Hello. I recently ran into some trouble with some malware I believe. The first symptom was my laptop just restarted by itself. When it turned back on, the firewall kept turning itself off. I also was getting frequent fake alerts from Windows Security trying to get me to install Perfect Defender 2009.
At first, I scanned my laptop using Spybot then Super AntiSpyware. Next, I tried using Malwarebytes but that was unable to run. I then tried scanning using AVG. It seemed to be scanning, but I was unable to actually click the tab to actually see if the scan was going. I then switched over to Safe Mode and was able to scan using both MalwareBytes and AVG. I restarted my laptop and the firewall problem and the popup seemed to stop. However, I was getting alot of command prompts opening as i restarted my laptop. So I scanned using Spybot, Super AntiSpyware, Malwarebytes, and AVG again.
I have yet to restart my laptop after doing the last AVG scan so I am unsure if the command prompt problem is still happening. I'm just wondering now if i should be concerned with backdoor trojans. I don't know if these problems were caused because of one and I am now looking for assistance to make sure my laptop is still secure. I shall now post the logs from the "READ THIS FIRST" thread...
I also included fixes made by Spybot -search and destroy- at the very end. It also seemed that when i ran Spybot search and destroy multiple times, that the win32.tdss.rtk always came back.
Edit: So i restarted the laptop and the command prompt thing seemed to be gone. yay, a mini-victory.
Malwarebytes' Anti-Malware 1.40
Database version: 2595
Windows 5.1.2600 Service Pack 3
8/10/2009 8:08:33 PM
mbam-log-2009-08-10 (20-08-33).txt
Scan type: Quick Scan
Objects scanned: 102412
Time elapsed: 3 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\Mozilla Firefox\chrome\amba.jar (Trojan.Hanam) -> Delete on reboot.
****************************
This was the scan from AVG
Scan "Scheduled scan" was finished.
No infection was found during this scan
Folders selected for scanning:;"Scan whole computer"
Scan started:;"Monday, August 10, 2009, 8:17:00 PM"
Scan finished:;"Tuesday, August 11, 2009, 12:28:15 AM (4 hour(s) 11 minute(s) 14 second(s))"
Total object scanned:;"1291848"
User who launched the scan:;"SYSTEM"
************************************
Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 6 Model 15 Stepping 10, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Enabled
.
Internet Explorer 7.0.5730.13
.
C:\ [Fixed-NTFS] .. ( Total:123 Go - Free:24 Go )
D:\ [CD_Rom]
E:\ [Fixed-NTFS] .. ( Total:25 Go - Free:2 Go )
.
Scan : 00:32.33
Path : C:\Documents and Settings\Jon Lam\Desktop\Rooter.exe
User : Jon Lam ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (956)
______ \??\C:\WINDOWS\system32\csrss.exe (1028)
______ \??\C:\WINDOWS\system32\winlogon.exe (1060)
______ C:\WINDOWS\system32\services.exe (1108)
______ C:\WINDOWS\system32\lsass.exe (1120)
______ C:\WINDOWS\system32\nvsvc32.exe (1292)
______ C:\WINDOWS\system32\svchost.exe (1316)
______ C:\WINDOWS\system32\svchost.exe (1388)
______ C:\WINDOWS\System32\svchost.exe (1436)
______ C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (1492)
______ C:\WINDOWS\system32\svchost.exe (1532)
______ C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (1684)
______ C:\WINDOWS\system32\svchost.exe (1816)
______ C:\WINDOWS\system32\spoolsv.exe (2032)
______ C:\WINDOWS\system32\svchost.exe (220)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (300)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (316)
______ C:\Program Files\Bonjour\mDNSResponder.exe (348)
______ C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (436)
______ C:\Program Files\Java\jre6\bin\jqs.exe (516)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (708)
______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (720)
______ C:\WINDOWS\system32\PnkBstrA.exe (812)
______ C:\WINDOWS\system32\PnkBstrB.exe (868)
______ C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (1000)
______ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (1524)
______ C:\WINDOWS\system32\svchost.exe (1700)
______ C:\Program Files\systemhound\Collector.exe (1948)
______ C:\Program Files\systemhound\shservice.exe (2372)
______ C:\WINDOWS\Explorer.EXE (2432)
______ C:\Program Files\systemhound\SiteBuilder\SiteBuilder.exe (2564)
______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (2616)
______ C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe (2664)
______ C:\PROGRA~1\AVG\AVG8\avgemc.exe (2724)
______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (2800)
______ C:\WINDOWS\System32\alg.exe (3360)
______ C:\Program Files\DellTPad\Apoint.exe (3812)
______ C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (3928)
______ C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (3964)
______ C:\Program Files\DellTPad\ApMsgFwd.exe (3980)
______ C:\WINDOWS\stsystra.exe (3988)
______ C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (4048)
______ C:\Program Files\DellTPad\HidFind.exe (4052)
______ C:\Program Files\Common Files\Real\Update_OB\realsched.exe (1508)
______ C:\Program Files\DellTPad\Apntex.exe (432)
______ C:\Program Files\Dell Support Center\bin\sprtcmd.exe (592)
______ C:\WINDOWS\OEM02Mon.exe (1172)
______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (1744)
______ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (1696)
______ C:\WINDOWS\system32\RunDLL32.exe (2600)
______ C:\WINDOWS\system32\rundll32.exe (2828)
______ C:\WINDOWS\system32\rundll32.exe (3068)
______ C:\Program Files\Java\jre6\bin\jusched.exe (3168)
______ C:\Program Files\iTunes\iTunesHelper.exe (2368)
______ C:\WINDOWS\system32\ctfmon.exe (3820)
______ C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (1348)
______ C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (2112)
______ C:\Documents and Settings\Jon Lam\My Documents\Backups\Windows\Windows_security_backup files\Windows_security_update_3475_36_d.exe (2116)
______ C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (2328)
______ C:\Program Files\Digital Line Detect\DLG.exe (3620)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (1452)
______ C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE (3704)
______ C:\Program Files\Launchy\Launchy.exe (2192)
______ C:\Program Files\Logitech\SetPoint\SetPoint.exe (2312)
______ C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (3140)
______ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (2080)
______ C:\Program Files\iPod\bin\iPodService.exe (3280)
______ C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (3304)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (5800)
______ C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (5304)
______ C:\Program Files\Mozilla Firefox\firefox.exe (4736)
______ C:\WINDOWS\system32\NOTEPAD.EXE (4592)
______ C:\Documents and Settings\Jon Lam\Desktop\Rooter.exe (1676)
______ C:\WINDOWS\system32\HPZipm12.exe (4324)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:115121664)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:115153920 | Length:132854722560)
\Device\Harddisk0\Partition0 (Start_Offset:132969876480 | Length:27069396480)
\Device\Harddisk0\Partition3 (Start_Offset:132969908736 | Length:27069364224)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\SyncBack Bi-Monthly Local Backup.job
C:\WINDOWS\Tasks\SyncBack Monthly Local Backup.job
C:\WINDOWS\Tasks\SyncBack Nightly Local Backup.job
C:\WINDOWS\Tasks\SyncBack Weekly Local Backup.job
C:\WINDOWS\Tasks\WebReg Photosmart C6100 series.job
C:\WINDOWS\Tasks\WGASetup.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
C:\DOCUME~1\JONLAM~1\Desktop\Jono\Programs\Lavasoft Ad-Aware 2008 + Spyware Doctor 2008 (Keys + Cracks Incl.)\Lavasoft Ad-Aware 2008 Professional Edition\crack\update-cracked.exe
==> Cracks & Keygens <==
.
----------------------\\ Scan completed at 00:33.07
.
C:\Rooter$\Rooter_1.txt - (11/08/2009 | 00:33.07).c
***************************
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/11 00:34
Program Version: Version 1.3.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB531D000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xB85E8000 Size: 8192 File Visible: No Signed: -
Status: -
Name: giveio.sys
Image Path: giveio.sys
Address: 0xB8671000 Size: 1664 File Visible: No Signed: -
Status: -
Name: hsoscviu.sys
Image Path: C:\WINDOWS\system32\drivers\hsoscviu.sys
Address: 0xB54C1000 Size: 61440 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB2206000 Size: 49152 File Visible: No Signed: -
Status: -
Name: SKYNETtlafqely.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETtlafqely.sys
Address: 0xB56FE000 Size: 151552 File Visible: - Signed: -
Status: Hidden from the Windows API!
