<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
<channel>
	<title>Malware</title>
	<description>Malware Removal Threads</description>
	<link>http://www.atribune.org/forums/index.php</link>
	<pubDate>Fri, 20 Nov 2009 23:18:50 +0100</pubDate>
	<ttl>0</ttl>
	<item>
		<title>Need help with Vundo.h infection</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5873</link>
		<description><![CDATA[My wife's XP SP2 laptop has a very persistent vundo.h infection. I managed to clean up the suite of other crap that came along with it with AVG, SpyBot, and Malwarebytes, but the root infection won't go away. I can't delete the .dlls and the registry entries just come back immediately. I've tried the above programs as well as fixvundo, vundofix, etc. Help please!<br /><br />I've tried to follow the instruction in the "before you post". Running thecomedian.exe was skipped since the program crashed. <br /><br />Logs attached...<br /><br />Thanks,<br />-Dan]]></description>
		<pubDate>Thu, 19 Nov 2009 02:49:43 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5873</guid>
	</item>
	<item>
		<title>Possibly cured, but was it a Vundo/ lsas.blaster.keylogger</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5863</link>
		<description><![CDATA[Atribune has helped me learn a lot in the past, and taught me a lot about battling viruses, so I seeked out this forum again to see if I did it right. Thanks!<br />Anyway,<br />Last week I somehow got this "lsas.blaster.keylogger", a fake virus that comes with a program that pretends to be an antivirus-antimalware but is actually a fake.  <br /><br />I used a variety of things: malwarebites, spywaredoctor, windowsdefender, SUPERantispyware and got rid of it.<br /><br />BUT, yesterday, malwarebites was mysteriously corrupted, spyware doctor found 140 infections and SUPERantispyware found some Vundo files all at once!  <br /><br />So, I deleted all of those bad files, used a recovery point and got it working again.<br /><br />BUT, did I get rid of everything?  I ran Clean up! then created the following Hijack-this log this morning:<br /><br />--------------------------------------<br /><br />Logfile of Trend Micro HijackThis v2.0.2<br />Scan saved at 7:30:13 AM, on 11/10/2009<br />Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />MSIE: Internet Explorer v8.00 (8.00.6001.18828)<br />Boot mode: Normal<br /><br />Running processes:<br />C:&#092;Windows&#092;system32&#092;taskeng.exe<br />C:&#092;Windows&#092;SYSTEM32&#092;WISPTIS.EXE<br />C:&#092;Program Files&#092;Common Files&#092;microsoft shared&#092;ink&#092;TabTip.exe<br />C:&#092;Windows&#092;system32&#092;Dwm.exe<br />C:&#092;Windows&#092;Explorer.EXE<br />C:&#092;Windows&#092;system32&#092;WTablet&#092;Wacom_TabletUser.exe<br />C:&#092;Program Files&#092;Windows Defender&#092;MSASCui.exe<br />C:&#092;WINDOWS&#092;RtHDVCpl.exe<br />C:&#092;hp&#092;support&#092;hpsysdrv.exe<br />C:&#092;Program Files&#092;Hewlett-Packard&#092;On-Screen OSD Indicator&#092;OSD.exe<br />C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAAnotif.exe<br />C:&#092;Program Files&#092;Lexmark 5400 Series&#092;lxctmon.exe<br />C:&#092;Program Files&#092;Lexmark 5400 Series&#092;ezprint.exe<br />C:&#092;Program Files&#092;Logitech&#092;QuickCam&#092;Quickcam.exe<br />C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;hpwuschd2.exe<br />C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Advisor&#092;HPAdvisor.exe<br />C:&#092;Users&#092;Lou  (admin)&#092;Program Files&#092;DNA&#092;btdna.exe<br />C:&#092;Program Files&#092;SUPERAntiSpyware&#092;SUPERANTISPYWARE.EXE<br />C:&#092;Users&#092;Lou  (admin)&#092;AppData&#092;Local&#092;Google&#092;Update&#092;GoogleUpdate.exe<br />C:&#092;Program Files&#092;Windows Media Player&#092;wmpnscfg.exe<br />C:&#092;Program Files&#092;Common Files&#092;microsoft shared&#092;ink&#092;InputPersonalization.exe<br />C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;ymsgr_tray.exe<br />C:&#092;Program Files&#092;Common Files&#092;Logishrd&#092;LQCVFX&#092;COCIManager.exe<br />C:&#092;Program Files&#092;mozilla firefox&#092;firefox.exe<br />C:&#092;hp&#092;kbd&#092;kbd.exe<br />C:&#092;Windows&#092;system32&#092;taskeng.exe<br />C:&#092;Users&#092;Lou  (admin)&#092;Downloads&#092;HijackThis.exe<br /><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://www.dellnet.com/" target="_blank">http://www.dellnet.com/</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://gmail.google.com/" target="_blank">http://gmail.google.com/</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,(Default) = <a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn1&#092;yt.dll<br />O1 - Hosts: ::1 localhost<br />O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn1&#092;yt.dll<br />O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelper.dll<br />O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)<br />O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:&#092;Program Files&#092;Norton AntiVirus&#092;Engine&#092;16.5.0.134&#092;IPSBHO.DLL<br />O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:&#092;Program Files&#092;Java&#092;jre1.6.0_01&#092;bin&#092;ssv.dll<br />O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Windows Live&#092;WindowsLiveLogin.dll<br />O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn1&#092;YTSingleInstance.dll<br />O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;PROGRA~1&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn1&#092;yt.dll<br />O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)<br />O4 - HKLM&#092;..&#092;Run: [Windows Defender] %ProgramFiles%&#092;Windows Defender&#092;MSASCui.exe -hide<br />O4 - HKLM&#092;..&#092;Run: [RtHDVCpl] RtHDVCpl.exe<br />O4 - HKLM&#092;..&#092;Run: [hpsysdrv] c:&#092;hp&#092;support&#092;hpsysdrv.exe<br />O4 - HKLM&#092;..&#092;Run: [KBD] C:&#092;HP&#092;KBD&#092;KbdStub.EXE<br />O4 - HKLM&#092;..&#092;Run: [OsdMaestro] "C:&#092;Program Files&#092;Hewlett-Packard&#092;On-Screen OSD Indicator&#092;OSD.exe"<br />O4 - HKLM&#092;..&#092;Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard&#092;HP Health Check&#092;HPHC_Scheduler.exe<br />O4 - HKLM&#092;..&#092;Run: [IAAnotif] "C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;Iaanotif.exe"<br />O4 - HKLM&#092;..&#092;Run: [lxctmon.exe] "C:&#092;Program Files&#092;Lexmark 5400 Series&#092;lxctmon.exe"<br />O4 - HKLM&#092;..&#092;Run: [Lexmark 5400 Series Fax Server] "C:&#092;Program Files&#092;Lexmark 5400 Series&#092;fm3032.exe" /s<br />O4 - HKLM&#092;..&#092;Run: [EzPrint] "C:&#092;Program Files&#092;Lexmark 5400 Series&#092;ezprint.exe"<br />O4 - HKLM&#092;..&#092;Run: [LXCTCATS] rundll32 C:&#092;Windows&#092;system32&#092;spool&#092;DRIVERS&#092;W32X86&#092;3&#092;LXCTtime.dll,_RunDLLEntry@16<br />O4 - HKLM&#092;..&#092;Run: [LogitechQuickCamRibbon] "C:&#092;Program Files&#092;Logitech&#092;QuickCam&#092;Quickcam.exe" /hide<br />O4 - HKLM&#092;..&#092;Run: [HP Software Update] C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe<br />O4 - HKCU&#092;..&#092;Run: [HPAdvisor] C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Advisor&#092;HPAdvisor.exe view=DOCKVIEW,SYSTRAY<br />O4 - HKCU&#092;..&#092;Run: [BitTorrent DNA] "C:&#092;Users&#092;Lou  (admin)&#092;Program Files&#092;DNA&#092;btdna.exe"<br />O4 - HKCU&#092;..&#092;Run: [SUPERAntiSpyware] C:&#092;Program Files&#092;SUPERAntiSpyware&#092;SUPERAntiSpyware.exe<br />O4 - HKCU&#092;..&#092;Run: [Messenger (Yahoo!)] "C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;YahooMessenger.exe" -quiet<br />O4 - HKCU&#092;..&#092;Run: [Google Update] "C:&#092;Users&#092;Lou  (admin)&#092;AppData&#092;Local&#092;Google&#092;Update&#092;GoogleUpdate.exe" /c<br />O4 - HKCU&#092;..&#092;Run: [WMPNSCFG] C:&#092;Program Files&#092;Windows Media Player&#092;WMPNSCFG.exe<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />O4 - Startup: Adobe Gamma.lnk = C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Calibration&#092;Adobe Gamma Loader.exe<br />O4 - Global Startup: Adobe Gamma Loader.lnk = C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Calibration&#092;Adobe Gamma Loader.exe<br />O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;EXCEL.EXE/3000<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;Program Files&#092;Java&#092;jre1.6.0_01&#092;bin&#092;ssv.dll<br />O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;Program Files&#092;Java&#092;jre1.6.0_01&#092;bin&#092;ssv.dll<br />O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:&#092;Program Files&#092;Bonjour&#092;ExplorerPlugin.dll<br />O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~1&#092;MICROS~3&#092;Office12&#092;REFIEBAR.DLL<br />O13 - Gopher Prefix: <br />O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:&#092;PROGRA~1&#092;COMMON~1&#092;Skype&#092;SKYPE4~1.DLL<br />O20 - Winlogon Notify: !SASWinLogon - C:&#092;Program Files&#092;SUPERAntiSpyware&#092;SASWINLO.DLL<br />O23 - Service: 1230320092 (.1230320092) - Unknown owner - C:&#092;ProgramData&#092;Lou  (admin)1230320092.exe<br />O23 - Service: Adobe LM Service - Adobe Systems - C:&#092;Program Files&#092;Common Files&#092;Adobe Systems Shared&#092;Service&#092;Adobelmsvc.exe<br />O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:&#092;Program Files&#092;Common Files&#092;Macrovision Shared&#092;FLEXnet Publisher&#092;FNPLicensingService.exe<br />O23 - Service: HP Health Check Service - Hewlett-Packard - c:&#092;Program Files&#092;Hewlett-Packard&#092;HP Health Check&#092;hphc_service.exe<br />O23 - Service: Intel&reg; Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;Iaantmon.exe<br />O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:&#092;Program Files&#092;Common Files&#092;Intuit&#092;Update Service&#092;IntuitUpdateService.exe<br />O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:&#092;Program Files&#092;Common Files&#092;LogiShrd&#092;LVMVFM&#092;LVPrcSrv.exe<br />O23 - Service: lxct_device -   - C:&#092;Windows&#092;system32&#092;lxctcoms.exe<br />O23 - Service: Norton AntiVirus - Symantec Corporation - C:&#092;Program Files&#092;Norton AntiVirus&#092;Engine&#092;16.5.0.134&#092;ccSvcHst.exe<br />O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:&#092;Windows&#092;system32&#092;nvvsvc.exe<br />O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:&#092;Program Files&#092;NVIDIA Corporation&#092;3D Vision&#092;nvSCPAPISvr.exe<br />O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:&#092;Windows&#092;system32&#092;Wacom_Tablet.exe<br />O23 - Service: XAudioService - Conexant Systems, Inc. - C:&#092;Windows&#092;system32&#092;DRIVERS&#092;xaudio.exe<br /><br />--<br />End of file - 9368 bytes<br />]]></description>
		<pubDate>Tue, 10 Nov 2009 15:32:57 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5863</guid>
	</item>
	<item>
		<title>Vundo Infected - Would Like Help With Final Cleaning Up</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5872</link>
		<description><![CDATA[I was infected by a Vundo variant while working on a machine that had not been connected to the Internet in years.  Before I could get it up to date with patches and anti-virus, I got hit by a drive-by download, probably when I was downloading an image to use as desktop wallpaper (in retrospect, going there before getting fully patched was very dumb, I know).  I was infected just by visiting one of these websites, I believe, without even clicking on a bogus link.<br /><br />Before I discovered this site, I found another site showing the exact phony control panel that came up on my system, so I followed the advice there, which involved running FreeFixer.  I subsequently ran Spybot S&D.  These were both helpful, but neither could completely remove the infection.  Then I came here.  Malwarebytes' Anti-Malware has mostly taken out the infection, but from a scan of the OTL log I can see that there are still a few files in the WINDOWS&#092;System32 folder that clearly look related to the infection, so I'd like to get advice on what to do to completely remove every last trace of this ***damn thing.<br /><br />By the way, this infection prevented the Malwarebytes' mbam.exe file from getting installed, so I had to install on a clean system, rename that executable and copy it over to the infected system.  You might want to update your "before you post" instructions to reflect that possibility.<br /><br />Here are all the logs, in order as per "before you post".  I'll send them over multiple posts.<br /><br />I'm also including the latest FreeFixer log, in case there's any helpful clues in there.<br /><br />Thanks in advance for any help you can give.  Cheers.<br /><br />-Linc]]></description>
		<pubDate>Tue, 17 Nov 2009 03:10:40 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5872</guid>
	</item>
	<item>
		<title>mcafee blocking buffer overflow error</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5874</link>
		<description><![CDATA[Mcafee is blocking buffer overflow in<br /><br />C:&#092;windows&#092;system32&#092;dllhost.exe<br /><br />i got this after downloading a file converting program<br /><br />here are the logs lockseardh opened but that was all that happened.<br />I let it rum for about a half an hour with no result.<br /><br />OTL & EXTRAS<br /><br />OTL logfile created on: 11/17/2009 12:11:52 AM - Run 1<br />OTL by OldTimer - Version 3.1.6.0     Folder = C:&#092;Users&#092;family&#092;Downloads<br />Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation<br />Internet Explorer (Version = 8.0.6001.18828)<br />Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br /> <br />1.99 Gb Total Physical Memory | 0.61 Gb Available Physical Memory | 30.70% Memory free<br />4.00 Gb Paging File | 2.91 Gb Available in Paging File | 72.77% Paging File free<br />Paging file location(s): ?:&#092;pagefile.sys [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;Windows | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 325.89 Gb Total Space | 142.43 Gb Free Space | 43.70% Space Free | Partition Type: NTFS<br />Drive D: | 9.46 Gb Total Space | 1.28 Gb Free Space | 13.54% Space Free | Partition Type: NTFS<br />Drive E: | 1003.03 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF<br />F: Drive not present or media not loaded<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />I: Drive not present or media not loaded<br /> <br />Computer Name: FAMILY-PC<br />Current User Name: family<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 14 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Processes (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />PRC - [2009/11/17 00:08:13 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:&#092;Users&#092;family&#092;Downloads&#092;OTL.exe<br />PRC - [2009/11/08 10:38:07 | 00,788,368 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe<br />PRC - [2009/11/08 10:38:05 | 01,179,232 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe<br />PRC - [2009/10/11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe<br />PRC - [2009/09/21 15:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe<br />PRC - [2009/09/21 15:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe<br />PRC - [2009/09/17 13:29:04 | 00,865,832 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe<br />PRC - [2009/09/17 13:29:04 | 00,645,328 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee.com&#092;Agent&#092;mcagent.exe<br />PRC - [2009/09/16 09:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;Mcshield.exe<br />PRC - [2009/09/16 08:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcsysmon.exe<br />PRC - [2009/09/15 09:23:54 | 00,894,136 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MpfSrv.exe<br />PRC - [2009/07/08 10:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;McProxy&#092;McProxy.exe<br />PRC - [2009/07/07 18:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;MNA&#092;McNASvc.exe<br />PRC - [2009/06/05 10:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />PRC - [2009/05/26 20:06:32 | 00,079,088 | ---- | M] (Yahoo! Inc.) -- C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;Ymsgr_tray.exe<br />PRC - [2009/04/11 01:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;System32&#092;wbem&#092;WmiPrvSE.exe<br />PRC - [2009/04/11 01:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;System32&#092;wbem&#092;WmiPrvSE.exe<br />PRC - [2009/04/11 01:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;System32&#092;wbem&#092;unsecapp.exe<br />PRC - [2009/04/11 01:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;System32&#092;wbem&#092;unsecapp.exe<br />PRC - [2009/04/11 01:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe<br />PRC - [2009/04/11 01:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe<br />PRC - [2009/04/11 01:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;explorer.exe<br />PRC - [2009/03/17 12:25:40 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe<br />PRC - [2009/02/26 19:57:18 | 00,252,952 | ---- | M] (Intel Corporation) -- C:&#092;Windows&#092;System32&#092;igfxsrvc.exe<br />PRC - [2009/02/26 19:57:16 | 00,150,552 | ---- | M] (Intel Corporation) -- C:&#092;Windows&#092;System32&#092;igfxpers.exe<br />PRC - [2009/02/26 19:57:12 | 00,173,592 | ---- | M] (Intel Corporation) -- C:&#092;Windows&#092;System32&#092;hkcmd.exe<br />PRC - [2009/02/23 08:05:34 | 00,111,856 | ---- | M] (Yahoo! Inc) -- C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe<br />PRC - [2009/02/18 13:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v3.0&#092;WPF&#092;PresentationFontCache.exe<br />PRC - [2009/01/23 09:46:14 | 00,203,280 | ---- | M] () -- C:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;McSACore.exe<br />PRC - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe<br />PRC - [2008/11/09 15:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe<br />PRC - [2008/06/02 18:50:34 | 00,354,840 | ---- | M] (Intel Corporation) -- C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAANTmon.exe<br />PRC - [2008/06/02 18:50:32 | 00,178,712 | ---- | M] (Intel Corporation) -- C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAAnotif.exe<br />PRC - [2008/03/25 19:49:02 | 00,184,320 | ---- | M] (Hewlett-Packard Co.) