003-05-15 05:00:00 | 000,027,309 | ---- | M] (Brother Industries ,Ltd ) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\brmfpp1.dll
[2008-07-06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007-01-17 21:25:06 | 000,118,784 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\lxctdrpp.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2002-09-05 16:12:26 | 000,122,880 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\X3Dview.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004-09-21 05:52:06 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004-09-21 05:52:06 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004-09-21 05:52:06 | 000,868,352 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008-04-13 20:12:08 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008-04-13 20:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2008-04-13 20:12:10 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-05-26 07:00:42
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Mark\Desktop\iTunesSetup.exe:SummaryInformation
< End of report >
OTL Extras logfile created on: 2010-07-07 20:03:58 - Run 1
OTL by OldTimer - Version 3.2.8.0 Folder = C:\Documents and Settings\Mark\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: | Country: | Language: | Date Format: yyyy-MM-dd
511.00 Mb Total Physical Memory | 208.00 Mb Available Physical Memory | 41.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 13.75 Gb Free Space | 36.91% Space Free | Partition Type: NTFS
Unable to calculate disk information.
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MARK-0
Current User Name: Mark
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\PROGRA~1\MICROS~2\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\PROGRA~1\MICROS~2\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\1128724321\ee\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1128724321\ee\AOLServiceHost.exe:*:Enabled:AOL Services -- File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\Program Files\Common Files\AOL\1128780009\ee\aolservicehost.exe" = C:\Program Files\Common Files\AOL\1128780009\ee\aolservicehost.exe:*:Enabled:AOL Services -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 -- File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
"C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe" = C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9 -- File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sony\Station\Launchpad\LaunchPad.exe" = C:\Program Files\Sony\Station\Launchpad\LaunchPad.exe:*:Enabled:LaunchPad -- ()
"C:\Program Files\Sony\Station\Launchpad\_aunchPad.exe" = C:\Program Files\Sony\Station\Launchpad\_aunchPad.exe:*:Enabled:_aunchPad -- ()
"C:\Program Files\Windows Media Player\wmplayer.exe" = C:\Program Files\Windows Media Player\wmplayer.exe:*:Disabled:Windows Media Player -- (Microsoft Corporation)
"C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe" = C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe:*:Enabled:Java 2 Platform Standard Edition binary -- (Sun Microsystems, Inc.)
"C:\Program Files\MP3 Rocket\MP3Rocket.exe" = C:\Program Files\MP3 Rocket\MP3Rocket.exe:*:Enabled:MP3 Rocket 4.9.7 -- ()
"C:\Program Files\MP3 Rocket\MP3Rocket_on_startup.exe" = C:\Program Files\MP3 Rocket\MP3Rocket_on_startup.exe:*:Disabled:MP3 Rocket (silent) -- ()
"C:\Program Files\MAIET\Gunz\GunzLauncher.exe" = C:\Program Files\MAIET\Gunz\GunzLauncher.exe:*:Enabled:GunzLauncher -- (MAIET entertainment)
"C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe" = C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice -- (Microsoft Corporation)
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation)
"C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation)
"C:\WINDOWS\system32\lxctcoms.exe" = C:\WINDOWS\system32\lxctcoms.exe:*:Enabled:Lexmark Communications System -- ( )
"C:\Documents and Settings\Mark\Local Settings\temp\RarSFX0\Setup.exe" = C:\Documents and Settings\Mark\Local Settings\temp\RarSFX0\Setup.exe:*:Enabled:Setup -- File not found
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}" = Symantec AntiVirus Client
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 20
"{2A2766A4-6AE4-11D4-AC8E-52544C1966EE}" = Backup Dell-Installed Programs
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63391350-41D4-4181-9D68-038777020C38}" = System Requirements Lab
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34E19B2-F4D4-4C1F-A565-BA92627178D8}" = Sony Media Manager 2.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBF3C503-946E-45EA-B347-EACC41781989}" = W Photo Studio
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC53BB56-FBB5-47BE-B342-E43CC83C0ECF}" = Sony Vegas 6.0c
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"6th" = Algebra 1 6.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0.1" = Adobe Photoshop 7.0.1
"AviSynth" = AviSynth 2.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DVDFab 6_is1" = DVDFab 6.0.4.0 (28/07/2009)
"EsetOnlineScanner" = ESET Online Scanner
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"Lexmark 5400 Series" = Lexmark 5400 Series
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"MP3 Rocket" = MP3 Rocket
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.3-05-09-14-01" = OpenMG Limited Patch 4.3-05-10-05-01
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"SystemRequirementsLab" = System Requirements Lab
"Window Washer" = Window Washer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GCalc 3" = GCalc 3
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2010-07-07 15:51:47 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 15:51:56 | Computer Name = MARK-0 | Source = Application Error | ID = 1001
Description = Fault bucket 20858171.
Error - 2010-07-07 16:01:53 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 16:02:18 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 16:05:52 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 16:06:54 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 16:08:04 | Computer Name = MARK-0 | Source = Application Error | ID = 1000
Description = Faulting application vpc32.exe, version 8.0.0.9374, faulting module
webshell.dll, version 8.0.0.9374, fault address 0x0000168d.
Error - 2010-07-07 16:08:06 | Computer Name = MARK-0 | Source = Application Error | ID = 1001
Description = Fault bucket 20858171.
Error - 2010-07-07 18:36:30 | Computer Name = MARK-0 | Source = Norton AntiVirus | ID = 16711694
Description = Symantec AntiVirus services failed to start. Virus definition file
is invalid. (CC001000)
Error - 2010-07-07 18:54:02 | Computer Name = MARK-0 | Source = Norton AntiVirus | ID = 16711694
Description = Symantec AntiVirus services failed to start. Virus definition file
is invalid. (CC001000)
[ System Events ]
Error - 2010-07-07 18:32:43 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The DefWatch service terminated unexpectedly. It has done this 1
time(s).
Error - 2010-07-07 18:32:43 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 2010-07-07 18:32:44 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The lxct_device service terminated unexpectedly. It has done this
1 time(s).
Error - 2010-07-07 18:32:44 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 2010-07-07 18:32:44 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The McAfee SiteAdvisor Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 2010-07-07 18:32:44 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7034
Description = The Window Washer Engine service terminated unexpectedly. It has
done this 1 time(s).
Error - 2010-07-07 18:36:35 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7023
Description = The Symantec AntiVirus Client service terminated with the following
error: %%10
Error - 2010-07-07 18:36:38 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep Lbd
Error - 2010-07-07 18:54:06 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7023
Description = The Symantec AntiVirus Client service terminated with the following
error: %%10
Error - 2010-07-07 18:54:07 | Computer Name = MARK-0 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep Lbd
< End of report >