Name: speedfan.sys
Image Path: speedfan.sys
Address: 0xB85AE000 Size: 5248 File Visible: No Signed: -
Status: -
Hidden Services
-------------------
Service Name: SKYNEToeqrqsmj
Image Path: C:\WINDOWS\system32\drivers\SKYNETtlafqely.sys
==EOF==
***********************************
OTL logfile created on: 8/11/2009 12:38:26 AM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\Jon Lam\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 123.73 Gb Total Space | 24.30 Gb Free Space | 19.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 25.21 Gb Total Space | 2.82 Gb Free Space | 11.17% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JONO
Current User Name: Jon Lam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\PnkBstrA.exe ()
PRC - C:\WINDOWS\System32\PnkBstrB.exe ()
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\systemhound\Collector.exe (Software Innovations UK Limited)
PRC - C:\Program Files\systemhound\shservice.exe (Software Innovations UK Limited.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\systemhound\SiteBuilder\SiteBuilder.exe (Software Innovations UK Limited)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe (Intel® Corporation)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Documents and Settings\Jon Lam\My Documents\Backups\Windows\Windows_security_backup files\Windows_security_update_3475_36_d.exe ()
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\Launchy\Launchy.exe ()
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Logitech, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Documents and Settings\Jon Lam\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (btwdins [Auto | Running]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) -- C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EvtEng [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Running]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) -- C:\WINDOWS\System32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) -- C:\WINDOWS\System32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LBTServ [On_Demand | Stopped]) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Stopped]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (PnkBstrA [Auto | Running]) -- C:\WINDOWS\System32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Running]) -- C:\WINDOWS\System32\PnkBstrB.exe ()
SRV - (RegSrvc [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (sprtsvc_dellsupportcenter [Auto | Running]) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (systemhound collector [Auto | Running]) -- C:\Program Files\systemhound\Collector.exe (Software Innovations UK Limited)
SRV - (systemhound scheduler [Auto | Running]) -- C:\Program Files\systemhound\shservice.exe (Software Innovations UK Limited.)
SRV - (systemhound site builder [Auto | Running]) -- C:\Program Files\systemhound\SiteBuilder\SiteBuilder.exe (Software Innovations UK Limited)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WLANKEEPER [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe (Intel® Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) -- C:\WINDOWS\system32\YPcservice.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (AegisP [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys (Cisco Systems, Inc.)
DRV - (akajxcq [Unknown | Running]) -- Service key not found. File not found
DRV - (ApfiltrService [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btwhid.sys (Broadcom Corporation.)
DRV - (btwmodem [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (DSproct [On_Demand | Stopped]) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\giveio.sys ()
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWAZL [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (LHidFilt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MPE [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (NETw4x32 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NETw4x32.sys (Intel Corporation)
DRV - (nm [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\NMnt.sys (Microsoft Corporation)
DRV - (NokiaSuite3 [Auto | Running]) -- C:\WINDOWS\System32\drivers\NokiaSuite3.sys (Nokia Mobile Phones Ltd.)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NWADI [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NWADIenum.sys (Novatel Wireless Inc)
DRV - (OEM02Afx [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\OEM02Afx.sys (Creative Technology Ltd.)
DRV - (OEM02Dev [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (PCASp50 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (PnkBstrK [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\PnkBstrK.sys ()
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rimmptsk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\rixdptsk.sys (REDC)
DRV - (s24trans [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SCDEmu [System | Running]) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (TVICHW32 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (USB28xxBGA [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\emOEM.sys (eMPIA Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WinDriver6 [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\windrvr6.sys (Jungo)
DRV - (XilinxPC4Driver [Auto | Running]) -- C:\WINDOWS\System32\drivers\xpc4drvr.sys (Xilinx, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/.../search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: *{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key error. File not found
IE - URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: avg@igeared:2.506.026.001
FF - prefs.js..extensions.enabledItems: battlefieldheroespatcher@ea.com:4.0.15.0
FF - prefs.js..extensions.enabledItems: betteryoutube@ginatrapani.org:0.4.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: {4776510a-a1f4-41f3-a3c8-35b474ecef23}:1.0.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/18 12:04:41 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/07/21 19:35:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/04 08:43:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/04 08:43:48 | 00,000,000 | ---D | M]
[2008/05/24 17:51:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Extensions
[2008/05/24 17:51:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/09 00:54:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Firefox\Profiles\ok9e8pgz.default\extensions
[2008/09/08 17:13:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Firefox\Profiles\ok9e8pgz.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2009/04/28 13:22:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Firefox\Profiles\ok9e8pgz.default\extensions\battlefieldheroespatcher@ea.com
[2008/09/10 01:33:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Firefox\Profiles\ok9e8pgz.default\extensions\betteryoutube@ginatrapani.org
[2008/09/27 18:10:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\mozilla\Firefox\Profiles\ok9e8pgz.default\extensions\moveplayer@movenetworks.com
[2009/08/09 00:54:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/04 08:43:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/09/09 12:30:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/18 12:04:58 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/01 17:40:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/15 20:59:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/04 08:43:33 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/04 08:43:33 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/05/21 11:33:58 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/03/21 13:28:46 | 01,335,600 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2007/07/02 15:20:48 | 00,069,632 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npijjiFFPlugin1.dll
[2008/06/27 17:03:12 | 01,446,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/04 08:43:40 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/05/25 16:31:29 | 00,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
[2008/09/05 17:33:52 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/07/19 19:08:57 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/09/05 17:34:16 | 00,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/09/05 17:33:44 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2007/04/16 10:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/08/04 08:43:44 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/04 08:43:44 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/29 15:40:31 | 00,001,489 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/08/04 08:43:44 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/04 08:43:44 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/04 08:43:44 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/04 08:43:44 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/04 08:43:44 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMCTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Windows Security Update] C:\Documents and Settings\Jon Lam\My Documents\Backups\Windows\Windows_security_backup files\Windows_security_update_3475_36_d.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchy.lnk = C:\Program Files\Launchy\Launchy.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Jon Lam\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html ()
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab (HpProductDetection Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {A0401AB6-634E-4E77-9E1F-231C29D523C1} http://www.windowsoffers.com/blockbuster/VistaPCDetector.cab (Vista PC Detector)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.0.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop Components:1 () - http://www.meatspin.com/
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/24 19:36:53 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{85b99fd8-98b3-11dc-91ef-001c26efbc7e}\Shell\AutoRun\command - "" = wd_windows_tools\setup.exe
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
MsConfig - StartUpReg: AdobeUpdater - hkey= - key= - C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Aim6 - hkey= - key= - C:\Program Files\AIM6\aim6.exe (AOL LLC)
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: MSMSGS - hkey= - key= - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
MsConfig - StartUpReg: PMCLoader - hkey= - key= - C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe (Pinnacle Systems GmbH)
MsConfig - StartUpReg: PMCRemote - hkey= - key= - C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe (Pinnacle Systems)
MsConfig - StartUpReg: Steam - hkey= - key= - c:\program files\steam\steam.exe (Valve Corporation)
MsConfig - StartUpReg: SUPERAntiSpyware - hkey= - key= - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
MsConfig - StartUpReg: Yahoo! Pager - hkey= - key= - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
MsConfig - StartUpReg: YBrowser - hkey= - key= - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
MsConfig - StartUpReg: YOP - hkey= - key= - C:\Program Files\Yahoo!\YOP\yop.exe (Yahoo! Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: aawservice - Reg Error: Value error.
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: WdfLoadGroup -
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: aawservice - Reg Error: Value error.
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: nm - C:\WINDOWS\System32\DRIVERS\NMnt.sys (Microsoft Corporation)
SafeBootNet: nm.sys - C:\WINDOWS\System32\DRIVERS\NMnt.sys (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: WdfLoadGroup -
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {0430454D-47EA-11D6-AD58-00010333D0AD} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} - Reg Error: Value error.