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqste08.exe<br />PRC - [2008/03/25 19:49:00 | 00,569,344 | ---- | M] (Hewlett-Packard Co.) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqbam08.exe<br />PRC - [2008/03/25 19:40:42 | 00,214,360 | ---- | M] (Hewlett-Packard Co.) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe<br />PRC - [2008/01/19 02:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Media Player&#092;wmpnetwk.exe<br />PRC - [2008/01/19 02:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Media Player&#092;wmpnscfg.exe<br />PRC - [2008/01/19 02:33:09 | 00,125,952 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;ehome&#092;ehtray.exe<br />PRC - [2008/01/19 02:33:09 | 00,037,376 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;ehome&#092;ehmsas.exe<br />PRC - [2007/11/02 20:12:50 | 00,262,144 | ---- | M] (Hewlett-Packard) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqgpc01.exe<br />PRC - [2007/10/18 06:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:&#092;Windows&#092;System32&#092;drivers&#092;XAudio.exe<br />PRC - [2007/10/14 21:17:32 | 00,049,152 | ---- | M] (Hewlett-Packard) -- C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;hpwuSchd2.exe<br />PRC - [2007/10/03 21:02:02 | 01,783,136 | ---- | M] (Hewlett-Packard) -- C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Advisor&#092;HPAdvisor.exe<br />PRC - [2007/10/02 10:30:08 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Motive&#092;McciCMService.exe<br />PRC - [2007/09/19 20:30:52 | 00,065,536 | ---- | M] (Hewlett-Packard) -- c:&#092;Program Files&#092;Hewlett-Packard&#092;HP Health Check&#092;HPHC_Service.exe<br />PRC - [2007/07/24 13:15:14 | 00,185,632 | ---- | M] (Protexis Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Protexis&#092;License Service&#092;PsiService_2.exe<br />PRC - [2007/04/25 13:18:48 | 00,537,520 | ---- | M] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvcoms.exe<br />PRC - [2007/04/12 19:59:48 | 00,198,184 | ---- | M] (SupportSoft, Inc.) -- C:&#092;Program Files&#092;FastAccessDSL&#092;HelpCenter43&#092;bin&#092;sprtcmd.exe<br />PRC - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:&#092;Program Files&#092;Viewpoint&#092;Common&#092;ViewpointService.exe<br />PRC - [2006/11/02 20:40:12 | 00,174,656 | ---- | M] () -- C:&#092;Windows&#092;System32&#092;PSIService.exe<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Modules (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />MOD - [2009/11/17 00:08:13 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:&#092;Users&#092;family&#092;Downloads&#092;OTL.exe<br />MOD - [2009/04/11 01:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0&#092;comctl32.dll<br />MOD - [2009/01/23 09:46:18 | 00,013,840 | ---- | M] () -- C:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;sahook.dll<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Win32 Services (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br />SRV - File not found --  -- (npkcmsvc)<br />SRV - [2009/11/08 10:38:05 | 01,179,232 | ---- | M] (Lavasoft) -- C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe -- (Lavasoft Ad-Aware Service)<br />SRV - [2009/09/24 20:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;System32&#092;FntCache.dll -- (FontCache)<br />SRV - [2009/09/21 15:36:02 | 00,545,568 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;iPod&#092;bin&#092;iPodService.exe -- (iPod Service)<br />SRV - [2009/09/17 13:29:04 | 00,865,832 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe -- (mcmscsvc)<br />SRV - [2009/09/16 10:23:32 | 00,365,072 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe -- (McODS)<br />SRV - [2009/09/16 09:22:08 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;Mcshield.exe -- (McShield)<br />SRV - [2009/09/16 08:28:38 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcsysmon.exe -- (McSysmon)<br />SRV - [2009/09/15 09:23:54 | 00,894,136 | ---- | M] (McAfee, Inc.) -- C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MPFSrv.exe -- (MpfService)<br />SRV - [2009/07/08 10:54:34 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;McProxy&#092;McProxy.exe -- (McProxy)<br />SRV - [2009/07/07 18:10:02 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:&#092;Program Files&#092;Common Files&#092;McAfee&#092;MNA&#092;McNASvc.exe -- (McNASvc)<br />SRV - [2009/06/05 10:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe -- (Apple Mobile Device)<br />SRV - [2009/05/14 20:40:41 | 00,085,096 | ---- | M] (Autodesk) -- C:&#092;Program Files&#092;Common Files&#092;Autodesk Shared&#092;Service&#092;AdskScSrv.exe -- (Autodesk Licensing Service)<br />SRV - [2009/04/25 10:23:23 | 00,133,104 | ---- | M] (Google Inc.) -- C:&#092;Program Files&#092;Google&#092;Update&#092;GoogleUpdate.exe -- (gupdate1c9c5b9d01dc851)<br />SRV - [2009/03/29 23:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v2.0.50727&#092;mscorsvw.exe -- (clr_optimization_v2.0.50727_32)<br />SRV - [2009/03/23 20:31:03 | 00,183,280 | ---- | M] (Google) -- C:&#092;Program Files&#092;Google&#092;Common&#092;Google Updater&#092;GoogleUpdaterService.exe -- (gusvc)<br />SRV - [2009/03/17 12:25:40 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:&#092;Program Files&#092;Common Files&#092;LightScribe&#092;LSSrvc.exe -- (LightScribeService)<br />SRV - [2009/02/18 13:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v3.0&#092;WPF&#092;PresentationFontCache.exe -- (FontCache3.0.0.0)<br />SRV - [2009/02/18 13:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v3.0&#092;Windows Communication Foundation&#092;SMSvcHost.exe -- (NetTcpPortSharing)<br />SRV - [2009/02/18 13:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v3.0&#092;Windows Communication Foundation&#092;infocard.exe -- (idsvc)<br />SRV - [2009/01/23 09:46:14 | 00,203,280 | ---- | M] () -- C:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;McSACore.exe -- (McAfee SiteAdvisor Service)<br />SRV - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Bonjour&#092;mDNSResponder.exe -- (Bonjour Service)<br />SRV - [2008/11/09 15:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:&#092;Program Files&#092;Yahoo!&#092;SoftwareUpdate&#092;YahooAUService.exe -- (YahooAUService)<br />SRV - [2008/07/18 12:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) -- C:&#092;Windows&#092;System32&#092;HPZipm12.dll -- (Pml Driver HPZ12)<br />SRV - [2008/07/18 12:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) -- C:&#092;Windows&#092;System32&#092;HPZinw12.dll -- (Net Driver HPZ12)<br />SRV - [2008/06/02 18:50:34 | 00,354,840 | ---- | M] (Intel Corporation) -- C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAANTmon.exe -- (IAANTMON)<br />SRV - [2008/03/25 20:27:36 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqddsvc.dll -- (hpqddsvc)<br />SRV - [2008/03/25 19:38:24 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqcxs08.dll -- (hpqcxs08)<br />SRV - [2008/01/19 02:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Defender&#092;MpSvc.dll -- (WinDefend)<br />SRV - [2008/01/19 02:33:39 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Windows Media Player&#092;wmpnetwk.exe -- (WMPNetworkSvc)<br />SRV - [2008/01/19 02:33:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;ehome&#092;ehrecvr.exe -- (ehRecvr)<br />SRV - [2007/10/18 06:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:&#092;Windows&#092;System32&#092;drivers&#092;XAudio.exe -- (XAudioService)<br />SRV - [2007/10/02 10:30:08 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Motive&#092;McciCMService.exe -- (McciCMService)<br />SRV - [2007/09/19 20:30:52 | 00,065,536 | ---- | M] (Hewlett-Packard) -- c:&#092;Program Files&#092;Hewlett-Packard&#092;HP Health Check&#092;hphc_service.exe -- (HP Health Check Service)<br />SRV - [2007/07/24 13:15:14 | 00,185,632 | ---- | M] (Protexis Inc.) -- C:&#092;Program Files&#092;Common Files&#092;Protexis&#092;License Service&#092;PsiService_2.exe -- (PSI_SVC_2)<br />SRV - [2007/04/25 13:18:48 | 00,537,520 | ---- | M] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvcoms.exe -- (lxbv_device)<br />SRV - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:&#092;Program Files&#092;Viewpoint&#092;Common&#092;ViewpointService.exe -- (Viewpoint Manager Service)<br />SRV - [2006/12/14 01:21:20 | 00,045,056 | ---- | M] (Sony Corporation) -- C:&#092;Program Files&#092;Common Files&#092;Sony Shared&#092;AVLib&#092;MSCSPTISRV.exe -- (MSCSPTISRV)<br />SRV - [2006/12/14 01:02:08 | 00,069,632 | ---- | M] (Sony Corporation) -- C:&#092;Program Files&#092;Common Files&#092;Sony Shared&#092;AVLib&#092;SPTISRV.exe -- (SPTISRV)<br />SRV - [2006/12/14 00:46:16 | 00,057,344 | ---- | M] () -- C:&#092;Program Files&#092;Common Files&#092;Sony Shared&#092;AVLib&#092;PACSPTISVR.exe -- (PACSPTISVR)<br />SRV - [2006/11/02 20:40:12 | 00,174,656 | ---- | M] () -- C:&#092;Windows&#092;System32&#092;PSIService.exe -- (ProtexisLicensing)<br />SRV - [2006/11/02 07:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;ehome&#092;ehsched.exe -- (ehSched)<br />SRV - [2006/11/02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:&#092;Windows&#092;ehome&#092;ehstart.dll -- (ehstart)<br />SRV - [2005/04/03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:&#092;Program Files&#092;Common Files&#092;InstallShield&#092;Driver&#092;11&#092;Intel 32&#092;IDriverT.exe -- (IDriverT)<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Standard Registry (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Internet Explorer ==========<!--colorc--></span><!--/colorc--><br /> <br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href="http://us.rd.yahoo.com/customize/ie/defaults/su/msgr10/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Extensions Off Page = about:NoAdd-ons<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;System32&#092;blank.htm<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Page_Transitions = 1<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr10/*http://www.yahoo.com" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Secondary Start Pages = [Binary data over 100 bytes]<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Security Risk Page = about:SecurityRisk<br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://www.yahoo.com/" target="_blank">http://www.yahoo.com/</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <a href="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" target="_blank">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomSearch = <a href="http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr10/*http://www.yahoo.com/ext/search/search.html" target="_blank">http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html</a><br />IE - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <a href="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" target="_blank">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm</a><br /> <br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;system32&#092;blank.htm<br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Page_Transitions = 1<br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank">http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch</a><br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://www.yahoo.com" target="_blank">http://www.yahoo.com</a><br />IE - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Internet Explorer&#092;Main,StartPageCache = 1<br />IE - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings: "ProxyEnable" = 0<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== FireFox ==========<!--colorc--></span><!--/colorc--><br /> <br />FF - prefs.js..browser.search.defaultenginename: "Google"<br />FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="<br />FF - prefs.js..browser.search.order.1: "Ask"<br />FF - prefs.js..browser.search.selectedEngine: "Google"<br />FF - prefs.js..browser.search.useDBForOrder: true<br />FF - prefs.js..browser.startup.homepage: "http://www.google.com/"<br />FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1<br />FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5<br />FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.4<br />FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:5.0.20090813W<br />FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090525<br />FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15<br />FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8<br />FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:0.0.0<br />FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1<br />FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17<br />FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5<br /> <br /> <br />FF - HKLM&#092;software&#092;mozilla&#092;eMusic Download Manager&#092;Extensions&#092;&#092;Components: C:&#092;Program Files&#092;eMusic Download Manager&#092;xulrunner&#092;components [2009/09/16 20:46:37 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;eMusic Download Manager&#092;Extensions&#092;&#092;Plugins: C:&#092;Program Files&#092;eMusic Download Manager&#092;xulrunner&#092;plugins [2009/09/16 20:46:34 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;Firefox&#092;Extensions&#092;&#092;{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;browserrecord [2008/07/14 22:21:53 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;Firefox&#092;Extensions&#092;&#092;{20a82645-c095-46ed-80e3-08825760534b}: c:&#092;Windows&#092;Microsoft.NET&#092;Framework&#092;v3.5&#092;Windows Presentation Foundation&#092;DotNetAssistantExtension&#092; [2009/06/28 02:00:50 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;Firefox&#092;Extensions&#092;&#092;{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:&#092;Program Files&#092;McAfee&#092;SiteAdvisor [2009/10/25 08:20:04 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;Mozilla Firefox 3.5.5&#092;extensions&#092;&#092;Components: C:&#092;Program Files&#092;Mozilla Firefox&#092;components [2009/11/07 01:07:29 | 00,000,000 | ---D | M]<br />FF - HKLM&#092;software&#092;mozilla&#092;Mozilla Firefox 3.5.5&#092;extensions&#092;&#092;Plugins: C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins [2009/11/07 01:07:29 | 00,000,000 | ---D | M]<br /> <br />[2008/08/23 15:48:09 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Extensions<br />[2008/08/23 15:48:09 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Extensions&#092;{ec8030f7-c20a-464f-9b0e-13a3a9e97384}<br />[2009/11/16 00:36:03 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions<br />[2009/10/27 22:38:29 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{3112ca9c-de6d-4884-a869-9855de68056c}<br />[2009/10/18 23:52:50 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{37E4D8EA-8BDA-4831-8EA1-89053939A250}<br />[2009/07/24 07:20:15 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{77b819fa-95ad-4f2c-ac7c-486b356188a9}<br />[2009/11/04 22:49:27 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{b9db16a4-6edc-47ec-a1f4-b86292ed211d}<br />[2009/10/13 22:42:39 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}<br />[2009/05/09 08:26:42 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}<br />[2009/11/04 22:23:04 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;extensions&#092;{DDC359D1-844A-42a7-9AA1-88A850A938A8}<br />[2009/07/02 23:23:30 | 00,000,681 | ---- | M] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;searchplugins&#092;ask.xml<br />[2009/05/08 17:13:42 | 00,009,895 | ---- | M] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Mozilla&#092;Firefox&#092;Profiles&#092;elreptq3.default&#092;searchplugins&#092;mywebsearch.xml<br />[2009/11/10 01:13:32 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions<br />[2009/11/07 01:07:29 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;{972ce4c6-7e08-4474-a285-3208198ce6fd}<br />[2009/09/28 20:54:02 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}<br />[2009/11/10 01:13:32 | 00,000,000 | ---D | M] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;extensions&#092;{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}<br />[2009/11/07 01:07:23 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;browserdirprovider.dll<br />[2009/11/07 01:07:23 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;components&#092;brwsrcmp.dll<br />[2007/04/10 19:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;np-mswmp.dll<br />[2008/08/06 18:22:02 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;np32dsw.dll<br />[2008/06/18 01:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npCouponPrinter.dll<br />[2009/10/11 04:17:27 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npdeploytk.dll<br />[2009/11/07 01:07:25 | 00,064,984 | ---- | M] (mozilla.org) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npnul32.dll<br />[2009/09/06 18:08:58 | 00,238,776 | ---- | M] (Pando Networks) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npPandoWebInst.dll<br />[2009/02/27 11:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;nppdf32.dll<br />[2008/07/14 22:21:47 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;nppl3260.dll<br />[2009/09/16 20:46:30 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin.dll<br />[2009/09/16 20:46:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin2.dll<br />[2009/09/16 20:46:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin3.dll<br />[2009/09/16 20:46:31 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin4.dll<br />[2009/09/16 20:46:32 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin5.dll<br />[2009/09/16 20:46:32 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin6.dll<br />[2009/09/16 20:46:32 | 00,159,744 | ---- | M] (Apple Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npqtplugin7.dll<br />[2005/04/27 15:10:49 | 00,102,400 | ---- | M] (RealNetworks) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npracplug.dll<br />[2008/07/14 22:21:57 | 00,008,192 | ---- | M] (RealNetworks, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;nprjplug.dll<br />[2008/07/14 22:21:39 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;nprpjplug.dll<br />[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;plugins&#092;npViewpoint.dll<br />[2009/06/24 06:27:00 | 00,001,394 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;amazondotcom.xml<br />[2009/06/24 06:27:00 | 00,002,193 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;answers.xml<br />[2009/06/24 06:27:00 | 00,001,534 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;creativecommons.xml<br />[2009/06/24 06:27:00 | 00,002,344 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;eBay.xml<br />[2009/06/24 06:27:00 | 00,002,371 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;google.xml<br />[2009/06/24 06:27:00 | 00,001,178 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;wikipedia.xml<br />[2009/06/24 06:27:00 | 00,000,792 | ---- | M] () -- C:&#092;Program Files&#092;Mozilla Firefox&#092;searchplugins&#092;yahoo.xml<br /> <br />O1 HOSTS File: (27 bytes) - C:&#092;Windows&#092;System32&#092;drivers&#092;etc&#092;hosts<br />O1 - Hosts: 127.0.0.1       localhost<br />O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn0&#092;yt.dll (Yahoo! Inc.)