Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: msconfig.exe has stopped working  (Read 13650 times)

0 Members and 1 Guest are viewing this topic.

Commoner

    Topic Starter


    Greenhorn

    msconfig.exe has stopped working
    « on: September 01, 2010, 07:36:17 PM »
    I've followed the steps given here

    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    with still no luck, these are my HijackThis & Malwarebytes logs

    HijackThis

    Quote
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 02:01:03, on 02/09/2010
    Platform: Windows 7  (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
    C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)
    O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [Vidalia] "C:\Program Files (x86)\Vidalia Bundle\Vidalia\vidalia.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: MySQL - Unknown owner - C:\MYSQL\bin\mysqld (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Unknown owner - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (file missing)
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 7307 bytes

    Malwarebytes

    Quote
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4518

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    02/09/2010 02:04:41
    mbam-log-2010-09-02 (02-04-41).txt

    Scan type: Quick scan
    Objects scanned: 130288
    Time elapsed: 4 minute(s), 56 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)



    Any help would be appreciated

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: msconfig.exe has stopped working
    « Reply #1 on: September 02, 2010, 06:36:57 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    SUPERAntiSpyware

    If you already have SUPERAntiSpyware be sure to check for updates before scanning!


    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to Update the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose Perform Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log somewhere you can easily find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post.
    *************************************
    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)
    O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (file missing)


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.
    **********************************
    Windows 7 on a 64 bit machine doesn't leave me with very many tools to clean your computer, but I'll try. I don't think this is a malware problem. Do you have your OS disk? These instructions are for Vista but they should apply to Windows 7

    If so,

    1/ Click the Start button.

    2/ From the Start Menu, Click All programs followed by Accessories.

    3/ In the Accessories menu, Right Click on the Command Prompt option.

    4/ From the drop down menu that appears, Click on the Run as administrator option.

    5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

    6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

    7/ A message will appear stating that the system scan will begin.

    8/ Be patient because the scan may take some time.

    9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

    10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

    11/ After the scan has completed, Close the command prompt window.
    Windows 8 and Windows 10 dual boot with two SSD's

    Commoner

      Topic Starter


      Greenhorn

      Re: msconfig.exe has stopped working
      « Reply #2 on: September 02, 2010, 08:21:49 PM »
      I've ran SUPERAntiSpyware 3 times with the same result, no problems.

      I've done sfc /scannow 3 times aswell with the same result, no problems :/

      I've really no idea what's wrong to be honest

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: msconfig.exe has stopped working
      « Reply #3 on: September 04, 2010, 01:24:35 PM »
      Download OTL  to your Desktop
      • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
      • Under the Custom Scan box paste this in
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      %SYSTEMDRIVE%\*.exe
      %systemroot%\*. /mp /s
      c:\$recycle.bin\*.* /s
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      nvstor32.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      explorer.exe
      svchost.exe
      userinit.exe
      qmgr.dll
      ws2_32.dll
      proquota.exe
      imm32.dll
      kernel32.dll
      ndis.sys
      autochk.exe
      spoolsv.exe
      xmlprov.dll
      ntmssvc.dll
      mswsock.dll
      Beep.SYS
      ntfs.sys
      termsrv.dll
      sfcfiles.dll
      st3shark.sys
      ahcix86.sys
      srsvc.dll
      nvrd32.sys
      /md5stop
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles

      • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
        • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
        • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
      Windows 8 and Windows 10 dual boot with two SSD's

      Commoner

        Topic Starter


        Greenhorn

        Re: msconfig.exe has stopped working
        « Reply #4 on: September 04, 2010, 06:28:12 PM »
        OTL.txt
        Quote
        OTL logfile created on: 05/09/2010 01:04:00 - Run 1
        OTL by OldTimer - Version 3.2.11.0     Folder = C:\Users\xxxxx\Desktop
        64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
        Internet Explorer (Version = 8.0.7600.16385)
        Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
         
        3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 77.00% Memory free
        7.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
        Paging file location(s): ?:\pagefile.sys [binary data]
         
        %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
        Drive C: | 37.80 Gb Total Space | 9.49 Gb Free Space | 25.10% Space Free | Partition Type: NTFS
        D: Drive not present or media not loaded
        E: Drive not present or media not loaded
        F: Drive not present or media not loaded
        G: Drive not present or media not loaded
        H: Drive not present or media not loaded
        I: Drive not present or media not loaded
        Drive K: | 152.67 Gb Total Space | 95.09 Gb Free Space | 62.29% Space Free | Partition Type: NTFS
         
        Computer Name: xxxxxxxxxxxx
        Current User Name: xxxxxxxxx
        Logged in as Administrator.
         