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {34C70B70-8FFF-4179-A2EB-0819FFA38126} - Reg Error: Value error.
ActiveX: {362A5D5E-1BF6-4CA7-87B4-B6686F3C1BEF} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4a01a151-e350-4839-a2b8-03dc39d6c8e5} - Reg Error: Value error.
ActiveX: {4DAEE2D4-A471-42AC-97A2-4C2A79C77648} - Reg Error: Value error.
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)
ActiveX: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - Reg Error: Value error.
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {944D7BBB-EA1D-43EB-B49F-F517CF2B6C9D} - Reg Error: Value error.
ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error.
ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error.
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {CE734E0A-D6D3-4A92-AF9F-499BE87A025C} - Reg Error: Value error.
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F53CE5EC-1CD8-41EB-A220-F8EA247E3A06} - Reg Error: Value error.
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\WINDOWS\System32\VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
========== Files/Folders - Created Within 30 Days ==========
[2009/08/11 00:35:59 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jon Lam\Desktop\OTL.exe
[2009/08/11 00:34:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jon Lam\Desktop\RootRepeal
[2009/08/11 00:33:50 | 00,462,996 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\RootRepeal.zip
[2009/08/11 00:32:48 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/08/11 00:32:14 | 00,173,119 | ---- | C] (Eric_71) -- C:\Documents and Settings\Jon Lam\Desktop\Rooter.exe
[2009/08/11 00:31:21 | 00,000,734 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\log.csv
[2009/08/10 19:57:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/08/10 19:56:42 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/10 19:56:38 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\NTREGOPT.lnk
[2009/08/10 19:56:38 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\ERUNT.lnk
[2009/08/10 19:56:38 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/08/10 19:55:13 | 00,272,384 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jon Lam\Desktop\TFC.exe
[2009/08/10 19:55:03 | 00,794,112 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\The_Comedian.exe
[2009/08/10 03:13:44 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/10 03:13:43 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/10 03:13:43 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/10 03:09:49 | 00,002,579 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/08/10 02:26:51 | 00,088,064 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\brontgui.com
[2009/08/10 02:17:51 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Jon Lam\Desktop\setup-spybotsd162.exe
[2009/08/10 01:23:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jon Lam\Application Data\Google
[2009/08/10 01:11:11 | 00,131,072 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\Cthulhu_BBQx8oDetail.png
[2009/08/09 21:56:23 | 01,165,539 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\HUD.rar
[2009/08/09 16:12:36 | 00,000,312 | ---- | C] () -- C:\WINDOWS\tasks\WebReg Photosmart C6100 series.job
[2009/08/06 21:48:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jon Lam\Application Data\FahMon
[2009/08/06 21:48:07 | 00,000,000 | ---D | C] -- C:\Program Files\FahMon
[2009/08/06 21:02:38 | 00,256,422 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\Folding@home-Win32-x86-623.zip
[2009/08/03 12:37:39 | 00,045,986 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\router rebate OfferWire_Prepaid_Card_WBR1310_072009.pdf
[2009/08/02 23:22:51 | 00,227,183 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\Back_to_School_534497581.pdf
[2009/07/29 23:31:45 | 00,406,007 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\Snes_Papercraft_set_by_ryo007.jpg
[2009/07/27 22:41:20 | 00,093,424 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\speedfan.JPG
[2009/07/27 18:25:41 | 00,092,222 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\ins_as5_intel_quad_wcap.pdf
[2009/07/27 14:22:37 | 00,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2009/07/27 14:22:37 | 00,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2009/07/20 19:30:44 | 00,075,274 | ---- | C] () -- C:\Documents and Settings\Jon Lam\Desktop\EVGA _ Community _ My Products.pdf
[2009/07/19 19:10:35 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/07/19 19:08:09 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/07/19 00:54:51 | 00,000,084 | ---- | C] () -- C:\WINDOWS\winDecrypt.INI
[2009/07/19 00:54:44 | 00,000,067 | ---- | C] () -- C:\pdfinfo.ini
[2009/07/19 00:49:54 | 00,001,024 | ---- | C] () -- C:\WINDOWS\System32\pwdremover.dat
[2009/07/19 00:49:54 | 00,000,036 | ---- | C] () -- C:\WINDOWS\verypdf.ini
[2009/07/19 00:49:17 | 00,000,000 | ---D | C] -- C:\Program Files\PDF Password Remover v2.5
[2009/07/18 20:47:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jon Lam\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2009/07/18 20:26:24 | 00,509,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_2.dll
[2009/07/18 20:26:24 | 00,068,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_1.dll
[2009/07/18 20:26:21 | 01,493,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_39.dll
[2009/07/18 20:26:21 | 00,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_39.dll
[2009/07/18 20:26:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2009/07/18 20:26:09 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2009/07/18 20:25:43 | 03,851,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_39.dll
[2009/07/18 20:25:10 | 00,000,000 | ---D | C] -- C:\Riot Games
[2009/07/16 15:05:20 | 03,998,334 | ---- | C] () -- C:\Documents and Settings\Jon Lam\My Documents\0716.pdf
[2009/07/14 15:43:27 | 00,000,000 | ---D | C] -- C:\Program Files\Tournament Indicator
[2009/07/13 21:42:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jon Lam\My Documents\Backups
[2009/05/01 00:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/03/23 02:47:03 | 00,201,488 | ---- | C] () -- C:\WINDOWS\System32\MACD32.DLL
[2009/03/23 02:47:03 | 00,144,144 | ---- | C] () -- C:\WINDOWS\System32\MASE32.DLL
[2009/03/23 02:47:03 | 00,141,584 | ---- | C] () -- C:\WINDOWS\System32\MAMC32.DLL
[2009/03/23 02:47:03 | 00,063,248 | ---- | C] () -- C:\WINDOWS\System32\MASD32.DLL
[2009/03/23 02:47:03 | 00,033,040 | ---- | C] () -- C:\WINDOWS\System32\MA32.DLL
[2009/01/14 19:42:11 | 00,005,248 | ---- | C] () -- C:\WINDOWS\giveio.sys
[2008/10/07 09:13:30 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/23 12:29:00 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2008/07/18 21:30:39 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/07/18 21:30:39 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/07/18 21:30:39 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/06/22 14:19:30 | 00,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/06/18 16:23:10 | 00,000,025 | ---- | C] () -- C:\WINDOWS\OverlayXP.ini
[2008/01/03 17:06:14 | 00,137,992 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/11/26 18:19:28 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2007/10/28 13:53:49 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/10/27 22:18:02 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/10/25 23:09:49 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/10/25 22:01:30 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2007/10/25 11:18:26 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/10/24 23:14:55 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007/05/17 14:52:30 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007/05/17 14:23:20 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2007/03/05 13:34:28 | 00,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2005/08/09 15:13:31 | 00,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/08/09 15:13:31 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 15:12:28 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/02/17 12:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 05:00:00 | 00,000,634 | ---- | C] () -- C:\WINDOWS\win.ini