<br />O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll (Adobe Systems Incorporated)<br />O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:&#092;Program Files&#092;Real&#092;RealPlayer&#092;rpbrowserrecordplugin.dll (RealPlayer)<br />O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:&#092;Program Files&#092;AT&T&#092;AT&T Internet Security Suite&#092;pkR.dll File not found<br />O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.<br />O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;scriptsn.dll (McAfee, Inc.)<br />O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;5.3.4501.1418&#092;swg.dll (Google Inc.)<br />O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;McIEPlg.dll ()<br />O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;Component&#092;fastsearch_B7C5AC242193BB3E.dll (Google Inc.)<br />O2 - BHO: (Java&#153; Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jp2ssv.dll (Sun Microsystems, Inc.)<br />O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn0&#092;YTSingleInstance.dll (Yahoo! Inc)<br />O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll (Hewlett-Packard Co.)<br />O3 - HKLM&#092;..&#092;Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;McIEPlg.dll ()<br />O3 - HKLM&#092;..&#092;Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />O3 - HKLM&#092;..&#092;Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.<br />O3 - HKLM&#092;..&#092;Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:&#092;Program Files&#092;Yahoo!&#092;Companion&#092;Installs&#092;cpn0&#092;yt.dll (Yahoo! Inc.)<br />O3 - HKCU&#092;..&#092;Toolbar&#092;WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:&#092;Program Files&#092;Google&#092;Google Toolbar&#092;GoogleToolbar_32.dll (Google Inc.)<br />O4 - HKLM..&#092;Run: [Adobe Reader Speed Launcher] C:&#092;Program Files&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe (Adobe Systems Incorporated)<br />O4 - HKLM..&#092;Run: [HelpCenter4.1] C:&#092;Program Files&#092;FastAccessDSL&#092;HelpCenter43&#092;bin&#092;sprtcmd.exe (SupportSoft, Inc.)<br />O4 - HKLM..&#092;Run: [HotKeysCmds] C:&#092;Windows&#092;System32&#092;hkcmd.exe (Intel Corporation)<br />O4 - HKLM..&#092;Run: [HP Software Update] C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;hpwuSchd2.exe (Hewlett-Packard)<br />O4 - HKLM..&#092;Run: [IAAnotif] C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;Iaanotif.exe (Intel Corporation)<br />O4 - HKLM..&#092;Run: [IgfxTray] C:&#092;Windows&#092;System32&#092;igfxtray.exe (Intel Corporation)<br />O4 - HKLM..&#092;Run: [iTunesHelper] C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe (Apple Inc.)<br />O4 - HKLM..&#092;Run: [mcagent_exe] C:&#092;Program Files&#092;McAfee.com&#092;Agent&#092;mcagent.exe (McAfee, Inc.)<br />O4 - HKLM..&#092;Run: [McENUI] C:&#092;Program Files&#092;McAfee&#092;MHN&#092;McENUI.exe (McAfee, Inc.)<br />O4 - HKLM..&#092;Run: [Persistence] C:&#092;Windows&#092;System32&#092;igfxpers.exe (Intel Corporation)<br />O4 - HKLM..&#092;Run: [QuickTime Task] C:&#092;Program Files&#092;QuickTime&#092;QTTask.exe (Apple Inc.)<br />O4 - HKLM..&#092;Run: [SunJavaUpdateSched] C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe (Sun Microsystems, Inc.)<br />O4 - HKLM..&#092;Run: [YSearchProtection] C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe (Yahoo! Inc)<br />O4 - HKCU..&#092;Run: [ehTray.exe] C:&#092;Windows&#092;ehome&#092;ehtray.exe (Microsoft Corporation)<br />O4 - HKCU..&#092;Run: [HPAdvisor] C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Advisor&#092;HPAdvisor.exe (Hewlett-Packard)<br />O4 - HKCU..&#092;Run: [Messenger (Yahoo!)] C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;YahooMessenger.exe (Yahoo! Inc.)<br />O4 - HKCU..&#092;Run: [Sidebar] C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe (Microsoft Corporation)<br />O4 - HKCU..&#092;Run: [swg] C:&#092;Program Files&#092;Google&#092;GoogleToolbarNotifier&#092;GoogleToolbarNotifier.exe (Google Inc.)<br />O4 - HKCU..&#092;Run: [WMPNSCFG] C:&#092;Program Files&#092;Windows Media Player&#092;wmpnscfg.exe (Microsoft Corporation)<br />O4 - Startup: C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;ERUNT AutoBackup.lnk = C:&#092;Program Files&#092;ERUNT&#092;AUTOBACK.EXE ()<br />O6 - HKLM&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Restrictions present<br />O6 - HKLM&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Toolbars present<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: BindDirectlyToPropertySetStorage = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: NoDrives = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: ConsentPromptBehaviorAdmin = 2<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: ConsentPromptBehaviorUser = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: EnableInstallerDetection = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: EnableLUA = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: EnableSecureUIAPaths = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: EnableVirtualization = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: PromptOnSecureDesktop = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: ValidateAdminCodeSignatures = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: dontdisplaylastusername = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: legalnoticecaption = <br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: legalnoticetext = <br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: scforceoption = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: shutdownwithoutlogon = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: undockwithoutlogon = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: FilterAdministratorToken = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: EnableUIADesktopToggle = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: DisableRegistryTools = 0<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_TEXT = 1<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_BITMAP = 2<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_OEMTEXT = 7<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_DIB = 8<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_PALETTE = 9<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_UNICODETEXT = 13<br />O6 - HKLM&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System&#092;UIPI&#092;Clipboard&#092;ExceptionFormats: CF_DIBV5 = 17<br />O7 - HKCU&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Control Panel present<br />O7 - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;Explorer: NoDrives = 0<br />O7 - HKCU&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;policies&#092;System: DisableRegistryTools = 0<br />O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;Smart Web Printing&#092;hpswp_BHO.dll (Hewlett-Packard Co.)<br />O10 - NameSpace_Catalog5&#092;Catalog_Entries&#92;&#48;00000000007 [] - C:&#092;Program Files&#092;Bonjour&#092;mdnsNSP.dll (Apple Inc.)<br />O13 - gopher Prefix: missing<br />O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} <a href="http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab" target="_blank">http://cdn.scan.onecare.live.com/resource/...s/wlscctrl2.cab</a> (Reg Error: Key error.)<br />O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_17)<br />O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_17)<br />O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <a href="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab" target="_blank">http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab</a> (Java Plug-in 1.6.0_17)<br />O17 - HKLM&#092;System&#092;CCS&#092;Services&#092;Tcpip&#092;Parameters: DhcpNameServer = 192.168.1.254<br />O18 - Protocol&#092;Handler&#092;http&#92;&#48;x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;http&#092;oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;https&#92;&#48;x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;https&#092;oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;ipp - No CLSID value found<br />O18 - Protocol&#092;Handler&#092;ipp&#92;&#48;x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;msdaipp - No CLSID value found<br />O18 - Protocol&#092;Handler&#092;msdaipp&#92;&#48;x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;msdaipp&#092;oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:&#092;Program Files&#092;Common Files&#092;System&#092;Ole DB&#092;MSDAIPP.DLL (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:&#092;Program Files&#092;Common Files&#092;microsoft shared&#092;Information Retrieval&#092;msitss.dll (Microsoft Corporation)<br />O18 - Protocol&#092;Handler&#092;sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:&#092;Program Files&#092;McAfee&#092;SiteAdvisor&#092;McIEPlg.dll ()<br />O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:&#092;Windows&#092;explorer.exe (Microsoft Corporation)<br />O20 - Winlogon&#092;Notify&#092;igfxcui: DllName - igfxdev.dll - C:&#092;Windows&#092;System32&#092;igfxdev.dll (Intel Corporation)<br />O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found<br />O31 - SafeBoot: AlternateShell - cmd.exe<br />O32 - HKLM CDRom: AutoRun - 1<br />O32 - AutoRun File - [2007/12/08 03:03:03 | 00,000,074 | ---- | M] () - C:&#092;autoexec.bat -- [ NTFS ]<br />O32 - AutoRun File - [2008/07/26 09:13:49 | 00,000,000 | R--D | M] - E:&#092;AutoRun -- [ UDF ]<br />O32 - AutoRun File - [2008/07/26 09:20:44 | 00,703,552 | R--- | M] (Electronic Arts Inc.) - E:&#092;AutoRun.exe -- [ UDF ]<br />O32 - AutoRun File - [2008/07/26 09:20:45 | 00,662,592 | R--- | M] (Electronic Arts Inc.) - E:&#092;AutoRunGUI.dll -- [ UDF ]<br />O32 - AutoRun File - [2008/07/26 09:20:38 | 00,000,156 | R--- | M] () - E:&#092;autorun.inf -- [ UDF ]<br />O33 - MountPoints2&#092;{e9d26d47-a970-11dd-8ff3-806e6f6e6963}&#092;Shell - "" = AutoRun<br />O33 - MountPoints2&#092;{e9d26d47-a970-11dd-8ff3-806e6f6e6963}&#092;Shell&#092;AutoRun&#092;command - "" = E:&#092;AutoRun.exe -- [2008/07/26 09:20:44 | 00,703,552 | R--- | M] (Electronic Arts Inc.)<br />O34 - HKLM BootExecute: (autocheck) -  File not found<br />O34 - HKLM BootExecute: (autochk) - C:&#092;Windows&#092;System32&#092;autochk.exe (Microsoft Corporation)<br />O34 - HKLM BootExecute: (*) -  File not found<br />O34 - HKLM BootExecute: (lsdelete) - C:&#092;Windows&#092;System32&#092;lsdelete.exe ()<br />O35 - comfile [open] -- "%1" %* File not found<br />O35 - exefile [open] -- "%1" %* File not found<br /> <br />NetSvcs: FastUserSwitchingCompatibility -  File not found<br />NetSvcs: Ias - C:&#092;Windows&#092;System32&#092;ias [2008/06/25 12:52:18 | 00,000,000 | ---D | M]<br />NetSvcs: Irmon - C:&#092;Windows&#092;System32&#092;irmon.dll (Microsoft Corporation)<br />NetSvcs: Nla -  File not found<br />NetSvcs: Ntmssvc -  File not found<br />NetSvcs: NWCWorkstation -  File not found<br />NetSvcs: Nwsapagent -  File not found<br />NetSvcs: SRService -  File not found<br />NetSvcs: Wmi - C:&#092;Windows&#092;System32&#092;wmi.dll (Microsoft Corporation)<br />NetSvcs: WmdmPmSp -  File not found<br />NetSvcs: LogonHours -  File not found<br />NetSvcs: PCAudit -  File not found<br />NetSvcs: helpsvc -  File not found<br />NetSvcs: uploadmgr -  File not found<br /> <br /> <br />SafeBootMin: Base - Driver Group<br />SafeBootMin: Boot Bus Extender - Driver Group<br />SafeBootMin: Boot file system - Driver Group<br />SafeBootMin: File system - Driver Group<br />SafeBootMin: Filter - Driver Group<br />SafeBootMin: HelpSvc - Service<br />SafeBootMin: Lavasoft Ad-Aware Service - C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (Lavasoft)<br />SafeBootMin: mcmscsvc - C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe (McAfee, Inc.)<br />SafeBootMin: MCODS - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe (McAfee, Inc.)<br />SafeBootMin: NTDS -  File not found<br />SafeBootMin: PCI Configuration - Driver Group<br />SafeBootMin: PEVSystemStart - Service<br />SafeBootMin: PNP Filter - Driver Group<br />SafeBootMin: Primary disk - Driver Group<br />SafeBootMin: procexp90.Sys - Driver<br />SafeBootMin: rootrepeal.sys - Reg Error: Value error.<br />SafeBootMin: sacsvr - Service<br />SafeBootMin: SCSI Class - Driver Group<br />SafeBootMin: System Bus Extender - Driver Group<br />SafeBootMin: WinDefend - C:&#092;Program Files&#092;Windows Defender&#092;MpSvc.dll (Microsoft Corporation)<br />SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy<br />SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers<br />SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br />SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices<br />SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices<br /> <br />SafeBootNet: Base - Driver Group<br />SafeBootNet: Boot Bus Extender - Driver Group<br />SafeBootNet: Boot file system - Driver Group<br />SafeBootNet: File system - Driver Group<br />SafeBootNet: Filter - Driver Group<br />SafeBootNet: HelpSvc - Service<br />SafeBootNet: Lavasoft Ad-Aware Service - C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWService.exe (Lavasoft)<br />SafeBootNet: mcmscsvc - C:&#092;Program Files&#092;McAfee&#092;MSC&#092;mcmscsvc.exe (McAfee, Inc.)<br />SafeBootNet: MCODS - C:&#092;Program Files&#092;McAfee&#092;VirusScan&#092;mcods.exe (McAfee, Inc.)<br />SafeBootNet: Messenger - Service<br />SafeBootNet: MpfService - C:&#092;Program Files&#092;McAfee&#092;MPF&#092;MPFSrv.exe (McAfee, Inc.)<br />SafeBootNet: NDIS Wrapper - Driver Group<br />SafeBootNet: NetBIOSGroup - Driver Group<br />SafeBootNet: NetDDEGroup - Driver Group<br />SafeBootNet: Network - Driver Group<br />SafeBootNet: NetworkProvider - Driver Group<br />SafeBootNet: NTDS -  File not found<br />SafeBootNet: PCI Configuration - Driver Group<br />SafeBootNet: PEVSystemStart - Service<br />SafeBootNet: PNP Filter - Driver Group<br />SafeBootNet: PNP_TDI - Driver Group<br />SafeBootNet: Primary disk - Driver Group<br />SafeBootNet: procexp90.Sys - Driver<br />SafeBootNet: rdsessmgr - Service<br />SafeBootNet: sacsvr - Service<br />SafeBootNet: SCSI Class - Driver Group<br />SafeBootNet: Streams Drivers - Driver Group<br />SafeBootNet: System Bus Extender - Driver Group<br />SafeBootNet: TDI - Driver Group<br />SafeBootNet: WinDefend - C:&#092;Program Files&#092;Windows Defender&#092;MpSvc.dll (Microsoft Corporation)<br />SafeBootNet: WudfPf - Driver<br />SafeBootNet: WudfUsbccidDriver - Driver<br />SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers<br />SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive<br />SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive<br />SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller<br />SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc<br />SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard<br />SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse<br />SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net<br />SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient<br />SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService<br />SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans<br />SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters<br />SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter<br />SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System<br />SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive<br />SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers<br />SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy<br />SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers<br />SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume<br />SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices<br />SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices<br />SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices<br /> <br />ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player<br />ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)<br />ActiveX: {181EDF2F-43A0-77D6-9EC9-64924BE399BB} - Microsoft Windows Media Player<br />ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player<br />ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - <br />ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0<br />ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0<br />ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0<br />ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%&#092;system32&#092;regsvr32.exe /s /n /i:/UserInstall %SystemRoot%&#092;system32&#092;themeui.dll<br />ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack<br />ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%&#092;Windows Mail&#092;WinMail.exe" OCInstallUserConfigOE<br />ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - <br />ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx<br />ActiveX: {45A609B8-408F-62D5-B1B6-3AAB0D47424D} - Browser Customizations<br />ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help<br />ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7<br />ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools<br />ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements<br />ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player<br />ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access<br />ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders<br />ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7<br />ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework<br />ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll<br />ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:&#092;Windows&#092;system32&#092;ie4uinit.exe -BaseSettings<br />ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:&#092;Windows&#092;system32&#092;Rundll32.exe C:&#092;Windows&#092;system32&#092;mscories.dll,Install<br />ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding<br />ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error.<br />ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error.<br />ActiveX: {AE3B58BB-075C-2B30-C93E-C5CFFBB64910} - Microsoft Windows Media Player 11.0<br />ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts<br />ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1<br />ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player<br />ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help<br />ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.<br />ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface<br />ActiveX: &gt;{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:&#092;Windows&#092;system32&#092;unregmp2.exe /ShowWMP<br />ActiveX: &gt;{26923b43-4d38-484f-9b9e-de460746276c} - C:&#092;Windows&#092;system32&#092;ie4uinit.exe -UserIconConfig<br />ActiveX: &gt;{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:&#092;Windows&#092;System32&#092;rundll32.exe" "C:&#092;Windows&#092;System32&#092;iedkcs32.dll",BrandIEActiveSetup SIGNUP<br /> <br />Drivers32: msacm.ac3acm - C:&#092;Windows&#092;System32&#092;AC3ACM.acm (fccHandler)<br />Drivers32: msacm.alf2cd - C:&#092;Windows&#092;System32&#092;alf2cd.acm (NCT Company)<br />Drivers32: msacm.l3acm - C:&#092;Windows&#092;System32&#092;l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)<br />Drivers32: msacm.l3codecp - C:&#092;Windows&#092;System32&#092;l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)<br />Drivers32: msacm.scg726 - C:&#092;Windows&#092;System32&#092;Scg726.acm (SHARP Corporation)<br />Drivers32: msacm.voxacm160 - C:&#092;Windows&#092;System32&#092;vct3216.acm (Voxware, Inc.)<br />Drivers32: vidc.cvid - C:&#092;Windows&#092;System32&#092;iccvid.dll (Radius Inc.)<br />Drivers32: vidc.DIVX - C:&#092;Windows&#092;System32&#092;divx.dll (DivXNetworks, Inc.)<br />Drivers32: vidc.dvsd - C:&#092;Windows&#092;System32&#092;mcdvd_32.dll (MainConcept)<br />Drivers32: vidc.mp42 - C:&#092;Windows&#092;System32&#092;mpg4c32.dll (Microsoft Corporation)<br />Drivers32: vidc.mp43 - C:&#092;Windows&#092;System32&#092;mpg4c32.dll (Microsoft Corporation)<br />Drivers32: vidc.mpg4 - C:&#092;Windows&#092;System32&#092;mpg4c32.dll (Microsoft Corporation)<br />Drivers32: vidc.tscc - C:&#092;Windows&#092;System32&#092;tsccvid.dll (TechSmith Corporation)<br />Drivers32: vidc.VP60 - C:&#092;Windows&#092;System32&#092;vp6vfw.dll (On2.com)<br />Drivers32: vidc.VP61 - C:&#092;Windows&#092;System32&#092;vp6vfw.dll (On2.com)<br />Drivers32: vidc.VP62 - C:&#092;Windows&#092;System32&#092;vp6vfw.dll (On2.com)<br />Drivers32: vidc.XVID - C:&#092;Windows&#092;System32&#092;xvidvfw.dll ()<br />OTL cannot create restorepoints on Vista OSs!<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files/Folders - Created Within 14 Days ==========<!--colorc--></span><!--/colorc--><br /> <br />[2009/11/16 23:33:40 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;ERUNT<br />[2009/11/09 19:05:28 | 00,000,000 | ---D | C] -- C:&#092;Windows&#092;WinBatch<br />[2009/11/08 21:50:12 | 00,000,000 | ---D | C] -- C:&#092;Users&#092;family&#092;Documents&#092;Hannahs pics<br />[2009/11/08 13:14:42 | 00,000,000 | ---D | C] -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;Nova Development<br />[2009/11/08 10:40:02 | 00,064,288 | ---- | C] (Lavasoft AB) -- C:&#092;Windows&#092;System32&#092;drivers&#092;Lbd.sys<br />[2009/11/08 10:39:53 | 00,093,360 | ---- | C] (Sunbelt Software) -- C:&#092;Windows&#092;System32&#092;drivers&#092;SBREDrv.sys<br />[2009/11/08 10:36:48 | 00,000,000 | -H-D | C] -- C:&#092;ProgramData&#092;{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />[2009/11/08 10:36:48 | 00,000,000 | -H-D | C] -- C:&#092;ProgramData&#092;{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}<br />[2009/11/07 03:18:13 | 00,000,000 | ---D | C] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;AVS4YOU<br />[2009/11/07 03:18:11 | 00,000,000 | ---D | C] -- C:&#092;ProgramData&#092;AVS4YOU<br />[2009/11/07 03:18:11 | 00,000,000 | ---D | C] -- C:&#092;ProgramData&#092;AVS4YOU<br />[2009/11/07 03:16:35 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Common Files&#092;AVSMedia<br />[2009/11/07 03:16:18 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;AVS4YOU<br />[2009/11/07 00:48:41 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;ConvertHelper<br />[2009/11/06 03:54:06 | 00,000,000 | -HSD | C] -- C:&#092;Windows&#092;System32&#092;%APPDATA%<br />[2009/11/06 01:48:53 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Windows Portable Devices<br />[2009/11/05 23:51:33 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Common Files&#092;SWF Studio<br />[2009/11/05 23:51:23 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;Riva<br />[2009/11/04 22:57:27 | 00,000,000 | ---D | C] -- C:&#092;Users&#092;family&#092;dwhelper<br />[2009/11/04 01:09:15 | 00,000,000 | ---D | C] -- C:&#092;Users&#092;family&#092;Documents&#092;CyberLink<br />[2009/11/04 00:56:41 | 00,000,000 | ---D | C] -- C:&#092;Program Files&#092;AVIConverter<br />[2008/04/27 20:50:05 | 00,774,144 | ---- | C] (RealNetworks, Inc.) -- C:&#092;Program Files&#092;RngInterstitial.dll<br />[2007/04/04 06:40:30 | 00,643,072 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvpmui.dll<br />[2007/04/04 06:39:22 | 01,224,704 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvserv.dll<br />[2007/04/04 06:34:14 | 00,421,888 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvcomm.dll<br />[2007/04/04 06:32:50 | 00,585,728 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvlmpm.dll<br />[2007/04/04 06:31:40 | 00,397,312 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbviesc.dll<br />[2007/04/04 06:29:30 | 00,094,208 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvpplc.dll<br />[2007/04/04 06:28:44 | 00,684,032 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvcomc.dll<br />[2007/04/04 06:28:12 | 00,163,840 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvprox.dll<br />[2007/04/04 06:22:26 | 00,413,696 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvinpa.dll<br />[2007/04/04 06:21:52 | 00,995,328 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvusb1.dll<br />[2007/04/04 06:18:20 | 00,696,320 | ---- | C] ( ) -- C:&#092;Windows&#092;System32&#092;lxbvhbn3.dll<br />[1 C:&#092;Windows&#092;System32&#092;*.tmp files -&gt; C:&#092;Windows&#092;System32&#092;*.tmp -&gt; ]<br />[1 C:&#092;Users&#092;family&#092;Documents&#092;*.tmp files -&gt; C:&#092;Users&#092;family&#092;Documents&#092;*.tmp -&gt; ]<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files - Modified Within 14 Days ==========<!--colorc--></span><!--/colorc--><br /> <br />[2009/11/17 00:11:42 | 04,980,736 | -HS- | M] () -- C:&#092;Users&#092;family&#092;ntuser.dat<br />[2009/11/17 00:05:02 | 00,000,886 | ---- | M] () -- C:&#092;Windows&#092;tasks&#092;GoogleUpdateTaskMachineUA.job<br />[2009/11/17 00:02:46 | 00,000,868 | ---- | M] () -- C:&#092;Windows&#092;tasks&#092;Google Software Updater.job<br />[2009/11/17 00:01:17 | 00,000,370 | ---- | M] () -- C:&#092;Windows&#092;tasks&#092;Ad-Aware Update (Weekly).job<br />[2009/11/16 23:59:45 | 00,016,573 | ---- | M] () -- C:&#092;Windows&#092;System32&#092;Config.MPF<br />[2009/11/16 23:59:41 | 27,107,616 | -HS- | M] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;fidbox.dat<br />[2009/11/16 23:59:15 | 00,000,882 | ---- | M] () -- C:&#092;Windows&#092;tasks&#092;GoogleUpdateTaskMachineCore.job<br />[2009/11/16 23:58:51 | 00,003,568 | -H-- | M] () -- C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0<br />[2009/11/16 23:58:51 | 00,003,568 | -H-- | M] () -- C:&#092;Windows&#092;System32&#092;7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0<br />[2009/11/16 23:58:47 | 00,000,006 | -H-- | M] () -- C:&#092;Windows&#092;tasks&#092;SA.DAT<br />[2009/11/16 23:58:43 | 00,067,584 | --S- | M] () -- C:&#092;Windows&#092;BootStat.dat<br />[2009/11/16 23:57:29 | 00,365,096 | -HS- | M] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;fidbox.idx<br />[2009/11/16 23:57:03 | 00,524,288 | -HS- | M] () -- C:&#092;Users&#092;family&#092;NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms<br />[2009/11/16 23:57:03 | 00,065,536 | -HS- | M] () -- C:&#092;Users&#092;family&#092;NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf<br />[2009/11/16 23:56:49 | 03,337,742 | -H-- | M] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;IconCache.db<br />[2009/11/16 23:40:18 | 00,000,820 | ---- | M] () -- C:&#092;Users&#092;Public&#092;Desktop&#092;Malwarebytes' Anti-Malware.lnk<br />[2009/11/16 23:33:46 | 00,000,915 | ---- | M] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;ERUNT AutoBackup.lnk<br />[2009/11/16 23:33:43 | 00,000,735 | ---- | M] () -- C:&#092;Users&#092;family&#092;Desktop&#092;NTREGOPT.lnk<br />[2009/11/16 23:33:42 | 00,000,716 | ---- | M] () -- C:&#092;Users&#092;family&#092;Desktop&#092;ERUNT.lnk<br />[2009/11/16 22:53:58 | 00,098,816 | ---- | M] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />[2009/11/16 16:21:40 | 00,002,202 | -HS- | M] () -- C:&#092;Windows&#092;System32&#092;KGyGaAvL.sys<br />[2009/11/15 08:06:07 | 00,001,929 | ---- | M] () -- C:&#092;Users&#092;Public&#092;Desktop&#092;Google Chrome.lnk<br />[2009/11/15 03:31:16 | 00,000,342 | ---- | M] () -- C:&#092;Windows&#092;tasks&#092;McDefragTask.job<br />[2009/11/11 03:23:40 | 00,434,648 | ---- | M] () -- C:&#092;Windows&#092;System32&#092;FNTCACHE.DAT<br />[2009/11/09 21:47:08 | 02,779,799 | ---- | M] () -- C:&#092;Users&#092;family&#092;Documents&#092;Thunder song.wma<br />[2009/11/08 13:34:14 | 00,151,040 | ---- | M] () -- C:&#092;Users&#092;family&#092;Documents&#092;hannah's stuff.pra<br />[2009/11/08 10:39:51 | 00,093,360 | ---- | M] (Sunbelt Software) -- C:&#092;Windows&#092;System32&#092;drivers&#092;SBREDrv.sys<br />[2009/11/08 10:39:44 | 00,015,880 | ---- | M] () -- C:&#092;Windows&#092;System32&#092;lsdelete.exe<br />[2009/11/08 10:36:47 | 00,001,009 | ---- | M] () -- C:&#092;Users&#092;Public&#092;Desktop&#092;Ad-Aware.lnk<br />[2009/11/07 03:17:25 | 00,001,088 | ---- | M] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVS4YOU Software Navigator.lnk<br />[2009/11/07 03:16:57 | 00,001,039 | ---- | M] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVS Video Converter 6.lnk<br />[2009/11/06 01:48:20 | 00,000,000 | -H-- | M] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;Msft_User_WpdMtpDr_01_07_00.Wdf<br />[2009/11/06 01:47:54 | 00,000,000 | -H-- | M] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;Msft_User_WpdFs_01_07_00.Wdf<br />[2009/11/04 00:56:41 | 00,000,635 | ---- | M] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVIConverter.lnk<br />[1 C:&#092;Windows&#092;System32&#092;*.tmp files -&gt; C:&#092;Windows&#092;System32&#092;*.tmp -&gt; ]<br />[1 C:&#092;Users&#092;family&#092;Documents&#092;*.tmp files -&gt; C:&#092;Users&#092;family&#092;Documents&#092;*.tmp -&gt; ]<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Files Created - No Company Name ==========<!--colorc--></span><!--/colorc--><br /> <br />[2009/11/16 23:33:46 | 00,000,915 | ---- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Microsoft&#092;Windows&#092;Start Menu&#092;Programs&#092;Startup&#092;ERUNT AutoBackup.lnk<br />[2009/11/16 23:33:43 | 00,000,735 | ---- | C] () -- C:&#092;Users&#092;family&#092;Desktop&#092;NTREGOPT.lnk<br />[2009/11/16 23:33:42 | 00,000,716 | ---- | C] () -- C:&#092;Users&#092;family&#092;Desktop&#092;ERUNT.lnk<br />[2009/11/16 23:06:06 | 00,000,370 | ---- | C] () -- C:&#092;Windows&#092;tasks&#092;Ad-Aware Update (Weekly).job<br />[2009/11/09 21:47:08 | 02,779,799 | ---- | C] () -- C:&#092;Users&#092;family&#092;Documents&#092;Thunder song.wma<br />[2009/11/08 13:34:13 | 00,151,040 | ---- | C] () -- C:&#092;Users&#092;family&#092;Documents&#092;hannah's stuff.pra<br />[2009/11/08 10:36:47 | 00,001,009 | ---- | C] () -- C:&#092;Users&#092;Public&#092;Desktop&#092;Ad-Aware.lnk<br />[2009/11/07 03:17:25 | 00,001,088 | ---- | C] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVS4YOU Software Navigator.lnk<br />[2009/11/07 03:16:57 | 00,001,039 | ---- | C] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVS Video Converter 6.lnk<br />[2009/11/06 01:48:20 | 00,000,000 | -H-- | C] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;Msft_User_WpdMtpDr_01_07_00.Wdf<br />[2009/11/06 01:47:54 | 00,000,000 | -H-- | C] () -- C:&#092;Windows&#092;System32&#092;drivers&#092;Msft_User_WpdFs_01_07_00.Wdf<br />[2009/11/06 01:32:19 | 00,057,667 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;ieuinit.inf<br />[2009/11/04 00:56:41 | 00,000,635 | ---- | C] () -- C:&#092;Users&#092;family&#092;Desktop&#092;AVIConverter.lnk<br />[2009/08/11 22:27:56 | 00,005,754 | ---- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;debug-Reloader.txt<br />[2009/07/27 18:55:35 | 03,337,742 | -H-- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;IconCache.db<br />[2009/07/24 05:56:11 | 00,117,248 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;EhStorAuthn.dll<br />[2009/07/22 06:59:30 | 00,000,088 | RHS- | C] () -- C:&#092;ProgramData&#092;5C77F4BDDF.sys<br />[2009/07/22 06:59:29 | 00,002,516 | -HS- | C] () -- C:&#092;ProgramData&#092;KGyGaAvL.sys<br />[2009/04/01 14:56:55 | 00,000,000 | ---- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;wklnhst.dat<br />[2009/03/05 06:54:58 | 00,073,728 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;RtNicProp32.dll<br />[2009/02/08 16:54:59 | 00,000,222 | ---- | C] () -- C:&#092;Windows&#092;7THLEVEL.INI<br />[2009/02/08 14:37:50 | 00,000,146 | ---- | C] () -- C:&#092;Windows&#092;SIERRA.INI<br />[2008/06/29 21:43:12 | 00,129,024 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;AVERM.dll<br />[2008/06/29 21:43:12 | 00,028,672 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;AVEQT.dll<br />[2008/03/25 15:56:08 | 00,147,456 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;igfxCoIn_v1461.dll<br />[2008/02/18 02:49:03 | 00,524,288 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;xvidcore.dll<br />[2008/02/18 02:49:02 | 00,139,264 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;xvidvfw.dll<br />[2008/02/04 23:40:14 | 00,002,202 | -HS- | C] () -- C:&#092;Windows&#092;System32&#092;KGyGaAvL.sys<br />[2008/02/04 22:23:28 | 00,000,441 | ---- | C] () -- C:&#092;Windows&#092;cdplayer.ini<br />[2008/01/31 04:37:54 | 00,000,092 | ---- | C] () -- C:&#092;Windows&#092;Lexstat.ini<br />[2008/01/31 03:49:48 | 00,000,376 | ---- | C] () -- C:&#092;Windows&#092;ODBC.INI<br />[2008/01/31 03:25:28 | 00,098,816 | ---- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini<br />[2008/01/31 02:28:15 | 00,001,356 | ---- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;d3d9caps.dat<br />[2008/01/30 23:58:09 | 00,000,021 | ---- | C] () -- C:&#092;Windows&#092;atid.ini<br />[2008/01/30 21:47:56 | 00,107,032 | -H-- | C] () -- C:&#092;Users&#092;family&#092;AppData&#092;Local&#092;GDIPFONTCACHEV1.DAT<br />[2007/12/08 02:51:40 | 00,002,415 | ---- | C] () -- C:&#092;ProgramData&#092;hpzinstall.log<br />[2007/12/08 02:42:49 | 01,238,832 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;igmedkrn.dll<br />[2007/12/08 02:42:49 | 00,147,456 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;igfxCoIn_v1332.dll<br />[2007/12/08 02:42:49 | 00,104,636 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;igmedcompkrn.dll<br />[2007/12/08 02:30:25 | 00,327,680 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;pythoncom25.dll<br />[2007/12/08 02:30:25 | 00,102,400 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;pywintypes25.dll<br />[2007/04/24 06:47:28 | 00,413,696 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;lxbvutil.dll<br />[2007/02/22 13:32:00 | 00,344,064 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;lxbvcoin.dll<br />[2006/11/02 07:50:50 | 00,000,174 | -HS- | C] () -- C:&#092;Program Files&#092;desktop.ini<br />[2006/11/02 07:37:35 | 00,037,665 | ---- | C] () -- C:&#092;Windows&#092;Fonts&#092;GlobalUserInterface.CompositeFont<br />[2006/11/02 07:37:35 | 00,029,779 | ---- | C] () -- C:&#092;Windows&#092;Fonts&#092;GlobalSerif.CompositeFont<br />[2006/11/02 07:37:35 | 00,026,489 | ---- | C] () -- C:&#092;Windows&#092;Fonts&#092;GlobalSansSerif.CompositeFont<br />[2006/11/02 07:37:35 | 00,026,040 | ---- | C] () -- C:&#092;Windows&#092;Fonts&#092;GlobalMonospace.CompositeFont<br />[2006/11/02 07:35:32 | 00,005,632 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;sysprepMCE.dll<br />[2006/11/02 05:23:31 | 00,000,215 | ---- | C] () -- C:&#092;Windows&#092;system.ini<br />[2006/11/02 05:23:31 | 00,000,179 | ---- | C] () -- C:&#092;Windows&#092;win.ini<br />[2006/11/02 02:40:29 | 00,013,750 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;pacerprf.ini<br />[2006/06/23 11:13:54 | 00,114,688 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;liclock.dll<br />[2005/10/25 22:12:10 | 00,040,960 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;lxbvvs.dll<br />[2005/09/15 17:40:22 | 00,164,352 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;unrar.dll<br />[1997/11/10 14:18:48 | 00,010,240 | ---- | C] () -- C:&#092;Windows&#092;System32&#092;vidx16.dll<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== LOP Check ==========<!