[2002/08/29 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[2001/07/07 03:00:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== Files - Modified Within 30 Days ==========
[2009/08/11 00:36:01 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jon Lam\Desktop\OTL.exe
[2009/08/11 00:33:52 | 00,462,996 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\RootRepeal.zip
[2009/08/11 00:32:14 | 00,173,119 | ---- | M] (Eric_71) -- C:\Documents and Settings\Jon Lam\Desktop\Rooter.exe
[2009/08/11 00:31:21 | 00,000,734 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\log.csv
[2009/08/10 20:14:55 | 39,716,319 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/10 20:13:25 | 00,000,634 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/08/10 20:11:25 | 00,094,401 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2009/08/10 20:11:23 | 00,126,624 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/08/10 20:11:15 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/08/10 20:10:25 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/08/10 20:10:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/08/10 20:10:14 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/08/10 19:56:42 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/10 19:56:38 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\NTREGOPT.lnk
[2009/08/10 19:56:38 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\ERUNT.lnk
[2009/08/10 19:55:13 | 00,272,384 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jon Lam\Desktop\TFC.exe
[2009/08/10 19:55:05 | 00,794,112 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\The_Comedian.exe
[2009/08/10 18:27:35 | 00,002,579 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/08/10 02:36:19 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Jon Lam\Desktop\setup-spybotsd162.exe
[2009/08/10 02:26:51 | 00,088,064 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\brontgui.com
[2009/08/10 02:00:10 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Nightly Local Backup.job
[2009/08/10 01:13:56 | 00,060,243 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/10 01:11:12 | 00,131,072 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\Cthulhu_BBQx8oDetail.png
[2009/08/09 21:57:04 | 01,165,539 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\HUD.rar
[2009/08/09 16:12:37 | 00,000,312 | ---- | M] () -- C:\WINDOWS\tasks\WebReg Photosmart C6100 series.job
[2009/08/09 02:00:05 | 00,000,452 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Weekly Local Backup.job
[2009/08/06 21:02:38 | 00,256,422 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\Folding@home-Win32-x86-623.zip
[2009/08/04 18:38:22 | 00,097,792 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/04 01:21:10 | 00,094,401 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2009/08/04 01:13:49 | 00,077,619 | ---- | M] () -- C:\WINDOWS\War3Unin.dat
[2009/08/03 13:36:28 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/03 12:37:39 | 00,045,986 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\router rebate OfferWire_Prepaid_Card_WBR1310_072009.pdf
[2009/08/02 23:22:51 | 00,227,183 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\Back_to_School_534497581.pdf
[2009/08/01 02:00:10 | 00,000,454 | ---- | M] () -- C:\WINDOWS\tasks\SyncBack Monthly Local Backup.job
[2009/07/29 23:31:45 | 00,406,007 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\Snes_Papercraft_set_by_ryo007.jpg
[2009/07/28 21:57:38 | 00,000,084 | ---- | M] () -- C:\WINDOWS\winDecrypt.INI
[2009/07/28 21:57:26 | 00,000,067 | ---- | M] () -- C:\pdfinfo.ini
[2009/07/28 21:57:22 | 00,000,036 | ---- | M] () -- C:\WINDOWS\verypdf.ini
[2009/07/27 22:41:20 | 00,093,424 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\speedfan.JPG
[2009/07/27 18:25:41 | 00,092,222 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\ins_as5_intel_quad_wcap.pdf
[2009/07/27 14:22:37 | 00,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2009/07/23 00:11:41 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/07/20 19:30:44 | 00,075,274 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Desktop\EVGA _ Community _ My Products.pdf
[2009/07/19 06:33:02 | 03,597,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009/07/19 06:33:02 | 03,597,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/07/19 06:32:59 | 06,067,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieframe.dll
[2009/07/19 06:32:59 | 06,067,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/19 00:49:54 | 00,001,024 | ---- | M] () -- C:\WINDOWS\System32\pwdremover.dat
[2009/07/17 14:02:32 | 00,335,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/16 15:05:21 | 03,998,334 | ---- | M] () -- C:\Documents and Settings\Jon Lam\My Documents\0716.pdf
========== LOP Check ==========
[2009/06/29 15:38:20 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/05/19 15:44:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/19 22:49:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2007/11/26 18:36:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ALM
[2009/06/29 15:38:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2008/11/30 22:14:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Blizzard
[2007/11/01 00:24:45 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/02/26 01:07:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2008/05/22 03:06:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2008/06/26 22:42:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EyePowerGames
[2009/04/24 09:42:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/05/24 21:26:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IJJIGame
[2007/10/24 23:21:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2008/02/19 20:55:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2007/11/02 03:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogiShrd
[2007/10/24 20:36:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2008/06/18 16:54:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/03/23 02:47:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/05/25 16:31:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2008/01/10 20:58:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/10/10 09:29:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/16 01:27:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/04/01 00:24:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/08/10 03:46:00 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Jon Lam\Application Data
[2009/06/02 18:48:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\.purple
[2007/10/25 22:41:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\acccore
[2007/10/27 22:01:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Ahead
[2009/07/03 15:27:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Atari
[2009/04/14 14:45:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Auslogics
[2008/06/26 23:45:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\AVGTOOLBAR
[2009/03/01 18:57:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Binary Fortress Software
[2008/06/19 08:16:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Digsby
[2009/05/05 15:39:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Download Manager
[2009/05/10 00:27:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\dvdcss
[2009/07/01 21:54:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Eltima Software
[2009/08/06 22:01:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\FahMon
[2009/06/02 18:48:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\gtk-2.0
[2009/01/14 23:54:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\hte
[2008/05/29 23:19:30 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Jon Lam\Application Data\ijjigame
[2007/10/24 23:21:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Intel
[2008/09/09 21:10:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\KeePass
[2008/12/08 21:42:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Launchy
[2007/11/02 04:04:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Leadertech
[2009/07/18 20:47:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2008/04/03 20:45:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\MathWorks
[2008/10/26 19:59:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Move Networks
[2008/05/08 12:50:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Nexon
[2009/01/11 16:35:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Pelles C
[2009/05/31 01:03:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\SharpReader
[2009/01/09 01:41:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\SSH
[2009/06/09 20:58:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\SystemRequirementsLab
[2009/08/06 21:45:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\TeraCopy
[2007/11/21 23:54:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\tmp
[2008/06/13 16:17:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\U3
[2009/08/05 01:39:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\uTorrent
[2008/06/05 13:47:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Ventrilo
[2007/10/29 00:23:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Viewpoint
[2009/01/31 23:38:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Vso
[2009/05/14 19:53:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\wootalyzer
[2009/02/11 23:35:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon Lam\Application Data\Xilinx
[2002/08/29 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/08/10 20:10:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/03/02 03:01:33 | 00,000,460 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Bi-Monthly Local Backup.job
[2009/08/01 02:00:10 | 00,000,454 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Monthly Local Backup.job
[2009/08/10 02:00:10 | 00,000,454 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Nightly Local Backup.job
[2009/08/09 02:00:05 | 00,000,452 | ---- | M] () -- C:\WINDOWS\Tasks\SyncBack Weekly Local Backup.job
[2009/08/09 16:12:37 | 00,000,312 | ---- | M] () -- C:\WINDOWS\Tasks\WebReg Photosmart C6100 series.job
[2009/08/10 20:11:15 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< %systemroot%\System32\antiwpa.dll >
< %systemroot%\SYSTEM32\wpa.dll >
< %systemroot%\setup\scripts\biestart.exe >
< %systemroot%\system32\drivers\royal.sys >
< %systemroot%\system32\oobe\AntiWPA_Crypt.dll >
< %TEMP%\antiwpa_crypt.dll >
< %TEMP%\antiwpa.dll /s >
< %PROGRAMFILES%\antiwpa.dll /s >
< %systemroot%\system32\crypt.dll >
< %TEMP%\crypt.dll >
< %SYSTEMDRIVE%\*. >
[2009/08/10 20:13:11 | 00,000,000 | ---D | M] -- C:
[2009/08/10 04:55:55 | 00,000,000 | -H-D | M] -- C:\$AVG8.VAULT$
[2008/09/23 12:51:59 | 00,000,000 | ---D | M] -- C:\bin
[2009/08/10 20:13:10 | 00,000,000 | ---D | M] -- C:\Config.Msi
[2008/01/10 20:59:03 | 00,000,000 | ---D | M] -- C:\dell
[2007/11/19 22:01:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings
[2007/10/25 09:39:20 | 00,000,000 | ---D | M] -- C:\DRIVERS
[2007/10/25 10:18:34 | 00,000,000 | ---D | M] -- C:\IEGD
[2008/05/10 15:33:00 | 00,000,000 | ---D | M] -- C:\ijji
[2007/10/24 20:40:59 | 00,000,000 | ---D | M] -- C:\Intel
[2009/01/14 19:35:05 | 00,000,000 | ---D | M] -- C:\Modeltech_xe_starter
[2007/10/25 23:04:12 | 00,000,000 | RH-D | M] -- C:\MSOCache
[2008/05/08 12:39:36 | 00,000,000 | ---D | M] -- C:\Nexon
[2009/06/04 00:23:48 | 00,000,000 | ---D | M] -- C:\NVIDIA
[2009/08/10 20:10:14 | 00,000,000 | R--D | M] -- C:\Program Files
[2007/11/20 02:12:04 | 00,000,000 | -HSD | M] -- C:\RECYCLER
[2009/07/18 20:25:10 | 00,000,000 | ---D | M] -- C:\Riot Games
[2009/08/11 00:33:07 | 00,000,000 | ---D | M] -- C:\Rooter$
[2009/04/01 08:34:44 | 00,000,000 | -HSD | M] -- C:\System Volume Information
[2008/09/23 12:51:24 | 00,000,000 | ---D | M] -- C:\Temp
[2009/08/10 20:11:48 | 00,000,000 | ---D | M] -- C:\WINDOWS
[2009/01/14 18:42:06 | 00,000,000 | ---D | M] -- C:\Xilinx
< %SYSTEMDRIVE%\*.* >
[2007/10/24 19:36:53 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/06/15 13:01:03 | 00,000,212 | -HS- | M] () -- C:\boot.ini
[2007/10/24 19:36:53 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/10/24 19:36:53 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/06/16 01:27:56 | 00,001,208 | -H-- | M] () -- C:\IPH.PH
[2007/10/22 20:11:52 | 03,072,054 | ---- | M] () -- C:\jono is a pooty.bmp
[2009/08/03 12:29:32 | 00,196,223 | ---- | M] () -- C:\mombi.log
[2007/10/24 19:36:53 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/03 22:38:34 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/08/20 20:16:12 | 00,250,048 | RHS- | M] () -- C:\ntldr
[2009/08/10 20:10:07 | 21,453,86496 | -HS- | M] () -- C:\pagefile.sys
[2009/07/28 21:57:26 | 00,000,067 | ---- | M] () -- C:\pdfinfo.ini
[2009/08/10 02:37:20 | 00,000,934 | ---- | M] () -- C:\resolve.log
[2009/08/11 00:34:43 | 00,002,856 | ---- | M] () -- C:\RootRepeal report 08-11-09 (00-34-43).txt
[2008/06/18 18:35:39 | 00,000,174 | ---- | M] () -- C:\Setup.log
[2008/11/20 14:40:06 | 00,000,510 | ---- | M] () -- C:\updatedatfix.log
[2008/06/16 00:11:44 | 00,000,152 | ---- | M] () -- C:\YServer.txt
< %PROGRAMFILES%\*. >
[2009/08/10 20:10:14 | 00,000,000 | R--D | M] -- C:\Program Files
[2009/01/02 17:30:19 | 00,000,000 | ---D | M] -- C:\Program Files\2BrightSparks
[2008/05/21 15:35:47 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/06/04 00:25:39 | 00,000,000 | ---D | M] -- C:\Program Files\AGEIA Technologies
[2009/06/16 01:27:56 | 00,000,000 | ---D | M] -- C:\Program Files\AIM6
[2008/02/17 14:24:07 | 00,000,000 | ---D | M] -- C:\Program Files\AOL
[2008/07/21 00:40:17 | 00,000,000 | ---D | M] -- C:\Program Files\Aplus DVD Copy
[2008/09/10 21:45:34 | 00,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2009/07/03 15:20:28 | 00,000,000 | ---D | M] -- C:\Program Files\Atari
[2009/04/14 14:45:36 | 00,000,000 | ---D | M] -- C:\Program Files\Auslogics
[2008/06/22 16:32:05 | 00,000,000 | ---D | M] -- C:\Program Files\AVG
[2008/04/14 01:43:20 | 00,000,000 | ---D | M] -- C:\Program Files\AviSynth 2.5
[2009/05/19 15:33:52 | 00,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2007/10/24 23:17:13 | 00,000,000 | ---D | M] -- C:\Program Files\Broadcom
[2009/05/17 21:04:05 | 00,000,000 | ---D | M] -- C:\Program Files\CamStudio
[2007/11/01 00:24:35 | 00,000,000 | -H-D | M] -- C:\Program Files\CanonBJ
[2009/01/01 11:14:40 | 00,000,000 | ---D | M] -- C:\Program Files\CCleaner
[2009/07/18 20:26:09 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files
[2007/10/24 19:32:30 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2007/10/25 02:31:54 | 00,000,000 | ---D | M] -- C:\Program Files\CONEXANT
[2008/06/18 18:34:00 | 00,000,000 | ---D | M] -- C:\Program Files\Creative
[2008/06/18 18:34:23 | 00,000,000 | ---D | M] -- C:\Program Files\Creative Live! Cam
[2008/06/18 18:34:16 | 00,000,000 | ---D | M] -- C:\Program Files\Dell
[2008/01/10 20:57:58 | 00,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
[2007/10/24 20:46:13 | 00,000,000 | ---D | M] -- C:\Program Files\DellSupport
[2007/10/24 20:45:11 | 00,000,000 | ---D | M] -- C:\Program Files\DellTPad
[2009/02/03 01:34:13 | 00,000,000 | ---D | M] -- C:\Program Files\Diablo II
[2007/10/24 23:15:04 | 00,000,000 | ---D | M] -- C:\Program Files\DIFX
[2009/01/14 19:41:54 | 00,000,000 | ---D | M] -- C:\Program Files\Digilent
[2007/10/24 20:39:18 | 00,000,000 | ---D | M] -- C:\Program Files\Digital Line Detect