--colorc--></span><!--/colorc--><br /> <br />[2008/01/31 00:02:20 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;acccore<br />[2009/10/22 22:14:40 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;AT&T<br />[2008/05/21 19:07:44 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Autodesk<br />[2008/11/22 10:56:00 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;CleanMyPC Software<br />[2009/07/22 06:59:35 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Corel<br />[2009/08/01 16:37:31 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;eMusic<br />[2008/09/27 10:06:27 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;ITTNord<br />[2008/06/29 21:28:29 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Moyea<br />[2008/06/13 12:28:14 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Nexon<br />[2008/08/16 13:06:41 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;PlayFirst<br />[2008/01/31 00:02:22 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;QQ Games Plugin<br />[2008/09/15 22:14:23 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Skinux<br />[2008/08/30 11:05:48 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Sudden Games<br />[2009/04/01 14:57:03 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Template<br />[2008/06/25 19:34:11 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Wal-Mart Digital Photo Viewer<br />[2008/02/24 03:35:50 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;WildTangent<br />[2008/02/08 00:36:27 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;WinBatch<br />[2008/02/24 20:02:37 | 00,000,000 | ---D | M] -- C:&#092;Users&#092;family&#092;AppData&#092;Roaming&#092;Winff<br />[2009/11/17 00:01:17 | 00,000,370 | ---- | M] () -- C:&#092;Windows&#092;Tasks&#092;Ad-Aware Update (Weekly).job<br />[2009/11/15 03:31:16 | 00,000,342 | ---- | M] () -- C:&#092;Windows&#092;Tasks&#092;McDefragTask.job<br />[2009/11/01 00:00:09 | 00,000,320 | ---- | M] () -- C:&#092;Windows&#092;Tasks&#092;McQcTask.job<br />[2009/11/16 23:58:47 | 00,000,006 | -H-- | M] () -- C:&#092;Windows&#092;Tasks&#092;SA.DAT<br />[2009/11/16 23:57:10 | 00,032,626 | ---- | M] () -- C:&#092;Windows&#092;Tasks&#092;SCHEDLGU.TXT<br />[2009/07/24 13:45:57 | 00,000,424 | -H-- | M] () -- C:&#092;Windows&#092;Tasks&#092;User_Feed_Synchronization-{4B3593F7-9DDC-4031-B174-350188CC183B}.job<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Purity Check ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Custom Scans ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;*.exe &gt;<!--colorc--></span><!--/colorc--><br />[2009/07/29 14:29:33 | 00,135,168 | ---- | M] () -- C:&#092;zip.exe<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;eventlog.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2007/01/13 01:30:08 | 00,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:&#092;Program Files&#092;CyberLink&#092;PowerDirector&#092;EventLog.dll<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;scecli.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2009/04/11 01:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:&#092;Windows&#092;System32&#092;scecli.dll<br />[1 C:&#092;Windows&#092;System32&#092;*.tmp files -&gt; C:&#092;Windows&#092;System32&#092;*.tmp -&gt; ]<br />[2006/11/02 04:46:12 | 00,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e&#092;scecli.dll<br />[2008/01/19 02:36:19 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12&#092;scecli.dll<br />[2009/04/11 01:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e&#092;scecli.dll<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;netlogon.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2009/04/11 01:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:&#092;Windows&#092;System32&#092;netlogon.dll<br />[1 C:&#092;Windows&#092;System32&#092;*.tmp files -&gt; C:&#092;Windows&#092;System32&#092;*.tmp -&gt; ]<br />[2006/11/02 04:46:11 | 00,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783&#092;netlogon.dll<br />[2008/01/19 02:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857&#092;netlogon.dll<br />[2009/04/11 01:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3&#092;netlogon.dll<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;cngaudit.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:&#092;Windows&#092;System32&#092;cngaudit.dll<br />[1 C:&#092;Windows&#092;System32&#092;*.tmp files -&gt; C:&#092;Windows&#092;System32&#092;*.tmp -&gt; ]<br />[2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:&#092;Windows&#092;winsxs&#092;x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6&#092;cngaudit.dll<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;sceclt.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;ntelogon.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;logevent.dll /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;iaStor.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2007/07/12 11:35:02 | 00,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:&#092;hp&#092;DRIVERS&#092;Intel_RAID&#092;iastor.sys<br />[2008/06/02 18:49:48 | 00,305,688 | ---- | M] (Intel Corporation) MD5=25C3D5F66A74A7BDDECA56085F040D2E -- C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;Driver&#092;IaStor.sys<br />[2008/06/02 18:50:10 | 00,382,488 | ---- | M] (Intel Corporation) MD5=3C4CD264B04D79A43A0F124C067BA08E -- C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;Driver64&#092;IaStor.sys<br />[2008/12/04 20:34:52 | 00,328,728 | ---- | M] (Intel Corporation) MD5=BAABB0301949774A66B955C65319635A -- C:&#092;Windows&#092;System32&#092;drivers&#092;iaStor.sys<br />[2007/07/12 11:35:02 | 00,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;iaahci.inf_cfa1dde4&#092;iaStor.sys<br />[2008/12/04 20:34:52 | 00,328,728 | ---- | M] (Intel Corporation) MD5=BAABB0301949774A66B955C65319635A -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;iastor.inf_08c343cc&#092;iaStor.sys<br />[2008/06/02 18:49:48 | 00,305,688 | ---- | M] (Intel Corporation) MD5=25C3D5F66A74A7BDDECA56085F040D2E -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;iastor.inf_27dcf4f5&#092;iaStor.sys<br />[2007/07/12 11:35:02 | 00,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;iastor.inf_ec8a8d1b&#092;iaStor.sys<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;nvstor.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2006/11/02 04:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:&#092;Windows&#092;System32&#092;drivers&#092;nvstor.sys<br />[2008/01/19 02:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;nvraid.inf_31c3d71d&#092;nvstor.sys<br />[2006/11/02 04:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;nvraid.inf_733654ff&#092;nvstor.sys<br />[2008/01/19 02:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:&#092;Windows&#092;winsxs&#092;x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467&#092;nvstor.sys<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;atapi.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2007/12/08 02:00:16 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=B3F2C79318B9BBE87B2C51033682D912 -- C:&#092;Windows&#092;System32&#092;drivers&#092;atapi.sys<br />[2007/12/08 02:00:16 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=B3F2C79318B9BBE87B2C51033682D912 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_4db4e301&#092;atapi.sys<br />[2008/02/13 03:06:21 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_64dfd8ea&#092;atapi.sys<br />[2008/02/13 03:06:22 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_7de13c21&#092;atapi.sys<br />[2009/04/11 01:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_b12d8e84&#092;atapi.sys<br />[2006/11/02 04:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_c6c2e699&#092;atapi.sys<br />[2008/01/19 02:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;mshdc.inf_cc18792d&#092;atapi.sys<br />[2008/02/13 03:06:22 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:&#092;Windows&#092;winsxs&#092;x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c&#092;atapi.sys<br />[2007/12/08 02:00:16 | 00,021,688 | ---- | M] (Microsoft Corporation) MD5=B3F2C79318B9BBE87B2C51033682D912 -- C:&#092;Windows&#092;winsxs&#092;x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20693_none_db7d35eb3dc727cc&#092;atapi.sys<br />[2008/02/13 03:06:21 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:&#092;Windows&#092;winsxs&#092;x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b&#092;atapi.sys<br />[2008/01/19 02:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:&#092;Windows&#092;winsxs&#092;x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c&#092;atapi.sys<br />[2009/04/11 01:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:&#092;Windows&#092;winsxs&#092;x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8&#092;atapi.sys<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;IdeChnDr.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;viasraid.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;AGP440.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br />[2006/11/02 04:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:&#092;Windows&#092;System32&#092;drivers&#092;AGP440.sys<br />[2008/01/19 02:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;machine.inf_51b95d75&#092;AGP440.sys<br />[2006/11/02 04:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;machine.inf_920a2c1f&#092;AGP440.sys<br />[2008/01/19 02:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;machine.inf_f750e484&#092;AGP440.sys<br />[2008/01/19 02:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:&#092;Windows&#092;winsxs&#092;x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a&#092;AGP440.sys<br />[2008/01/19 02:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:&#092;Windows&#092;winsxs&#092;x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6&#092;AGP440.sys<br /> <br /><!--coloro:#A23BEC--><span style="color:#A23BEC"><!--/coloro-->&lt; %SYSTEMDRIVE%&#092;vaxscsi.sys /s /md5 &gt;<!--colorc--></span><!--/colorc--><br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Alternate Data Streams ==========<!--colorc--></span><!--/colorc--><br /> <br />@Alternate Data Stream - 96 bytes -&gt; C:&#092;ProgramData&#092;TEMP:ED810E46<br />@Alternate Data Stream - 130 bytes -&gt; C:&#092;ProgramData&#092;TEMP:FF9C44FE<br />@Alternate Data Stream - 127 bytes -&gt; C:&#092;ProgramData&#092;TEMP:A97FF73C<br />@Alternate Data Stream - 123 bytes -&gt; C:&#092;ProgramData&#092;TEMP:66E02052<br />@Alternate Data Stream - 119 bytes -&gt; C:&#092;ProgramData&#092;TEMP:ECF54A0E<br />@Alternate Data Stream - 119 bytes -&gt; C:&#092;ProgramData&#092;TEMP:39C7B7C6<br />&lt; End of report &gt;<br /><br />OTL Extras logfile created on: 11/17/2009 12:11:52 AM - Run 1<br />OTL by OldTimer - Version 3.1.6.0     Folder = C:&#092;Users&#092;family&#092;Downloads<br />Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation<br />Internet Explorer (Version = 8.0.6001.18828)<br />Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy<br /> <br />1.99 Gb Total Physical Memory | 0.61 Gb Available Physical Memory | 30.70% Memory free<br />4.00 Gb Paging File | 2.91 Gb Available in Paging File | 72.77% Paging File free<br />Paging file location(s): ?:&#092;pagefile.sys [binary data]<br /> <br />%SystemDrive% = C: | %SystemRoot% = C:&#092;Windows | %ProgramFiles% = C:&#092;Program Files<br />Drive C: | 325.89 Gb Total Space | 142.43 Gb Free Space | 43.70% Space Free | Partition Type: NTFS<br />Drive D: | 9.46 Gb Total Space | 1.28 Gb Free Space | 13.54% Space Free | Partition Type: NTFS<br />Drive E: | 1003.03 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF<br />F: Drive not present or media not loaded<br />G: Drive not present or media not loaded<br />H: Drive not present or media not loaded<br />I: Drive not present or media not loaded<br /> <br />Computer Name: FAMILY-PC<br />Current User Name: family<br />Logged in as Administrator.<br /> <br />Current Boot Mode: Normal<br />Scan Mode: Current user<br />Company Name Whitelist: On<br />Skip Microsoft Files: On<br />File Age = 14 Days<br />Output = Standard<br />Quick Scan<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Extra Registry (SafeList) ==========<!--colorc--></span><!--/colorc--><br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== File Associations ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;extension&gt;]<br />.chm [@ = chm.file] -- "%SystemRoot%&#092;hh.exe" %1<br />.hlp [@ = hlpfile] -- C:&#092;Windows&#092;winhlp32.exe (Microsoft Corporation)<br />.html [@ = htmlfile] -- C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE (Microsoft Corporation)<br /> <br />[HKEY_CURRENT_USER&#092;SOFTWARE&#092;Classes&#092;&lt;extension&gt;]<br />.html [@ = FirefoxHTML] -- C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe (Mozilla Corporation)<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Shell Spawning ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Classes&#092;&lt;key&gt;&#092;shell&#092;[command]&#092;command]<br />batfile [open] -- "%1" %* File not found<br />chm.file [open] -- "%SystemRoot%&#092;hh.exe" %1 File not found<br />cmdfile [open] -- "%1" %* File not found<br />comfile [open] -- "%1" %* File not found<br />exefile [open] -- "%1" %* File not found<br />helpfile [open] -- Reg Error: Key error.<br />hlpfile [open] -- %SystemRoot%&#092;winhlp32.exe %1 (Microsoft Corporation)<br />htmlfile [edit] -- "C:&#092;Program Files&#092;Microsoft Office&#092;Office&#092;msohtmed.exe" %1 (Microsoft Corporation)<br />htmlfile [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" -nohome (Microsoft Corporation)<br />htmlfile [opennew] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" %1 (Microsoft Corporation)<br />http [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE" -nohome (Microsoft Corporation)<br />https [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe" -nohome (Microsoft Corporation)<br />piffile [open] -- "%1" %* File not found<br />regfile [merge] -- Reg Error: Key error.<br />scrfile [config] -- "%1" File not found<br />scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)<br />scrfile [open] -- "%1" /S File not found<br />txtfile [edit] -- Reg Error: Key error.