[2008/06/19 08:15:57 | 00,000,000 | ---D | M] -- C:\Program Files\Digsby
[2009/03/01 18:54:46 | 00,000,000 | ---D | M] -- C:\Program Files\DisplayFusion
[2008/05/12 02:05:25 | 00,000,000 | ---D | M] -- C:\Program Files\DivX
[2008/03/18 01:09:09 | 00,000,000 | ---D | M] -- C:\Program Files\DVD Decrypter
[2008/04/01 00:38:30 | 00,000,000 | ---D | M] -- C:\Program Files\DVDFab Platinum 4
[2009/05/25 17:18:56 | 00,000,000 | ---D | M] -- C:\Program Files\EA Games
[2008/01/03 16:16:26 | 00,000,000 | ---D | M] -- C:\Program Files\Electronic Arts
[2009/08/10 19:56:42 | 00,000,000 | ---D | M] -- C:\Program Files\ERUNT
[2009/08/06 21:48:09 | 00,000,000 | ---D | M] -- C:\Program Files\FahMon
[2009/07/25 01:31:15 | 00,000,000 | ---D | M] -- C:\Program Files\Full Tilt Poker
[2007/10/25 10:50:34 | 00,000,000 | ---D | M] -- C:\Program Files\Grisoft
[2007/10/25 23:39:05 | 00,000,000 | ---D | M] -- C:\Program Files\Guitar Pro 5
[2008/09/23 12:48:09 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2008/09/23 12:53:01 | 00,000,000 | ---D | M] -- C:\Program Files\HP
[2008/04/30 19:33:09 | 00,000,000 | ---D | M] -- C:\Program Files\iDump
[2008/05/10 15:33:00 | 00,000,000 | ---D | M] -- C:\Program Files\ijji
[2007/10/31 21:21:28 | 00,000,000 | ---D | M] -- C:\Program Files\Illustrate
[2008/03/13 01:14:04 | 00,000,000 | ---D | M] -- C:\Program Files\Image-Line
[2009/07/18 20:25:09 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2007/10/24 23:20:29 | 00,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/07/28 15:09:16 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/07/19 19:10:35 | 00,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/07/19 19:11:05 | 00,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/06/15 20:59:26 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2008/05/28 16:11:19 | 00,000,000 | ---D | M] -- C:\Program Files\KeyLemon
[2008/05/14 14:56:33 | 00,000,000 | ---D | M] -- C:\Program Files\Last.fm
[2008/12/08 21:42:12 | 00,000,000 | ---D | M] -- C:\Program Files\Launchy
[2008/10/10 09:30:44 | 00,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2007/11/02 04:00:52 | 00,000,000 | ---D | M] -- C:\Program Files\Logitech
[2009/08/10 19:52:44 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/04/03 20:25:48 | 00,000,000 | ---D | M] -- C:\Program Files\MATLAB
[2008/08/21 02:17:31 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger
[2007/10/25 23:09:10 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2007/10/24 19:37:06 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2008/06/01 00:37:04 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2008/01/25 17:51:33 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2007/10/25 23:09:14 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2007/10/24 20:38:03 | 00,000,000 | ---D | M] -- C:\Program Files\Modem Diagnostic Tool
[2008/08/20 20:22:50 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/08/10 20:13:11 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2008/07/14 10:00:14 | 00,000,000 | ---D | M] -- C:\Program Files\MSECache
[2007/10/24 19:31:05 | 00,000,000 | ---D | M] -- C:\Program Files\MSN
[2007/10/24 19:32:03 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2007/10/28 13:53:05 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/10/25 04:10:00 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2007/10/27 21:58:25 | 00,000,000 | ---D | M] -- C:\Program Files\Nero
[2008/08/20 20:19:11 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2009/06/16 20:16:07 | 00,000,000 | ---D | M] -- C:\Program Files\Nokia
[2008/08/20 20:19:06 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2009/05/25 16:31:27 | 00,000,000 | ---D | M] -- C:\Program Files\Pando Networks
[2007/12/23 19:30:47 | 00,000,000 | ---D | M] -- C:\Program Files\PartyGaming
[2007/10/25 11:08:29 | 00,000,000 | ---D | M] -- C:\Program Files\PC Wizard 2008
[2009/07/19 00:49:20 | 00,000,000 | ---D | M] -- C:\Program Files\PDF Password Remover v2.5
[2009/08/05 01:39:36 | 00,000,000 | ---D | M] -- C:\Program Files\PeerGuardian2
[2009/01/11 16:34:06 | 00,000,000 | ---D | M] -- C:\Program Files\PellesC
[2008/07/15 01:55:00 | 00,000,000 | ---D | M] -- C:\Program Files\Pinnacle
[2007/12/20 01:33:15 | 00,000,000 | ---D | M] -- C:\Program Files\PowerISO
[2009/02/22 20:49:10 | 00,000,000 | ---D | M] -- C:\Program Files\Project64 1.6
[2008/08/31 02:16:51 | 00,000,000 | ---D | M] -- C:\Program Files\QuickMediaConverter
[2009/07/19 19:08:57 | 00,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/05/25 17:22:51 | 00,000,000 | ---D | M] -- C:\Program Files\Rainmeter
[2007/11/11 21:21:48 | 00,000,000 | ---D | M] -- C:\Program Files\Real
[2008/04/14 14:44:58 | 00,000,000 | ---D | M] -- C:\Program Files\Red Kawa
[2009/05/25 17:22:41 | 00,000,000 | ---D | M] -- C:\Program Files\Samurize
[2008/02/15 02:10:03 | 00,000,000 | ---D | M] -- C:\Program Files\SharpReader
[2007/10/24 23:55:49 | 00,000,000 | ---D | M] -- C:\Program Files\SigmaTel
[2008/02/12 23:13:20 | 00,000,000 | ---D | M] -- C:\Program Files\Skype
[2009/08/06 22:08:53 | 00,000,000 | ---D | M] -- C:\Program Files\SpeedFan
[2009/08/10 02:38:26 | 00,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2007/10/25 23:41:08 | 00,000,000 | ---D | M] -- C:\Program Files\SSH Communications Security
[2008/03/04 15:59:42 | 00,000,000 | ---D | M] -- C:\Program Files\Starcraft
[2009/08/10 01:16:03 | 00,000,000 | ---D | M] -- C:\Program Files\Steam
[2009/05/09 23:12:27 | 00,000,000 | ---D | M] -- C:\Program Files\StepMania
[2009/08/10 10:13:44 | 00,000,000 | ---D | M] -- C:\Program Files\SUPERAntiSpyware
[2007/10/25 03:34:57 | 00,000,000 | ---D | M] -- C:\Program Files\systemhound
[2009/06/09 20:58:37 | 00,000,000 | ---D | M] -- C:\Program Files\SystemRequirementsLab
[2009/06/07 14:51:55 | 00,000,000 | ---D | M] -- C:\Program Files\TeraCopy
[2007/12/20 01:45:51 | 00,000,000 | ---D | M] -- C:\Program Files\The Rosetta Stone
[2009/07/17 00:50:22 | 00,000,000 | ---D | M] -- C:\Program Files\Tournament Indicator
[2007/10/24 19:48:19 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/07/03 10:14:51 | 00,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2008/06/05 13:46:27 | 00,000,000 | ---D | M] -- C:\Program Files\Ventrilo
[2007/12/15 23:41:37 | 00,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2008/06/09 18:58:49 | 00,000,000 | ---D | M] -- C:\Program Files\VideoraiPodConverter
[2007/10/25 22:40:33 | 00,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2008/03/13 01:14:15 | 00,000,000 | ---D | M] -- C:\Program Files\VstPlugins
[2009/08/04 01:19:00 | 00,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2008/10/09 16:05:31 | 00,000,000 | ---D | M] -- C:\Program Files\WC3Banlist
[2007/10/24 23:53:18 | 00,000,000 | ---D | M] -- C:\Program Files\WIDCOMM
[2008/04/13 23:34:11 | 00,000,000 | ---D | M] -- C:\Program Files\WinAVI Video Converter
[2009/06/28 16:36:45 | 00,000,000 | ---D | M] -- C:\Program Files\WinDjView
[2008/07/14 10:00:42 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Installer Clean Up
[2009/03/31 23:21:48 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live Safety Center
[2007/11/25 01:02:45 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/05/25 17:22:41 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/08/20 20:19:06 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2007/10/24 19:35:45 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2007/10/28 18:45:04 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2008/06/18 19:02:22 | 00,000,000 | ---D | M] -- C:\Program Files\wLite
[2009/03/25 22:50:36 | 00,000,000 | ---D | M] -- C:\Program Files\Wootalyzer
[2009/02/14 01:57:35 | 00,000,000 | ---D | M] -- C:\Program Files\World of Warcraft
[2007/10/24 19:37:06 | 00,000,000 | ---D | M] -- C:\Program Files\xerox
[2008/06/16 00:07:38 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo!
< %systemroot%\*.exe >
[2007/07/18 19:51:26 | 00,090,112 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\CtDrvIns.exe
[2006/12/15 15:54:30 | 00,061,440 | ---- | M] (eMPIA Technology, Inc.) -- C:\WINDOWS\emMON.exe
[2008/04/13 17:12:19 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2008/04/13 17:12:21 | 00,010,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\hh.exe
[1998/10/29 16:45:06 | 00,306,688 | ---- | M] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2008/02/29 04:12:38 | 00,076,304 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\KHALMNPR.Exe
[2008/04/13 17:12:19 | 01,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\newstartbutton.exe
[2008/04/13 17:12:19 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\newstartbutton2.exe
[2008/04/13 17:12:19 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\newstartbutton2_original.exe
[2008/04/13 17:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2007/10/11 01:02:00 | 00,028,672 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OEM02Cfg.exe
[2007/05/10 01:01:00 | 00,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OEM02Mon.exe
[2008/04/13 17:12:19 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\original explorer.exe
[2008/04/13 17:12:32 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\regedit.exe
[2007/12/11 18:26:51 | 00,070,656 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\ScUnin.exe
[2008/04/13 17:12:35 | 00,032,866 | ---- | M] (Smart Link) -- C:\WINDOWS\slrundll.exe
[2007/05/06 17:10:52 | 00,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
[2002/08/29 05:00:00 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2002/08/29 05:00:00 | 00,049,680 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_16.exe
[2002/08/29 05:00:00 | 00,025,600 | ---- | M] (Twain Working Group) -- C:\WINDOWS\twunk_32.exe
[2005/09/12 15:13:46 | 00,233,472 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroBackItUp.exe
[2005/09/12 15:13:46 | 00,233,472 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroMediaHome.exe
[2005/09/12 15:13:46 | 00,233,472 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroShowTime.exe
[2005/09/12 15:13:46 | 00,233,472 | ---- | M] (Nero AG) -- C:\WINDOWS\UNNeroVision.exe
[2005/09/12 15:13:46 | 00,233,472 | ---- | M] (Nero AG) -- C:\WINDOWS\UNRecode.exe
[1999/12/17 11:13:04 | 00,086,016 | ---- | M] (MindVision Software) -- C:\WINDOWS\unvise32.exe
[2008/05/05 21:17:37 | 00,139,264 | ---- | M] (Blizzard Entertainment) -- C:\WINDOWS\War3Unin.exe
[2002/08/29 05:00:00 | 00,256,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhelp.exe
[2008/04/13 17:12:39 | 00,283,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
< %systemroot%\system32\drivers\*.exe >
< %systemroot%\system32\drivers\*.dat >
< %systemroot%\system\*.exe >
< %PROGRAMFILES%\*.* >
< %APPDATA%\*.* >
[2009/07/11 17:45:30 | 01,074,008 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\8d51356f4bb435f1b6f84a242a76b34c-i686.cache-2
[2007/10/24 12:03:23 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\desktop.ini
[2007/12/29 04:14:51 | 00,087,608 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\inst.exe
[2007/12/29 04:14:51 | 00,007,887 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\pcouffin.cat
[2007/12/29 04:14:51 | 00,001,144 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\pcouffin.inf
[2007/12/29 04:14:56 | 00,000,034 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\pcouffin.log
[2007/12/29 04:14:51 | 00,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\Jon Lam\Application Data\pcouffin.sys
[2009/03/20 18:04:18 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\Jon Lam\Application Data\winscp.rnd
< set /c >
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Jon Lam\Application Data
CLASSPATH=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=JONO
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Jon Lam
LMC_HOME=C:\Xilinx\10.1\ISE\smartmodel\nt\installed_nt
LM_LICENSE_FILE=C:\Documents and Settings\Jon Lam\Project Nav\license.dat;C:\Documents and Settings\Jon Lam\Desktop\license.dat
LOGONSERVER=\\JONO
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\Jon Lam\Application Data\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\Xilinx\10.1\ISE\bin\nt;C:\Xilinx\10.1\ISE\lib\nt;C:\Xilinx\10.1\ISE\smartmodel\nt\installed_nt\lib\pcnt.lib;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\MATLAB\R2007b\bin;C:\Program Files\MATLAB\R2007b\bin\win32;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\SSH Communications Security\SSH Secure Shell;C:\Modeltech_xe_starter\win32xoem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 10, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0a
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\JONLAM~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\JONLAM~1\LOCALS~1\Temp
USERDOMAIN=JONO
USERNAME=Jon Lam
USERPROFILE=C:\Documents and Settings\Jon Lam
windir=C:\WINDOWS
XILINX=C:\Xilinx\10.1\ISE
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 8/11/2009 12:38:26 AM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\Jon Lam\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 123.73 Gb Total Space | 24.30 Gb Free Space | 19.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 25.21 Gb Total Space | 2.82 Gb Free Space | 11.17% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JONO
Current User Name: Jon Lam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = YBrowser.HTML] -- C:\Program Files\Yahoo!\browser\ybrowser.exe (Yahoo!, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"6112:TCP" = 6112:TCP:*:Enabled:frozen throne
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"58121:TCP" = 58121:TCP:*:Enabled:Pando Media Booster
"58121:UDP" = 58121:UDP:*:Enabled:Pando Media Booster
"8395:TCP" = 8395:TCP:*:Enabled:League of Legends Launcher
"8395:UDP" = 8395:UDP:*:Enabled:League of Legends Launcher
"8396:TCP" = 8396:TCP:*:Enabled:League of Legends Launcher
"8396:UDP" = 8396:UDP:*:Enabled:League of Legends Launcher
"8397:TCP" = 8397:TCP:*:Enabled:League of Legends Launcher
"8397:UDP" = 8397:UDP:*:Enabled:League of Legends Launcher
"8398:TCP" = 8398:TCP:*:Enabled:League of Legends Launcher
"8398:UDP" = 8398:UDP:*:Enabled:League of Legends Launcher
"8399:TCP" = 8399:TCP:*:Enabled:League of Legends Launcher
"8399:UDP" = 8399:UDP:*:Enabled:League of Legends Launcher
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\Starcraft\StarCraft.exe" = C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft - Brood War -- (Blizzard Entertainment)
"C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe" = C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:*:Enabled:Battlefield 2 -- ()
"C:\Program Files\systemhound\Collector.exe" = C:\Program Files\systemhound\Collector.exe:*:Disabled:systemhound collector -- (Software Innovations UK Limited)
"C:\Documents and Settings\Jon Lam\Local Settings\Temp\WZSE0.TMP\SymNRT.exe" = C:\Documents and Settings\Jon Lam\Local Settings\Temp\WZSE0.TMP\SymNRT.exe:*:Enabled:Symantec Removal Utility -- File not found
"C:\Documents and Settings\Jon Lam\Local Settings\Temp\WZSE1.TMP\SymNRT.exe" = C:\Documents and Settings\Jon Lam\Local Settings\Temp\WZSE1.TMP\SymNRT.exe:*:Enabled:Symantec Removal Utility -- File not found
"C:\ijji\ENGLISH\u_gbound.exe" = C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:<ijji Downloader> -- (NHN USA inc.)
"C:\Program Files\ijji\ENGLISH\Gunbound Revolution\GunBound.gme" = C:\Program Files\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound -- (Softnyx)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"C:\Program Files\Deusty\Mojo\Mojo.exe" = C:\Program Files\Deusty\Mojo\Mojo.exe:*:Enabled:Mojo -- File not found
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
"C:\Program Files\Steam\steamapps\beebop89\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\beebop89\team fortress 2\hl2.exe:*:Enabled:hl2 -- ()
"C:\Program Files\wLite\wLite.exe" = C:\Program Files\wLite\wLite.exe:*:Enabled:webcamXP -- File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Steam\steamapps\jimmyclackers21@yahoo.com\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\jimmyclackers21@yahoo.com\team fortress 2\hl2.exe:*:Enabled:hl2 -- ()
"C:\Program Files\Warcraft III\Frozen Throne.exe" = C:\Program Files\Warcraft III\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne -- (Blizzard Entertainment)
"C:\Program Files\Steam\steamapps\jimmyclackers21@yahoo.com\counter-strike source\hl2.exe" = C:\Program Files\Steam\steamapps\jimmyclackers21@yahoo.com\counter-strike source\hl2.exe:*:Enabled:hl2 -- ()
"C:\Documents and Settings\Jon Lam\Local Settings\Temp\Blizzard Launcher Temporary - 0efa5e88\Launcher.exe" = C:\Documents and Settings\Jon Lam\Local Settings\Temp\Blizzard Launcher Temporary - 0efa5e88\Launcher.exe:*:Enabled:Blizzard Launcher -- File not found
"C:\Xilinx\10.1\ISE\bin\nt\_pn.exe" = C:\Xilinx\10.1\ISE\bin\nt\_pn.exe:*:Enabled:Xilinx - ISE -- (Xilinx Inc.)