<br />Unknown [openas] -- %SystemRoot%&#092;system32&#092;rundll32.exe %SystemRoot%&#092;system32&#092;shell32.dll,OpenAs_RunDLL %1 File not found<br />Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)<br />Directory [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />Folder [open] -- %SystemRoot%&#092;Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)<br />Folder [explore] -- %SystemRoot%&#092;Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)<br />Drive [find] -- %SystemRoot%&#092;Explorer.exe (Microsoft Corporation)<br />Applications&#092;iexplore.exe [open] -- "C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe" %1 (Microsoft Corporation)<br />CLSID&#092;{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:&#092;Program Files&#092;Internet Explorer&#092;iexplore.exe" (Microsoft Corporation)<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Security Center Settings ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center]<br />"cval" = 1<br />"UacDisableNotify" = 0<br />"InternetSettingsDisableNotify" = 0<br />"AutoUpdateDisableNotify" = 0<br />"FirewallDisableNotify" = 0<br />"AntiVirusDisableNotify" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring]<br />"DisableMonitoring" = 1<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecAntiVirus]<br />"DisableMonitoring" = 1<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Monitoring&#092;SymantecFirewall]<br />"DisableMonitoring" = 1<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Svc]<br />"AntiVirusOverride" = 0<br />"AntiSpywareOverride" = 0<br />"FirewallOverride" = 0<br />"VistaSp1" = Reg Error: Unknown registry data type -- File not found<br />"VistaSp2" = Reg Error: Unknown registry data type -- File not found<br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Security Center&#092;Svc&#092;Vol]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile]<br />"EnableFirewall" = 0<br />"DisableNotifications" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile]<br />"EnableFirewall" = 0<br />"DisableNotifications" = 0<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;GloballyOpenPorts&#092;List]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;PublicProfile]<br />"EnableFirewall" = 0<br />"DisableNotifications" = 0<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Authorized Applications List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;DomainProfile&#092;AuthorizedApplications&#092;List]<br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;StandardProfile&#092;AuthorizedApplications&#092;List]<br />"C:&#092;Program Files&#092;EarthLink TotalAccess&#092;TaskPanl.exe" = C:&#092;Program Files&#092;EarthLink TotalAccess&#092;TaskPanl.exe:*:Enabled:Earthlink -- File not found<br />"C:&#092;Program Files&#092;BitTorrent&#092;bittorrent.exe" = C:&#092;Program Files&#092;BitTorrent&#092;bittorrent.exe:*:Enabled:BitTorrent -- File not found<br /> <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Vista Active Open Ports Exception List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;FirewallRules]<br />"{1D79E345-FFE9-40C2-9202-6A920BE41491}" = rport=139 | protocol=6 | dir=out | app=system | <br />"{26E08E8D-8F80-4539-829D-802DD00A0B45}" = lport=139 | protocol=6 | dir=in | app=system | <br />"{62048C40-74C4-4486-B6B2-16AAAF2A58B8}" = rport=137 | protocol=17 | dir=out | app=system | <br />"{6C914009-8AC5-4C44-975E-AFA2ADDB66DB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%&#092;system32&#092;spoolsv.exe | <br />"{90625EE6-4203-4E6B-8A82-A6FB38C195B7}" = rport=445 | protocol=6 | dir=out | app=system | <br />"{A7AFF096-2D22-4758-A654-43E1FF5440EF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | <br />"{D8311AD7-E00C-46F8-AE06-95F60ABFC313}" = lport=138 | protocol=17 | dir=in | app=system | <br />"{E708FD3D-2CD2-4262-A5FA-D6733778E650}" = lport=445 | protocol=6 | dir=in | app=system | <br />"{ECF26460-3F08-400C-AE59-62C26DE56647}" = lport=137 | protocol=17 | dir=in | app=system | <br />"{F51316CB-B17F-49CE-962E-1111337C9FDC}" = rport=138 | protocol=17 | dir=out | app=system | <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Vista Active Application Exception List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SYSTEM&#092;CurrentControlSet&#092;Services&#092;SharedAccess&#092;Parameters&#092;FirewallPolicy&#092;FirewallRules]<br />"{0564967B-27AF-49F6-8245-A7F2ADCBA92F}" = protocol=17 | dir=in | app=c:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe | <br />"{0D5632C9-3190-4572-B72E-CA401101017B}" = protocol=17 | dir=in | app=c:&#092;windows&#092;system32&#092;lxbvcoms.exe | <br />"{13609E7B-805A-40BC-91FC-40E122E9F689}" = protocol=17 | dir=in | app=c:&#092;program files&#092;itunes&#092;itunes.exe | <br />"{13C794D6-FB49-4CDE-8746-0B0AC6F7B61D}" = protocol=17 | dir=in | app=c:&#092;program files&#092;aim6&#092;aim6.exe | <br />"{1AB65B10-F227-42DA-9A2D-91621148F44A}" = protocol=6 | dir=in | app=c:&#092;program files&#092;bellsouth&#092;mccibrowser.exe | <br />"{1B6FD537-22D7-40BD-986D-7ED6F97B8A72}" = protocol=17 | dir=in | app=c:&#092;program files&#092;bonjour&#092;mdnsresponder.exe | <br />"{2C47A73F-544F-4F73-8A83-7B349EF3BF10}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | <br />"{495B0F40-8921-4B0F-B925-9B23B39E467A}" = protocol=6 | dir=in | app=c:&#092;windows&#092;system32&#092;lxbvcoms.exe | <br />"{4D83017C-A8D2-4D7A-8D0E-A6CDD1D8CDC3}" = protocol=6 | dir=in | app=c:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe | <br />"{4FAE7E42-AFD2-4946-A0B0-F6C2C4D5BFA7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | <br />"{5F554643-842F-4E2F-809B-F203CF5DA3A4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | <br />"{692109D4-8AEB-44D8-BDA6-A046A9D8BC4F}" = protocol=6 | dir=in | app=c:&#092;program files&#092;bonjour&#092;mdnsresponder.exe | <br />"{719B634B-3C16-4E72-A5B7-5FDD282092AF}" = protocol=17 | dir=in | app=c:&#092;program files&#092;dna&#092;btdna.exe | <br />"{78993F7F-B07B-4426-8C03-22B43BD3F28C}" = protocol=6 | dir=in | app=c:&#092;program files&#092;pando networks&#092;media booster&#092;pmb.exe | <br />"{7B3E5411-29FE-44FC-AF15-9934EDD69699}" = protocol=17 | dir=in | app=c:&#092;program files&#092;bellsouth&#092;mccibrowser.exe | <br />"{7E82D3BA-EDF1-4EFC-9262-EF9ADE7FA90B}" = dir=in | app=c:&#092;program files&#092;pando networks&#092;media booster&#092;pmb.exe | <br />"{989ACB2C-6F64-43E0-9E2B-E63BB92BC9CE}" = protocol=17 | dir=in | app=c:&#092;program files&#092;common files&#092;aol&#092;loader&#092;aolload.exe | <br />"{99CAB6D2-B236-4148-AEBD-B67C8FC30FAD}" = protocol=17 | dir=in | app=c:&#092;program files&#092;pando networks&#092;media booster&#092;pmb.exe | <br />"{9D2FA44F-AC46-4FED-943F-A7FCC833EE71}" = protocol=17 | dir=in | app=c:&#092;program files&#092;bittorrent&#092;bittorrent.exe | <br />"{A977F543-B128-435E-91CB-F38EE2A95117}" = protocol=6 | dir=in | app=c:&#092;program files&#092;bittorrent&#092;bittorrent.exe | <br />"{C230E5BA-6C56-4F4E-8FBD-8BA600309AE9}" = protocol=6 | dir=in | app=c:&#092;program files&#092;dna&#092;btdna.exe | <br />"{C330009F-7C13-4523-871B-668D6D3181D2}" = protocol=17 | dir=in | app=c:&#092;program files&#092;pando networks&#092;media booster&#092;pmb.exe | <br />"{C5F14717-D1FA-485C-AACB-1F4AA34D68A6}" = protocol=6 | dir=in | app=c:&#092;program files&#092;pando networks&#092;media booster&#092;pmb.exe | <br />"{CF066B1F-FEC2-4E7D-9200-38FA5FFA153B}" = protocol=6 | dir=in | app=c:&#092;program files&#092;itunes&#092;itunes.exe | <br />"{D5DC7905-98E0-44F4-954E-2138B1E6080A}" = dir=in | app=c:&#092;program files&#092;common files&#092;mcafee&#092;mna&#092;mcnasvc.exe | <br />"{EB194BE1-05EE-4477-B1B9-3A65BCAF9328}" = protocol=6 | dir=in | app=c:&#092;program files&#092;common files&#092;aol&#092;loader&#092;aolload.exe | <br />"{F089385B-5626-4F3B-8DC2-12C2AA75FB2F}" = protocol=6 | dir=in | app=c:&#092;program files&#092;aim6&#092;aim6.exe | <br />"{F7CF15F4-9D77-4654-B597-A0FD63B163BC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | <br />"TCP Query User{003607D0-4184-4FD5-9D01-5FCA58109AEC}C:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe | <br />"TCP Query User{1E54808C-EB1A-48B0-BAEC-173316713F92}C:&#092;program files&#092;bb11 reloader&#092;bbreloader.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;bb11 reloader&#092;bbreloader.exe | <br />"TCP Query User{3C39F3C2-2DB3-41DB-8A86-F50A15921489}C:&#092;program files&#092;bb11 reloader&#092;bar.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;bb11 reloader&#092;bar.exe | <br />"TCP Query User{4C55D5F2-F30D-4825-896D-1226C301C0B5}C:&#092;program files&#092;bb9 reloader&#092;bbreloader.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;bb9 reloader&#092;bbreloader.exe | <br />"TCP Query User{5C9DDA13-3F1E-4735-A9F7-BF15C223ED09}C:&#092;users&#092;family&#092;desktop&#092;iexplore.exe" = protocol=6 | dir=in | app=c:&#092;users&#092;family&#092;desktop&#092;iexplore.exe | <br />"TCP Query User{6A86DF17-08FD-480D-BA03-3EAD61A93FBF}C:&#092;program files&#092;electronic arts&#092;eadm&#092;core.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;electronic arts&#092;eadm&#092;core.exe | <br />"TCP Query User{6FEA3C42-4EC2-4FEB-8654-6FB070E50651}C:&#092;program files&#092;real&#092;realplayer&#092;realplay.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;real&#092;realplayer&#092;realplay.exe | <br />"TCP Query User{95C4061A-C34D-4C38-B703-581E8C9B7A3D}C:&#092;program files&#092;mozilla firefox&#092;firefox.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;mozilla firefox&#092;firefox.exe | <br />"TCP Query User{9838BF94-E3E2-4C02-95FA-6B9EB1A02F8D}C:&#092;program files&#092;bb10 reloader&#092;bbreloader.exe" = protocol=6 | dir=in | app=c:&#092;program files&#092;bb10 reloader&#092;bbreloader.exe | <br />"TCP Query User{BA127C7D-237D-4366-A9F3-CB7A201B5A5D}C:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;www.macromedia.com&#092;bin&#092;octoshape&#092;octoshape.exe" = protocol=6 | dir=in | app=c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;www.macromedia.com&#092;bin&#092;octoshape&#092;octoshape.exe | <br />"UDP Query User{04936E66-0EDB-49C1-A544-380DC9CA4050}C:&#092;program files&#092;mozilla firefox&#092;firefox.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;mozilla firefox&#092;firefox.exe | <br />"UDP Query User{091E7A66-C9F0-4BE8-A546-BFA90523DAB6}C:&#092;program files&#092;bb9 reloader&#092;bbreloader.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;bb9 reloader&#092;bbreloader.exe | <br />"UDP Query User{096A4874-04D4-4D60-B226-B9746057F44F}C:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;yahoo!&#092;messenger&#092;yahoomessenger.exe | <br />"UDP Query User{0C92D36B-2434-4FB5-90E5-A4423A1C3681}C:&#092;program files&#092;electronic arts&#092;eadm&#092;core.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;electronic arts&#092;eadm&#092;core.exe | <br />"UDP Query User{2C8E4EAE-F4D6-439A-BFCF-6F948F2672AD}C:&#092;program files&#092;real&#092;realplayer&#092;realplay.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;real&#092;realplayer&#092;realplay.exe | <br />"UDP Query User{8A3E1085-4383-4A29-9FE9-F4C44D7826DC}C:&#092;program files&#092;bb11 reloader&#092;bbreloader.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;bb11 reloader&#092;bbreloader.exe | <br />"UDP Query User{90F6E261-38F7-4F74-9A1D-886AF92C5BB3}C:&#092;program files&#092;bb10 reloader&#092;bbreloader.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;bb10 reloader&#092;bbreloader.exe | <br />"UDP Query User{A6FEA435-74D1-4185-98B9-875F5218DE2C}C:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;www.macromedia.com&#092;bin&#092;octoshape&#092;octoshape.exe" = protocol=17 | dir=in | app=c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;www.macromedia.com&#092;bin&#092;octoshape&#092;octoshape.exe | <br />"UDP Query User{B6117340-CA28-4006-8DE1-961EEAA49682}C:&#092;users&#092;family&#092;desktop&#092;iexplore.exe" = protocol=17 | dir=in | app=c:&#092;users&#092;family&#092;desktop&#092;iexplore.exe | <br />"UDP Query User{CF45D1CF-ACA7-40C4-87FB-BFD74D4A6BA2}C:&#092;program files&#092;bb11 reloader&#092;bar.exe" = protocol=17 | dir=in | app=c:&#092;program files&#092;bb11 reloader&#092;bar.exe | <br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== HKEY_LOCAL_MACHINE Uninstall List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />"{00030409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Small Business<br />"{022B0C16-18C9-464A-8BC6-2B2CC6342E5F}" = Image Trends' ShineOff Plug-In 1.0.2<br />"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status<br />"{05D60953-9012-44DF-A1A6-9DD97AD6580A}" = Corel Painter X<br />"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour<br />"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5<br />"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support<br />"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox<br />"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library<br />"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1<br />"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works<br />"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer<br />"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService<br />"{1A0FDBEB-BDFE-454C-AE09-4EF58B4DCD2A}" = Art Explosion Home & Student Print Center<br />"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe<br />"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget<br />"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine<br />"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer<br />"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check<br />"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer<br />"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java&#153; 6 Update 17<br />"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2<br />"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java&#153; SE Runtime Environment 6 Update 1<br />"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE<br />"{35A0AEE7-A74F-47B5-A573-CDE69F5C99D0}" = Rhapsody MP3 Download Manager<br />"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant<br />"{37F9D0BD-9AED-4EE6-BCA3-BA0749636E04}" = Hoyle Board Games 2003<br />"{3EBA6E7C-3DF6-48AE-B87B-4CAFB2C1C3F7}" = LightScribe Template Labeler<br />"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go<br />"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets<br />"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout<br />"{4D9C7DA3-D532-432D-A556-5F6CD186B0A5}" = DJ_AIO_03_F4200_ProductContext<br />"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC<br />"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)<br />"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In<br />"{5783F2D7-0201-0409-0000-0060B0CE6BBA}" = AutoCAD 2004<br />"{5783F2D7-0211-0409-0000-0060B0CE6BBA}" = AutoCAD Express Tools Volumes 1-9<br />"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English<br />"{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services<br />"{62653245-3DC5-4019-AF6B-4E62D6150D9E}" = F4200_Help<br />"{64E72FB1-2343-4977-B4A8-262CD53D0BD3}" = Corel Paint Shop Pro Photo X2<br />"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check<br />"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder<br />"{67DFCE0D-BBA9-43AC-90B3-548390ECE522}" = F4200<br />"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm<br />"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update<br />"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin<br />"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder<br />"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable<br />"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com<br />"{77EBC8CD-F808-4ECD-93D0-311C27B09827}" = ATT eChat Support Tools<br />"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business<br />"{7BB40A22-8D98-43F9-A08A-E7EFF5AB1324}" = Camtasia Studio 5<br />"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software<br />"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime<br />"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight<br />"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport<br />"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2<br />"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University<br />"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system<br />"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel&reg; Matrix Storage Manager<br />"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player<br />"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster<br />"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend<br />"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp<br />"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback<br />"{9DBCE8C7-FE94-4D8F-9FF0-38EF3D8BC99E}" = DJ_AIO_03_F4200_Software<br />"{9ED71778-0E56-4760-9FC6-2C29D75100C5}" = Radioshack USB-to-Serial Cable Driver Installer<br />"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan<br />"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR<br />"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime<br />"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter<br />"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper<br />"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support<br />"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder<br />"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1<br />"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8<br />"{AFAD41A9-9687-48A3-848F-693C11451433}" = HP Customer Experience Enhancements<br />"{B29B526D-F027-4122-BC7A-D9E5BC86CC40}" = DJ_AIO_03_F4200_Software_Min<br />"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life<br />"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply<br />"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5<br />"{C01F4D52-6933-494E-8056-C2063D2F451C}" = BB11 Reloader<br />"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3<br />"{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}" = MapleStory<br />"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint<br />"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector<br />"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth<br />"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg<br />"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00<br />"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1<br />"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch<br />"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component<br />"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes<br />"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware<br />"{DF507C99-7DE1-4fa8-8632-AB8A205F1258}" = The Sims™ 2 Store Edition<br />"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons<br />"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01<br />"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime<br />"{E8C2622C-9FF1-4F60-8008-A0208154F9F3}" = muvee autoProducer 6.1<br />"{e96b3d28-47d6-43cc-98fd-7069eeab6b11}" = HP Total Care Advisor<br />"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery<br />"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver<br />"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)<br />"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01<br />"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy<br />"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife<br />"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update<br />"AceHTML Freeware" = AceHTML Freeware<br />"Ad-Aware" = Ad-Aware<br />"Adobe AIR" = Adobe AIR<br />"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX<br />"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin<br />"Adobe Shockwave Player" = Adobe Shockwave Player 11<br />"AIM_6" = AIM 6<br />"AutoCAD 2009 - English" = AutoCAD 2009 - English<br />"Autodesk Express Viewer" = Autodesk Express Viewer<br />"AVIConverter" = AVIConverter 5.1<br />"AVS Update Manager_is1" = AVS Update Manager 1.0<br />"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3<br />"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6<br />"BellSouth Application Management" = BellSouth Application Management<br />"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.3<br />"CEP - Colour Enable Packages_is1" = CEP - Color Enable Package<br />"Clue" = Clue<br />"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP<br />"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com<br />"DirectXMediaRuntime" = DirectX Media Runtime 5.1<br />"Disney Toontown Online" = Disney Toontown Online<br />"EADM" = EA Download Manager<br />"eMusic Download Manager" = eMusic Download Manager 4.1.2<br />"ERUNT_is1" = ERUNT 1.1j<br />"Free Internet Eraser_is1" = Free Internet Eraser 2.30<br />"Google Chrome" = Google Chrome<br />"Google Updater" = Google Updater<br />"HDMI" = Intel&reg; Graphics Media Accelerator Driver<br />"HijackThis" = HijackThis 2.0.2<br />"HP Imaging Device Functions" = HP Imaging Device Functions 10.0<br />"HP Photosmart Essential" = HP Photosmart Essential 2.5<br />"HP Smart Web Printing" = HP Smart Web Printing<br />"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0<br />"HPExtendedCapabilities" = HP Customer Participation Program 10.0<br />"InstallShield_{37F9D0BD-9AED-4EE6-BCA3-BA0749636E04}" = Hoyle Board Games 2003<br />"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector<br />"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00<br />"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware<br />"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1<br />"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)<br />"MSC" = McAfee SecurityCenter<br />"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control<br />"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator<br />"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools<br />"Q-Xpress Installer" = Q-Xpress Installer 1.1.9<br />"RCA Detective™_is1" = RCA Detective™ 2.0.0.98<br />"RCA easyRip™_is1" = RCA easyRip™ 1.4.6.0<br />"Serwpl" = RadioShack USB to Serial Cable<br />"Shop for HP Supplies" = Shop for HP Supplies<br />"ST6UNST #1" = Meracl ImageMap Generator v3.5.3<br />"ViewpointMediaPlayer" = Viewpoint Media Player<br />"WildTangent hp Master Uninstall" = My HP Games<br />"WinAce Archiver" = WinAce Archiver - Powered by AdVantage<br />"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner<br />"Wisdom-soft ScreenHunter 5.0 Free" = Wisdom-soft ScreenHunter 5.0 Free<br />"Xvid_is1" = Xvid 1.1.3 final uninstall<br />"Yahoo! Companion" = Yahoo! Toolbar<br />"Yahoo! Mail" = Yahoo! Internet Mail<br />"Yahoo! Messenger" = Yahoo! Messenger<br />"Yahoo! Search Defender" = Yahoo! Search Protection<br />"Yahoo! Software Update" = Yahoo! Software Update<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== HKEY_CURRENT_USER Uninstall List ==========<!--colorc--></span><!--/colorc--><br /> <br />[HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Uninstall]<br />"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player<br />"Yahoo! BrowserPlus" = Yahoo! BrowserPlus<br /> <br /><!--coloro:#E56717--><span style="color:#E56717"><!--/coloro-->========== Last 10 Event Log Errors ==========<!--colorc--></span><!--/colorc--><br /> <br />[ Application Events ]<br />Error - 7/21/2009 10:59:02 AM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 11:22:27 AM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 12:29:52 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 2:09:47 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 2:56:18 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 4:35:08 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 8:15:03 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/21/2009 10:17:12 PM | Computer Name = family-PC | Source = EventSystem | ID = 4621<br />Description = <br /> <br />Error - 7/22/2009 5:25:31 AM | Computer Name = family-PC | Source = Application Error | ID = 1000<br />Description = Faulting application Painter X.exe, version 10.0.0.46, time stamp <br />0x45804269, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a7a6,<br /> exception code 0xc0000005, fault offset 0x00068516,  process id 0x434, application<br /> start time 0x01ca0aac413b4b10.<br /> <br />Error - 7/22/2009 9:20:15 PM | Computer Name = family-PC | Source = EventSystem | ID = 4609<br />Description = <br /> <br />[ Media Center Events ]<br />Error - 2/15/2008 4:50:23 PM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.<br /> <br />Error - 4/17/2008 9:57:13 PM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.<br /> <br />Error - 6/1/2008 9:32:07 PM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.<br /> <br />Error - 6/30/2008 3:36:54 PM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.<br /> <br />Error - 8/28/2008 11:48:38 AM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.<br /> <br />Error - 8/31/2008 2:05:33 AM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.<br /> <br />Error - 6/11/2009 2:20:06 PM | Computer Name = family-PC | Source = MCUpdate | ID = 0<br />Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.<br /> <br />[ System Events ]<br />Error - 11/17/2009 12:03:57 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 12:03:57 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 12:03:57 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 12:04:35 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7022<br />Description = <br /> <br />Error - 11/17/2009 12:04:36 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7026<br />Description = <br /> <br />Error - 11/17/2009 1:00:19 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 1:00:19 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 1:00:19 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7000<br />Description = <br /> <br />Error - 11/17/2009 1:00:36 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7022<br />Description = <br /> <br />Error - 11/17/2009 1:00:36 AM | Computer Name = family-PC | Source = Service Control Manager | ID = 7026<br />Description = <br /> <br /> <br />&lt; End of report &gt;<br /><br /><br />MBAM LOG:<br /><br />Malwarebytes' Anti-Malware 1.41<br />Database version: 3185<br />Windows 6.0.6002 Service Pack 2<br /><br />11/16/2009 11:52:49 PM<br />mbam-log-2009-11-16 (23-52-49).txt<br /><br />Scan type: Quick Scan<br />Objects scanned: 120886<br />Time elapsed: 11 minute(s), 35 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 0<br />Folders Infected: 0<br />Files Infected: 0<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />(No malicious items detected)<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />(No malicious items detected)<br /><br />ROOTER:<br /><br />Rooter.exe (v1.0.2) by Eric_71<br />.<br />The token does not have the SeDebugPrivilege privilege ! (error:1300)<br /><b>Can not acquire SeDebugPrivilege !<br />Please run the tool as administrator ..</b><br />.<br />Windows Vista Home Edition (6.0.6002) Service Pack 2<br />[32_bits] - x86 Family 6 Model 15 Stepping 13, GenuineIntel<br />.<br />Error OpenService (wscsvc) : 6<br />Error OpenSCManager : 5<br />Error OpenService (MpsSvc) : 6<br />Windows Defender -&gt; Disabled !<br />User Account Control (UAC) -&gt; Enabled<br />.<br />Internet Explorer 8.0.6001.18828<br />Mozilla Firefox 3.5.5 (en-US)<br />.<br />C:&#092;  [Fixed-NTFS] .. ( Total:325 Go - Free:139 Go )<br />D:&#092;  [Fixed-NTFS] .. ( Total:9 Go - Free:1 Go )<br />E:&#092;  [CD_Rom]<br />.<br />Scan : 22:36.53<br />Path : C:&#092;Users&#092;family&#092;Downloads&#092;Rooter.exe<br />User : family ( Administrator -&gt; YES )<br />.<br />----------------------&#092;&#092; Processes<br />.<br />Locked [System Process] (0)<br />Locked System (4)<br />Locked smss.exe (484)<br />Locked csrss.exe (568)<br />Locked wininit.exe (612)<br />Locked services.exe (656)<br />Locked lsass.exe (668)<br />Locked lsm.exe (680)<br />Locked svchost.exe (864)<br />Locked svchost.exe (924)<br />Locked svchost.exe (1096)<br />Locked svchost.exe (1128)<br />Locked svchost.exe (1140)<br />Locked audiodg.exe (1220)<br />Locked svchost.exe (1244)<br />Locked SLsvc.exe (1268)<br />Locked svchost.exe (1304)<br />Locked svchost.exe (1488)<br />Locked AAWService.exe (1588)<br />Locked spoolsv.exe (1684)<br />Locked svchost.exe (1744)<br />Locked AppleMobileDeviceService.exe (1956)<br />Locked mDNSResponder.exe (1972)<br />Locked svchost.exe (2028)<br />Locked IAANTmon.exe (2044)<br />Locked LSSrvc.exe (508)<br />Locked lxbvcoms.exe (1116)<br />Locked McSACore.exe (1348)<br />Locked McciCMService.exe (1524)<br />Locked McProxy.exe (764)<br />Locked Mcshield.exe (1596)<br />Locked MpfSrv.exe (528)<br />Locked svchost.exe (2068)<br />Locked svchost.exe (2096)<br />Locked svchost.exe (2108)<br />Locked PSIService.exe (2128)<br />Locked PsiService_2.exe (2156)<br />Locked svchost.exe (2184)<br />Locked ViewpointService.exe (2240)<br />Locked svchost.exe (2256)<br />Locked SearchIndexer.exe (2296)<br />Locked XAudio.exe (2380)<br />Locked YahooAUService.exe (2520)<br />Locked taskeng.exe (3232)<br />Locked unsecapp.exe (2084)<br />Locked WmiPrvSE.exe (336)<br />Locked wmpnetwk.exe (3912)<br />Locked mcsysmon.exe (2472)<br />Locked mcmscsvc.exe (836)<br />Locked iPodService.exe (4188)<br />Locked PresentationFontCache.exe (4868)<br />Locked HPHC_Service.exe (5060)<br />Locked McNASvc.exe (5132)<br />Locked WmiPrvSE.exe (5200)<br />Locked csrss.exe (4680)<br />Locked winlogon.exe (860)<br />______ c:&#092;PROGRA~1&#092;mcafee.com&#092;agent&#092;mcagent.exe (3828)<br />______ C:&#092;Windows&#092;system32&#092;Dwm.exe (1084)<br />______ C:&#092;Windows&#092;system32&#092;taskeng.exe (2760)<br />______ C:&#092;Windows&#092;Explorer.EXE (5408)<br />______ C:&#092;Program Files&#092;Lavasoft&#092;Ad-Aware&#092;AAWTray.exe (4368)<br />______ C:&#092;Program Files&#092;FastAccessDSL&#092;HelpCenter43&#092;bin&#092;sprtcmd.exe (6008)<br />______ C:&#092;Program Files&#092;Intel&#092;Intel Matrix Storage Manager&#092;IAAnotif.exe (4160)<br />______ C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;hpwuSchd2.exe (4112)<br />______ C:&#092;Program Files&#092;Yahoo!&#092;Search Protection&#092;SearchProtection.exe (768)<br />______ C:&#092;Program Files&#092;iTunes&#092;iTunesHelper.exe (5988)<br />______ C:&#092;Windows&#092;System32&#092;hkcmd.exe (5300)<br />______ C:&#092;Windows&#092;System32&#092;igfxpers.exe (5940)<br />______ C:&#092;Program Files&#092;Java&#092;jre6&#092;bin&#092;jusched.exe (304)<br />______ C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe (3172)<br />______ C:&#092;Program Files&#092;Hewlett-Packard&#092;HP Advisor&#092;HPAdvisor.exe (3372)<br />______ C:&#092;Windows&#092;system32&#092;igfxsrvc.exe (5212)<br />______ C:&#092;Windows&#092;ehome&#092;ehtray.exe (3932)<br />______ C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqtra08.exe (3268)<br />______ C:&#092;Program Files&#092;Windows Media Player&#092;wmpnscfg.exe (4144)<br />______ C:&#092;Windows&#092;system32&#092;wbem&#092;unsecapp.exe (2452)<br />______ C:&#092;Windows&#092;ehome&#092;ehmsas.exe (5016)<br />______ C:&#092;Program Files&#092;Windows Sidebar&#092;sidebar.exe (5804)<br />______ C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqSTE08.exe (2892)<br />______ C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqbam08.exe (5320)<br />______ C:&#092;Program Files&#092;Yahoo!&#092;Messenger&#092;ymsgr_tray.exe (5460)<br />______ C:&#092;Program Files&#092;HP&#092;Digital Imaging&#092;bin&#092;hpqgpc01.exe (728)<br />Locked WUDFHost.exe (6100)<br />______ C:&#092;Windows&#092;System32&#092;mobsync.exe (5012)<br />______ C:&#092;Windows&#092;system32&#092;DllHost.exe (4472)<br />______ C:&#092;Program Files&#092;Mozilla Firefox&#092;firefox.exe (3756)<br />______ C:&#092;Users&#092;family&#092;Downloads&#092;Rooter.exe (1196)<br />.<br />----------------------&#092;&#092; Device&#092;Harddisk0&#092;<br />.<br />&#092;Device&#092;Harddisk0 [Sectors : 63 x 512 Bytes]<br />.<br />&#092;Device&#092;Harddisk0&#092;Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:349919829504)<br />&#092;Device&#092;Harddisk0&#092;Partition2 (Start_Offset:349919861760 | Length:10158220800)<br />.<br />----------------------&#092;&#092; Scheduled Tasks<br />.<br />C:&#092;Windows&#092;Tasks&#092;Ad-Aware Update (Weekly).job<br />C:&#092;Windows&#092;Tasks&#092;Google Software Updater.job<br />C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineCore.job<br />C:&#092;Windows&#092;Tasks&#092;GoogleUpdateTaskMachineUA.job<br />C:&#092;Windows&#092;Tasks&#092;McDefragTask.job<br />C:&#092;Windows&#092;Tasks&#092;McQcTask.job<br />C:&#092;Windows&#092;Tasks&#092;SA.DAT<br />C:&#092;Windows&#092;Tasks&#092;SCHEDLGU.TXT<br />C:&#092;Windows&#092;Tasks&#092;User_Feed_Synchronization-{4B3593F7-9DDC-4031-B174-350188CC183B}.job<br />.<br />----------------------&#092;&#092; Registry<br />.<br />.<br />----------------------&#092;&#092; Files & Folders<br />.<br />C:&#092;PROGRA~1&#092;PrivacyEraser Computing<br /><b>==&gt; Rogues &lt;==</b><br />.<br />----------------------&#092;&#092; Scan completed at 22:39.38<br />.<br />C:&#092;Rooter$&#092;Rooter_4.txt - (17/11/2009 | 22:39.38)<br /><br />CKSCANNER:<br /><br />CKScanner - Additional Security Risks - These are not necessarily bad<br />c:&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;eggcrack1.gif<br />c:&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;eggcrack2.gif<br />c:&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;_eggcrack1.gif<br />c:&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;_eggcrack2.gif<br />c:&#092;users&#092;family&#092;appdata&#092;local&#092;virtualstore&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;eggcrack1.gif<br />c:&#092;users&#092;family&#092;appdata&#092;local&#092;virtualstore&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;eggcrack2.gif<br />c:&#092;users&#092;family&#092;appdata&#092;local&#092;virtualstore&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;_eggcrack1.gif<br />c:&#092;users&#092;family&#092;appdata&#092;local&#092;virtualstore&#092;program files&#092;hp games&#092;insaniquarium deluxe&#092;images&#092;_eggcrack2.gif<br />c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;#sharedobjects&#092;fz4j5zdh&#092;crackle.com&#092;cracklesettings.sol<br />c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;#sharedobjects&#092;fz4j5zdh&#092;www.crackle.com&#092;cracklesettings.sol<br />c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;#sharedobjects&#092;fz4j5zdh&#092;www.crackle.com&#092;tracking.sol<br />c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;macromedia.com&#092;support&#092;flashplayer&#092;sys&#092;#crackle.com&#092;settings.sol<br />c:&#092;users&#092;family&#092;appdata&#092;roaming&#092;macromedia&#092;flash player&#092;macromedia.com&#092;support&#092;flashplayer&#092;sys&#092;#www.crackle.com&#092;settings.sol<br />scanner sequence 3.ZZ.11<br /> ----- EOF ----- <br /><br /><br />ROOTREPEAL:<br /><br />rootrepeal crashed six time before this report<br /><br />ROOTREPEAL &copy; AD, 2007-2009<br />==================================================<br />Scan Start Time:		2009/11/18 01:58<br />Program Version:		Version 1.3.5.0<br />Windows Version:		Windows Vista SP2<br />==================================================<br /><br />Drivers<br />-------------------<br />Name: dump_iaStor.sys<br />Image Path: C:&#092;Windows&#092;System32&#092;Drivers&#092;dump_iaStor.sys<br />Address: 0x93203000	Size: 892928	File Visible: No	Signed: -<br />Status: -<br /><br />Name: rootrepeal.sys<br />Image Path: C:&#092;Windows&#092;system32&#092;drivers&#092;rootrepeal.sys<br />Address: 0xB31E1000	Size: 49152	File Visible: No	Signed: -<br />Status: -<br /><br />Processes<br />-------------------<br />Path: System<br />PID: 4	Status: Locked to the Windows API!<br /><br />Path: C:&#092;Windows&#092;System32&#092;audiodg.exe<br />PID: 1280	Status: Locked to the Windows API!<br /><br />==EOF==<br /><br />thank you for your help<br />]]></description>
		<pubDate>Thu, 19 Nov 2009 04:42:41 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5874</guid>
	</item>
	<item>
		<title>unknown virus/malware</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5861</link>
		<description><![CDATA[Hi again----I have definitely a problem and may be the vundo virus again on a different computer for my friend.  I have a lot of popups, trouble accessing the internet and running programs.<br /><br />Doing the initial steps I can not run--<br />ATF Cleaner<br />MBAM<br />CKScanner<br /><br />(also there was not an AV program anylonger and could not install AVG)<br /><br />OTL, Rooter, LockSearch and RootRepeal logs to follow]]></description>
		<pubDate>Tue, 10 Nov 2009 03:51:18 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5861</guid>
	</item>
	<item>
		<title>Vundo, please help me remove it!</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5860</link>
		<description><![CDATA[Hello.<br /><br />I have a rather irritating problem.<br />I normally use firefox but today internet explorer keeps popping up on it's own with a blank page and a random URL at the top. Then a message pops up saying IE has stopped working. <br /><br />I ran three different virus scans in regular and safe mode each and was able to remove a few harmful things each time but no matter what I do, I still have the same problem. I has Malwarebytes installed but it wasn't working so I reinstalled it and kept getting a message saying <br /><br /><i>Unable to execute file:<br /><br />c:&#092;Program Files&#092;Malwarebytes' Anti-Malware/mbam.exe<br /><br />CreateProcess failed; Code 2.<br />The system cannot find the file specified.</i><br /><br />So The next thing I did was ran OTS.<br /><br />But I don't know what to do after that to get my computer back to normal.<br />Can someone help me please? <br /><br /><br />Here is the report from OTS, I didn't know how else to upload it here. I hope it works.<br /><a href='http://www.atribune.org/forums/index.php?act=attach&type=post&id=1253'>http://www.atribune.org/forums/index.php?act=attach&type=post&id=1253</a>]]></description>
		<pubDate>Mon, 09 Nov 2009 01:27:36 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5860</guid>
	</item>
	<item>
		<title>Guide for New Vundo.H virus</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5866</link>
		<description>removed malware advice</description>
		<pubDate>Fri, 13 Nov 2009 12:37:27 +0100</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5866</guid>
	</item>
	<item>
		<title>Virus that shuts down anti-virus help??</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5837</link>
		<description><![CDATA[i know i have a virus on my computer. whenever i run ANY type of anit-virus, it will shut it down and uninstall it immeditaly. this includes (so far) Webroot, Ad-ware, Spyware Docto, Super Anti-Spyware, and Malwarebytes' Anit-malware. i have tried re-installing all of them, but it just won't take hold. As such, i cant do the 'before you post' thing, although i have tried. Any ideas? (btw- this is all on the family's home computer, and i'm leaving for college again soon. if there's no post, that's why) Thanks!]]></description>
		<pubDate>Sun, 18 Oct 2009 19:58:22 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5837</guid>
	</item>
	<item>
		<title>possible vundo problem; please help</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5809</link>
		<description><![CDATA[I think I might have a Vundo problem on my computer. I think this because I was getting the Virus Doctor pop ups. I ran Vundo Fix and got nothing. I would greatly appreciate any help. Thanks.<br /><br />I have the logs for Malwarebytes and hijackThis<br /><br /><br /><br /><br />Malwarebytes:<br /><br />Malwarebytes' Anti-Malware 1.41<br />Database version: 2792<br />Windows 6.0.6002 Service Pack 2<br /><br />9/13/2009 3:26:55 PM<br />mbam-log-2009-09-13 (15-26-55).txt<br /><br />Scan type: Quick Scan<br />Objects scanned: 77698<br />Time elapsed: 2 minute(s), 2 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 2<br />Folders Infected: 0<br />Files Infected: 0<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoActiveDesktopChanges (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Explorer&#092;Advanced&#092;Start_ShowSearch (Hijack.StartMenu) -&gt; Bad: (0) Good: (1) -&gt; Quarantined and deleted successfully.<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />(No malicious items detected)<br /><br /><br /><br /><br /><br />hijackthis:<br />Logfile of Trend Micro HijackThis v2.0.2<br />Scan saved at 4:11:01 PM, on 9/13/2009<br />Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />MSIE: Internet Explorer v8.00 (8.00.6001.18813)<br />Boot mode: Normal<br /><br />Running processes:<br />C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QLBCTRL.exe<br />C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashDisp.exe<br />C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msntask.exe<br />C:&#092;Windows&#092;SysWow64&#092;Macromed&#092;Flash&#092;FlashUtil10a.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Trend Micro&#092;HijackThis&#092;HijackThis.exe<br /><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;SysWOW64&#092;blank.htm<br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />O1 - Hosts: ::1 localhost<br />O2 - BHO: (no name) - MRI_DISABLED - (no file)<br />O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msneshellx.dll<br />O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msneshellx.dll<br />O4 - HKLM&#092;..&#092;Run: [WirelessAssistant] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Wireless Assistant&#092;HPWAMain.exe<br />O4 - HKLM&#092;..&#092;Run: [QlbCtrl.exe] "C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QlbCtrl.exe" /Start<br />O4 - HKLM&#092;..&#092;Run: [avast!] C:&#092;PROGRA~1&#092;ALWILS~1&#092;Avast4&#092;ashDisp.exe<br />O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files (x86)&#092;QuickTime&#092;QTTask.exe" -atboottime<br />O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe"<br />O4 - HKLM&#092;..&#092;Run: [Malwarebytes Anti-Malware (reboot)] "C:&#092;Program Files (x86)&#092;Malwarebytes' Anti-Malware&#092;mbam.exe" /runcleanupscript<br />O4 - HKCU&#092;..&#092;Run: [Sidebar] "C:&#092;Program Files&#092;Windows Sidebar&#092;Sidebar.exe" /autorun<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;EXCEL.EXE/3000<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~2&#092;Java&#092;JRE16~1.0_0&#092;bin&#092;ssv.dll<br />O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~2&#092;Java&#092;JRE16~1.0_0&#092;bin&#092;ssv.dll<br />O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;REFIEBAR.DLL<br />O13 - Gopher Prefix: <br />O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;stwrt64.inf_5730ce9f&#092;AESTSr64.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;Alg.exe,-112 (ALG) - Unknown owner - C:&#092;Windows&#092;System32&#092;alg.exe (file missing)<br />O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;aswUpdSv.exe<br />O23 - Service: avast! Antivirus - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashServ.exe<br />O23 - Service: avast! Mail Scanner - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashMaiSv.exe<br />O23 - Service: avast! Web Scanner - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashWebSv.exe<br />O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files (x86)&#092;Bonjour&#092;mDNSResponder.exe<br />O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;Com4QLBEx.exe<br />O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:&#092;Windows&#092;system32&#092;DFSR.exe (file missing)<br />O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files (x86)&#092;iPod&#092;bin&#092;iPodService.exe<br />O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:&#092;Windows&#092;System32&#092;msdtc.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;System32&#092;netlogon.dll,-102 (Netlogon) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: Recovery Service for Windows - Unknown owner - C:&#092;Program Files (x86)&#092;SMINST&#092;BLService.exe<br />O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:&#092;Program Files (x86)&#092;CyberLink&#092;Shared files&#092;RichVideo.exe<br />O23 - Service: @%systemroot%&#092;system32&#092;Locator.exe,-2 (RpcLocator) - Unknown owner - C:&#092;Windows&#092;system32&#092;locator.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;samsrv.dll,-1 (SamSs) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;SLsvc.exe,-101 (slsvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;SLsvc.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:&#092;Windows&#092;System32&#092;snmptrap.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;spoolsv.exe,-1 (Spooler) - Unknown owner - C:&#092;Windows&#092;System32&#092;spoolsv.exe (file missing)<br />O23 - Service: Audio Service (STacSV) - Unknown owner - C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;stwrt64.inf_5730ce9f&#092;STacSV64.exe (file missing)<br />O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Media&#092;TV&#092;Kernel&#092;TV&#092;TVCapSvc.exe<br />O23 - Service: @%SystemRoot%&#092;system32&#092;ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:&#092;Windows&#092;system32&#092;UI0Detect.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;vds.exe,-100 (vds) - Unknown owner - C:&#092;Windows&#092;System32&#092;vds.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;vssvc.exe,-102 (VSS) - Unknown owner - C:&#092;Windows&#092;system32&#092;vssvc.exe (file missing)<br />O23 - Service: @%Systemroot%&#092;system32&#092;wbem&#092;wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbem&#092;WmiApSrv.exe (file missing)<br />O23 - Service: @%ProgramFiles%&#092;Windows Media Player&#092;wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Windows Media Player&#092;wmpnetwk.exe (file missing)<br /><br />--<br />End of file - 8350 bytes<br />]]></description>
		<pubDate>Sun, 13 Sep 2009 22:28:08 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5809</guid>
	</item>
	<item>
		<title>possible vundo problem; please help</title>
		<link>http://www.atribune.org/forums/index.php?showtopic=5808</link>
		<description><![CDATA[I think I might have a Vundo problem on my computer. I think this because I was getting the Virus Doctor pop ups. I ran Vundo Fix and got nothing. I would greatly appreciate any help. Thanks.<br /><br />I have the logs for Malwarebytes and hijackThis<br /><br /><br /><br /><br />Malwarebytes:<br /><br />Malwarebytes' Anti-Malware 1.41<br />Database version: 2792<br />Windows 6.0.6002 Service Pack 2<br /><br />9/13/2009 3:26:55 PM<br />mbam-log-2009-09-13 (15-26-55).txt<br /><br />Scan type: Quick Scan<br />Objects scanned: 77698<br />Time elapsed: 2 minute(s), 2 second(s)<br /><br />Memory Processes Infected: 0<br />Memory Modules Infected: 0<br />Registry Keys Infected: 0<br />Registry Values Infected: 0<br />Registry Data Items Infected: 2<br />Folders Infected: 0<br />Files Infected: 0<br /><br />Memory Processes Infected:<br />(No malicious items detected)<br /><br />Memory Modules Infected:<br />(No malicious items detected)<br /><br />Registry Keys Infected:<br />(No malicious items detected)<br /><br />Registry Values Infected:<br />(No malicious items detected)<br /><br />Registry Data Items Infected:<br />HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Policies&#092;Explorer&#092;NoActiveDesktopChanges (Hijack.DisplayProperties) -&gt; Bad: (1) Good: (0) -&gt; Quarantined and deleted successfully.<br />HKEY_CURRENT_USER&#092;SOFTWARE&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Explorer&#092;Advanced&#092;Start_ShowSearch (Hijack.StartMenu) -&gt; Bad: (0) Good: (1) -&gt; Quarantined and deleted successfully.<br /><br />Folders Infected:<br />(No malicious items detected)<br /><br />Files Infected:<br />(No malicious items detected)<br /><br /><br /><br /><br /><br />hijackthis:<br />Logfile of Trend Micro HijackThis v2.0.2<br />Scan saved at 4:11:01 PM, on 9/13/2009<br />Platform: Windows Vista SP2 (WinNT 6.00.1906)<br />MSIE: Internet Explorer v8.00 (8.00.6001.18813)<br />Boot mode: Normal<br /><br />Running processes:<br />C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QLBCTRL.exe<br />C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashDisp.exe<br />C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msntask.exe<br />C:&#092;Windows&#092;SysWow64&#092;Macromed&#092;Flash&#092;FlashUtil10a.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Internet Explorer&#092;iexplore.exe<br />C:&#092;Program Files (x86)&#092;Trend Micro&#092;HijackThis&#092;HijackThis.exe<br /><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = <a href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb" target="_blank">http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...ion&pf=cnnb</a><br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = <br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,CustomizeSearch = <br />R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Local Page = C:&#092;Windows&#092;SysWOW64&#092;blank.htm<br />R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Toolbar,LinksFolderName = <br />O1 - Hosts: ::1 localhost<br />O2 - BHO: (no name) - MRI_DISABLED - (no file)<br />O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:&#092;Program Files (x86)&#092;Common Files&#092;Adobe&#092;Acrobat&#092;ActiveX&#092;AcroIEHelperShim.dll<br />O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msneshellx.dll<br />O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:&#092;Program Files (x86)&#092;MSN&#092;Toolbar&#092;3.0.0541.0&#092;msneshellx.dll<br />O4 - HKLM&#092;..&#092;Run: [WirelessAssistant] C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Wireless Assistant&#092;HPWAMain.exe<br />O4 - HKLM&#092;..&#092;Run: [QlbCtrl.exe] "C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;QlbCtrl.exe" /Start<br />O4 - HKLM&#092;..&#092;Run: [avast!] C:&#092;PROGRA~1&#092;ALWILS~1&#092;Avast4&#092;ashDisp.exe<br />O4 - HKLM&#092;..&#092;Run: [Adobe Reader Speed Launcher] "C:&#092;Program Files (x86)&#092;Adobe&#092;Reader 9.0&#092;Reader&#092;Reader_sl.exe"<br />O4 - HKLM&#092;..&#092;Run: [QuickTime Task] "C:&#092;Program Files (x86)&#092;QuickTime&#092;QTTask.exe" -atboottime<br />O4 - HKLM&#092;..&#092;Run: [iTunesHelper] "C:&#092;Program Files (x86)&#092;iTunes&#092;iTunesHelper.exe"<br />O4 - HKLM&#092;..&#092;Run: [Malwarebytes Anti-Malware (reboot)] "C:&#092;Program Files (x86)&#092;Malwarebytes' Anti-Malware&#092;mbam.exe" /runcleanupscript<br />O4 - HKCU&#092;..&#092;Run: [Sidebar] "C:&#092;Program Files&#092;Windows Sidebar&#092;Sidebar.exe" /autorun<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-19&#092;..&#092;Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br />O4 - HKUS&#092;S-1-5-20&#092;..&#092;Run: [Sidebar] %ProgramFiles%&#092;Windows Sidebar&#092;Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br />O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;EXCEL.EXE/3000<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~2&#092;Java&#092;JRE16~1.0_0&#092;bin&#092;ssv.dll<br />O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:&#092;PROGRA~2&#092;Java&#092;JRE16~1.0_0&#092;bin&#092;ssv.dll<br />O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;ONBttnIE.dll<br />O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:&#092;PROGRA~2&#092;MICROS~2&#092;Office12&#092;REFIEBAR.DLL<br />O13 - Gopher Prefix: <br />O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - <a href="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab" target="_blank">http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab</a><br />O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;stwrt64.inf_5730ce9f&#092;AESTSr64.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;Alg.exe,-112 (ALG) - Unknown owner - C:&#092;Windows&#092;System32&#092;alg.exe (file missing)<br />O23 - Service: Apple Mobile Device - Apple Inc. - C:&#092;Program Files (x86)&#092;Common Files&#092;Apple&#092;Mobile Device Support&#092;bin&#092;AppleMobileDeviceService.exe<br />O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;aswUpdSv.exe<br />O23 - Service: avast! Antivirus - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashServ.exe<br />O23 - Service: avast! Mail Scanner - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashMaiSv.exe<br />O23 - Service: avast! Web Scanner - ALWIL Software - C:&#092;Program Files&#092;Alwil Software&#092;Avast4&#092;ashWebSv.exe<br />O23 - Service: Bonjour Service - Apple Inc. - C:&#092;Program Files (x86)&#092;Bonjour&#092;mDNSResponder.exe<br />O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;HP Quick Launch Buttons&#092;Com4QLBEx.exe<br />O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:&#092;Windows&#092;system32&#092;DFSR.exe (file missing)<br />O23 - Service: iPod Service - Apple Inc. - C:&#092;Program Files (x86)&#092;iPod&#092;bin&#092;iPodService.exe<br />O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:&#092;Windows&#092;System32&#092;msdtc.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;System32&#092;netlogon.dll,-102 (Netlogon) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: Recovery Service for Windows - Unknown owner - C:&#092;Program Files (x86)&#092;SMINST&#092;BLService.exe<br />O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:&#092;Program Files (x86)&#092;CyberLink&#092;Shared files&#092;RichVideo.exe<br />O23 - Service: @%systemroot%&#092;system32&#092;Locator.exe,-2 (RpcLocator) - Unknown owner - C:&#092;Windows&#092;system32&#092;locator.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;samsrv.dll,-1 (SamSs) - Unknown owner - C:&#092;Windows&#092;system32&#092;lsass.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;SLsvc.exe,-101 (slsvc) - Unknown owner - C:&#092;Windows&#092;system32&#092;SLsvc.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:&#092;Windows&#092;System32&#092;snmptrap.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;spoolsv.exe,-1 (Spooler) - Unknown owner - C:&#092;Windows&#092;System32&#092;spoolsv.exe (file missing)<br />O23 - Service: Audio Service (STacSV) - Unknown owner - C:&#092;Windows&#092;System32&#092;DriverStore&#092;FileRepository&#092;stwrt64.inf_5730ce9f&#092;STacSV64.exe (file missing)<br />O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Hewlett-Packard&#092;Media&#092;TV&#092;Kernel&#092;TV&#092;TVCapSvc.exe<br />O23 - Service: @%SystemRoot%&#092;system32&#092;ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:&#092;Windows&#092;system32&#092;UI0Detect.exe (file missing)<br />O23 - Service: @%SystemRoot%&#092;system32&#092;vds.exe,-100 (vds) - Unknown owner - C:&#092;Windows&#092;System32&#092;vds.exe (file missing)<br />O23 - Service: @%systemroot%&#092;system32&#092;vssvc.exe,-102 (VSS) - Unknown owner - C:&#092;Windows&#092;system32&#092;vssvc.exe (file missing)<br />O23 - Service: @%Systemroot%&#092;system32&#092;wbem&#092;wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:&#092;Windows&#092;system32&#092;wbem&#092;WmiApSrv.exe (file missing)<br />O23 - Service: @%ProgramFiles%&#092;Windows Media Player&#092;wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:&#092;Program Files (x86)&#092;Windows Media Player&#092;wmpnetwk.exe (file missing)<br /><br />--<br />End of file - 8350 bytes<br />]]></description>
		<pubDate>Sun, 13 Sep 2009 22:28:03 +0200</pubDate>
		<guid>http://www.atribune.org/forums/index.php?showtopic=5808</guid>
	</item>
</channel>
</rss>