"C:\Modeltech_xe_starter\win32xoem\vish.exe" = C:\Modeltech_xe_starter\win32xoem\vish.exe:*:Enabled:vish -- ()
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\pulseaudio-0.9.6\pulseaudio.exe" = C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\pulseaudio-0.9.6\pulseaudio.exe:*:Enabled:pulseaudio -- File not found
"C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\Xming\Xming.exe" = C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\Xming\Xming.exe:*:Enabled:Xming X Server -- File not found
"C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\colinux-slirp-net-daemon.exe" = C:\Documents and Settings\Jon Lam\Desktop\Portable_Ubuntu\colinux-slirp-net-daemon.exe:*:Enabled:coLinux daemon program -- File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)
"C:\Program Files\Tournament Indicator\Indicator.exe" = C:\Program Files\Tournament Indicator\Indicator.exe:*:Enabled:Tournament Indicator -- File not found
"C:\Riot Games\League of Legends\Air\LolClient.exe" = C:\Riot Games\League of Legends\Air\LolClient.exe:*:Enabled:League of Legends Lobby -- ()
"C:\Riot Games\League of Legends\Game\League of Legends.exe" = C:\Riot Games\League of Legends\Game\League of Legends.exe:*:Enabled:League of Legends Game Client -- ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP90" = Canon iP90
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 14
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = Logitech Registration
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45C86D91-32E5-4422-9CA7-DF30EBF005FF}" = Adept
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}" = SSH Secure Shell
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3382A07-BFF1-4A8D-9524-DEF82AE3F58B}" = League of Legends
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{B076073A-5527-4F4F-B46B-B10692277DA2}" = DisplayFusion
"{B0D588B4-4AE2-4A1D-AC44-119BD0B62A22}" = systemhound-central-server
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B3B4CD34-6C20-4b28-A231-FEC55B42C579}" = c6100_Help
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C02E178A-52FA-3266-E945-BE38D3171033}" = Nero 7 Ultra Edition
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8574AE5-370F-4246-A301-B85A2CC89A5E}" = C6100
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DF62D775-BB7C-4AFA-9CA4-DDA1C4855F28}" = Dell Mobile Broadband Card Utility
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = AusLogics Disk Defrag
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{ED472FBE-FF70-47CE-B1A1-B22365EE9304}" = ModelSim XE III 6.3c
"{ED50ECE9-EC54-4C05-B5ED-EE4741A9F2EC}" = Battlefield 2142
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}" = Pinnacle TVCenter Pro
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"2600BA1ED6C80F04935D3D8F92F569EE52C29F5C" = Windows Driver Package - Digilent (dmodusb) USB (8/10/2004 )
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"AIM Toolbar" = AIM Toolbar 5.0
"AIM_6" = AIM 6
"Aplus DVD Copy_is1" = Aplus DVD Copy 8.79
"AVG8Uninstall" = AVG Free 8.5
"AviSynth" = AviSynth 2.5
"CamStudio" = CamStudio
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"dBpowerAMP AAC Codec" = dBpowerAMP AAC Codec
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp m4a Codec" = dBpoweramp m4a Codec
"dBpoweramp m4b Audio book Encoder" = dBpoweramp m4b Audio book Encoder
"dBpowerAMP Mp4 Codec" = dBpowerAMP Mp4 Codec
"dBpoweramp Musepack Codec" = dBpoweramp Musepack Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"dBpowerAMP WMA V9.1 Codec" = dBpowerAMP WMA V9.1 Codec
"DELL Webcam Center" = DELL Webcam Center
"DELL Webcam Manager" = DELL Webcam Manager
"dMC Power Pack" = dMC Power Pack
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVDFab Platinum 4_is1" = DVDFab Platinum 4.1.2.0
"ERUNT_is1" = ERUNT 1.1j
"FahMon" = FahMon - Folding@home client monitoring software
"Guitar Pro 5_is1" = Guitar Pro 5.0
"Gunbound Revolution_is1" = Gunbound Revolution
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"iDump" = iDump (Backing up your iPod)
"ie7" = Windows Internet Explorer 7
"LastFM_is1" = Last.fm 1.5.0.24910
"Launchy_21344213_is1" = Launchy 2.1.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabR2007b" = MATLAB R2007b
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PC Wizard 2008_is1" = PC Wizard 2008.1.80
"PDF Password Remover v2.5_is1" = PDF Password Remover v2.5
"PeerGuardian_is1" = PeerGuardian 2.0
"PellesC" = Pelles C for Windows (remove only)
"PowerISO" = PowerISO
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 6.0" = RealPlayer
"RollerCoaster Tycoon® 3 Platinum" = RollerCoaster Tycoon® 3 Platinum
"SharpReader_is1" = SharpReader 0.9.7.0
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SpeedFan" = SpeedFan (remove only)
"Starcraft" = Starcraft
"Steam App 10" = Counter-Strike
"Steam App 12900" = Audiosurf
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"StepMania" = StepMania (remove only)
"SyncBack_is1" = SyncBack
"SystemRequirementsLab" = System Requirements Lab
"TeraCopy_is1" = TeraCopy 1.22
"The Rosetta Stone" = The Rosetta Stone
"Tweak UI 2.10" = Tweak UI
"Videora iPod Converter" = Videora iPod Converter 0.91
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WinAVI Video Converter_is1" = WinAVI Video Converter
"WinDjView" = WinDjView 1.0.1
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wootalyzer" = Wootalyzer!
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilinx ISE 10.1" = Xilinx ISE 10.1
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ijji FireFox Launcher" = ijji FireFox Launcher 1.0
"ijji.com" = ijji
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/10/2009 4:58:27 AM | Computer Name = JONO | Source = Application Hang | ID = 1001
Description = Fault bucket 1394815431.
Error - 8/10/2009 6:27:16 AM | Computer Name = JONO | Source = nview_info | ID = 11141121
Description =
Error - 8/10/2009 11:09:00 PM | Computer Name = JONO | Source = Application Error | ID = 1000
Description = Faulting application notepad.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x013a8740.
Error - 8/10/2009 11:09:00 PM | Computer Name = JONO | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x023b9060.
Error - 8/10/2009 11:09:01 PM | Computer Name = JONO | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.40.0.0, faulting module unknown,
version 0.0.0.0, fault address 0x01a18740.
Error - 8/10/2009 11:09:01 PM | Computer Name = JONO | Source = Application Error | ID = 1000
Description = Faulting application stsystra.exe, version 1.0.5511.0, faulting module
unknown, version 0.0.0.0, fault address 0x02249060.
Error - 8/10/2009 11:09:01 PM | Computer Name = JONO | Source = Application Error | ID = 1000
Description = Faulting application windows_security_update_3475_36_d.exe, version
3.3.0.0, faulting module unknown, version 0.0.0.0, fault address 0x02619060.
Error - 8/10/2009 11:09:12 PM | Computer Name = JONO | Source = Application Error | ID = 1001
Description = Fault bucket 1408978895.
Error - 8/10/2009 11:09:12 PM | Computer Name = JONO | Source = Application Error | ID = 1001
Description = Fault bucket 1408978897.
Error - 8/10/2009 11:09:13 PM | Computer Name = JONO | Source = Application Error | ID = 1001
Description = Fault bucket 1408978906.
< End of report >
***************************
--- Report generated: 2009-08-10 18:27 ---
Win32.TDSS.rtk: [SBI $79B0E3AB] File (File, fixed)
C:\WINDOWS\system32\drivers\SKYNETtlafqely.sys
Properties.size=0
Properties.md5=809A789DE00384C2DC7C88187BEC3D37
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETkbmiovuo.dll
Properties.size=0
Properties.md5=B8E6D0EB211CDFE7FEC0014933DE6E73
Win32.TDSS.rtk: [SBI $49F1C28A] File (File, fixed)
C:\WINDOWS\system32\SKYNETsvvneufq.dll
Properties.size=0
Properties.md5=6851DFF34F77A0185A2BBCB4A3ECE987
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNETfydstbtu.dat
Properties.size=0
Properties.md5=08004F558C470066869182998E12BB47
Win32.TDSS.rtk: [SBI $1A7ABF3C] File (File, fixed)
C:\WINDOWS\system32\SKYNEToepdfbvh.dat
Properties.size=0
Properties.md5=3EB2E50624A75C67983EE24A9196CE54
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2008-07-07 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-08-10 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-07-28 advcheck.dll (1.6.3.17)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-07-30 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-08-04 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-08-04 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-07-30 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-07-14 Includes\Malware.sbi (*)
2009-08-05 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-08-04 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-07-30 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-08-04 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-07-22 Includes\Trojans.sbi (*)
2009-08-05 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Thanks in advance for the help.