        Current Boot Mode: Normal
        Scan Mode: Current user
        Include 64bit Scans
        Company Name Whitelist: On
        Skip Microsoft Files: On
        File Age = 90 Days
        Output = Standard
        Quick Scan
         
        ========== Processes (SafeList) ==========
         
        PRC - [2010/09/05 01:02:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\xxxxxx\Desktop\OTL.exe
        PRC - [2010/07/24 08:51:16 | 004,334,272 | ---- | M] (Almico Software (www.almico.com)) -- C:\Program Files (x86)\SpeedFan\speedfan.exe
        PRC - [2010/07/09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
        PRC - [2009/12/23 15:24:36 | 000,415,232 | ---- | M] () -- C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
        PRC - [2009/12/23 10:36:50 | 000,361,984 | ---- | M] () -- C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
        PRC - [2009/04/30 11:23:26 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
        PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
        PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
         
         
        ========== Modules (SafeList) ==========
         
        MOD - [2010/09/05 01:02:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\xxxxxxx\Desktop\OTL.exe
        MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
        MOD - [2009/07/14 02:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
         
         
        ========== Win32 Services (SafeList) ==========
         
        SRV:64bit: - [2010/06/29 18:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
        SRV:64bit: - [2009/07/14 02:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
        SRV:64bit: - [2009/07/14 02:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
        SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
        SRV:64bit: - [2009/07/14 02:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
        SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
        SRV - [2010/07/09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
        SRV - [2010/06/04 19:23:52 | 007,653,376 | ---- | M] () [Auto | Running] -- C:\MYSQL\bin\mysqld.exe -- (MySQL)
        SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
        SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
        SRV - [2009/04/30 11:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
        SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
         
         
        ========== Driver Services (SafeList) ==========
         
        DRV:64bit: - [2010/08/28 07:00:34 | 000,035,200 | ---- | M] (SteelSeries Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SAlpham64.sys -- (SAlphamHid)
        DRV:64bit: - [2010/05/23 20:56:20 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
        DRV:64bit: - [2010/04/19 20:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
        DRV:64bit: - [2010/02/17 19:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
        DRV:64bit: - [2010/02/17 19:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
        DRV:64bit: - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
        DRV:64bit: - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
        DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
        DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
        DRV:64bit: - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
        DRV:64bit: - [2009/07/14 02:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
        DRV:64bit: - [2009/07/14 02:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
        DRV:64bit: - [2009/07/14 02:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
        DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
        DRV:64bit: - [2009/07/14 01:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
        DRV:64bit: - [2009/07/14 00:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
        DRV:64bit: - [2009/07/14 00:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
        DRV:64bit: - [2009/07/14 00:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
        DRV:64bit: - [2009/06/10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
        DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
        DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
        DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
        DRV:64bit: - [2009/06/10 21:34:21 | 000,034,304 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\l260x64.sys -- (Atc002)
        DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
        DRV:64bit: - [2008/10/21 09:22:44 | 000,145,960 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
        DRV:64bit: - [2008/10/21 09:22:44 | 000,128,552 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017obex.sys -- (s0017obex)
        DRV:64bit: - [2008/10/21 09:22:44 | 000,034,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
        DRV:64bit: - [2008/10/21 09:22:42 | 000,152,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017mdm.sys -- (s0017mdm)
        DRV:64bit: - [2008/10/21 09:22:42 | 000,133,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
        DRV:64bit: - [2008/10/21 09:22:42 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017mdfl.sys -- (s0017mdfl)
        DRV:64bit: - [2008/10/21 09:22:40 | 000,113,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
        DRV:64bit: - [2008/09/18 10:50:38 | 000,012,800 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Mo3Fltr.sys -- (Mo3Fltr)
        DRV:64bit: - [2007/02/26 18:15:20 | 000,092,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
        DRV:64bit: - [2005/03/29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
        DRV - [2007/02/07 19:27:46 | 000,014,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
         
         
        ========== Standard Registry (SafeList) ==========
         
         
        ========== Internet Explorer ==========
         
        IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
        IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - Reg Error: Key error. File not found
         
        IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
        IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
        IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
        IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B6 F3 92 AA 4A F8 CA 01  [binary data]
        IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
         
        ========== FireFox ==========
         
        FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
        FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
        FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
        FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
         
        FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/30 03:35:02 | 000,000,000 | ---D | M]
        FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/30 03:35:02 | 000,000,000 | ---D | M]
         
        [2010/05/20 19:12:52 | 000,000,000 | ---D | M] -- C:\Users\xxxxxx\AppData\Roaming\Mozilla\Extensions
        [2010/09/04 19:32:38 | 000,000,000 | ---D | M] -- C:\Users\xxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions
        [2010/06/25 03:16:16 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\xxxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
        [2010/07/22 15:48:15 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\xxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
        [2010/07/22 15:45:19 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
        [2010/08/25 16:52:30 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
        [2010/07/10 15:34:01 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
        [2010/08/25 16:53:49 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
        [2010/07/25 15:59:38 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\k8bqwplj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
        [2010/09/04 19:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
        [2010/08/13 20:39:01 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
        [2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
        [2010/01/16 01:55:13 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
        [2010/01/16 01:55:13 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
        [2010/01/16 01:55:13 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
        [2010/01/16 01:55:13 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
         
        O1 HOSTS File: ([2010/08/31 22:34:37 | 000,416,980 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
        O1 - Hosts: 127.0.0.1   www.007guard.com
        O1 - Hosts: 127.0.0.1   007guard.com
        O1 - Hosts: 127.0.0.1   008i.com
        O1 - Hosts: 127.0.0.1   www.008k.com
        O1 - Hosts: 127.0.0.1   008k.com
        O1 - Hosts: 127.0.0.1   www.00hq.com
        O1 - Hosts: 127.0.0.1   00hq.com
        O1 - Hosts: 127.0.0.1   010402.com
        O1 - Hosts: 127.0.0.1   www.032439.com
        O1 - Hosts: 127.0.0.1   032439.com
        O1 - Hosts: 127.0.0.1   www.0scan.com
        O1 - Hosts: 127.0.0.1   0scan.com
        O1 - Hosts: 127.0.0.1   1000gratisproben.com
        O1 - Hosts: 127.0.0.1   www.1000gratisproben.com
        O1 - Hosts: 127.0.0.1   1001namen.com
        O1 - Hosts: 127.0.0.1   www.1001namen.com
        O1 - Hosts: 127.0.0.1   100888290cs.com
        O1 - Hosts: 127.0.0.1   www.100888290cs.com
        O1 - Hosts: 127.0.0.1   www.10sek.com
        O1 - Hosts: 127.0.0.1   www.1-2005-search.com
        O1 - Hosts: 127.0.0.1   1-2005-search.com
        O1 - Hosts: 14389 more lines...
        O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
        O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
        O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
        O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
        O4 - HKLM..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program Files (x86)\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe ()
        O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWow64\StikyNot.exe File not found
        O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
        O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
        O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
        O13 - gopher Prefix: missing
        O13 - gopher Prefix: missing
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
        O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
        O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
        O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
        O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
        O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
        O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
        O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
        O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
        O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
        O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
        O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
        O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
        O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
        O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
        O32 - HKLM CDRom: AutoRun - 1
        O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
        O35:64bit: - HKLM\..comfile [open] -- "%1" %*
        O35:64bit: - HKLM\..exefile [open] -- "%1" %*
        O35 - HKLM\..comfile [open] -- "%1" %*
        O35 - HKLM\..exefile [open] -- "%1" %*
        O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
        O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
        O37 - HKLM\...com [@ = comfile] -- "%1" %*
        O37 - HKLM\...exe [@ = exefile] -- "%1" %*
         
        NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
         
        MsConfig:64bit - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
        MsConfig:64bit - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
        MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
        MsConfig:64bit - StartUpReg: Sony Ericsson PC Suite - hkey= - key= - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
        MsConfig:64bit - StartUpReg: XboxStat - hkey= - key= - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
        MsConfig:64bit - State: "startup" - Reg Error: Key error.
         
        SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
        SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
        SafeBootMin:64bit: Base - Driver Group
        SafeBootMin:64bit: Boot Bus Extender - Driver Group
        SafeBootMin:64bit: Boot file system - Driver Group
        SafeBootMin:64bit: File system - Driver Group
        SafeBootMin:64bit: Filter - Driver Group
        SafeBootMin:64bit: HelpSvc - Service
        SafeBootMin:64bit: PCI Configuration - Driver Group
        SafeBootMin:64bit: PNP Filter - Driver Group
        SafeBootMin:64bit: Primary disk - Driver Group
        SafeBootMin:64bit: sacsvr - Service
        SafeBootMin:64bit: SCSI Class - Driver Group
        SafeBootMin:64bit: System Bus Extender - Driver Group
        SafeBootMin:64bit: vmms - Service
        SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
        SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
        SafeBootMin: Base - Driver Group
        SafeBootMin: Boot Bus Extender - Driver Group
        SafeBootMin: Boot file system - Driver Group
        SafeBootMin: File system - Driver Group
        SafeBootMin: Filter - Driver Group
        SafeBootMin: HelpSvc - Service
        SafeBootMin: PCI Configuration - Driver Group
        SafeBootMin: PNP Filter - Driver Group
        SafeBootMin: Primary disk - Driver Group
        SafeBootMin: sacsvr - Service
        SafeBootMin: SCSI Class - Driver Group
        SafeBootMin: System Bus Extender - Driver Group
        SafeBootMin: vmms - Service
        SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
         
        SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
        SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
        SafeBootNet:64bit: Base - Driver Group
        SafeBootNet:64bit: Boot Bus Extender - Driver Group
        SafeBootNet:64bit: Boot file system - Driver Group
        SafeBootNet:64bit: File system - Driver Group
        SafeBootNet:64bit: Filter - Driver Group
        SafeBootNet:64bit: HelpSvc - Service
        SafeBootNet:64bit: Messenger - Service
        SafeBootNet:64bit: NDIS Wrapper - Driver Group
        SafeBootNet:64bit: NetBIOSGroup - Driver Group
        SafeBootNet:64bit: NetDDEGroup - Driver Group
        SafeBootNet:64bit: Network - Driver Group
        SafeBootNet:64bit: NetworkProvider - Driver Group
        SafeBootNet:64bit: PCI Configuration - Driver Group
        SafeBootNet:64bit: PNP Filter - Driver Group
        SafeBootNet:64bit: PNP_TDI - Driver Group
        SafeBootNet:64bit: Primary disk - Driver Group
        SafeBootNet:64bit: rdsessmgr - Service
        SafeBootNet:64bit: sacsvr - Service
        SafeBootNet:64bit: SCSI Class - Driver Group
        SafeBootNet:64bit: Streams Drivers - Driver Group
        SafeBootNet:64bit: System Bus Extender - Driver Group
        SafeBootNet:64bit: TDI - Driver Group
        SafeBootNet:64bit: vmms - Service
        SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
        SafeBootNet:64bit: WudfUsbccidDriver - Driver
        SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
        SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
        SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
        SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
        SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
        SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
        SafeBootNet: Base - Driver Group
        SafeBootNet: Boot Bus Extender - Driver Group
        SafeBootNet: Boot file system - Driver Group
        SafeBootNet: File system - Driver Group
        SafeBootNet: Filter - Driver Group
        SafeBootNet: HelpSvc - Service
        SafeBootNet: Messenger - Service
        SafeBootNet: NDIS Wrapper - Driver Group
        SafeBootNet: NetBIOSGroup - Driver Group
        SafeBootNet: NetDDEGroup - Driver Group
        SafeBootNet: Network - Driver Group
        SafeBootNet: NetworkProvider - Driver Group
        SafeBootNet: PCI Configuration - Driver Group
        SafeBootNet: PNP Filter - Driver Group
        SafeBootNet: PNP_TDI - Driver Group
        SafeBootNet: Primary disk - Driver Group
        SafeBootNet: rdsessmgr - Service
        SafeBootNet: sacsvr - Service
        SafeBootNet: SCSI Class - Driver Group
        SafeBootNet: Streams Drivers - Driver Group
        SafeBootNet: System Bus Extender - Driver Group
        SafeBootNet: TDI - Driver Group
        SafeBootNet: vmms - Service
        SafeBootNet: WudfUsbccidDriver - Driver
        SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
        SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
        SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
        SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
        SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
        SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
         
        ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
        ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
        ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
        ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
        ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
        ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
        ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
        ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
        ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
        ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
        ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
        ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
        ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
        ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
        ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
        ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
        ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
        ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
        ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
        ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
        ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
        ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
        ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
        ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
        ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
        ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
        ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
        ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
        ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
        ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
        ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
        ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
        ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
        ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
        ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
        ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
        ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
        ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
        ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
        ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
        ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
        ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
        ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
        ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
        ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
        ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
        ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
        ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
        ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
        ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
         
        Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
        Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
        Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
        Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
        Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
        Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
        Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
        Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
        Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
         
        ========== Files/Folders - Created Within 90 Days ==========
         
        [2010/09/05 01:02:43 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\xxxxx\Desktop\OTL.exe
        [2010/09/02 03:40:11 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\Registry Backups
        [2010/09/02 03:26:07 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\SteelSeries
        [2010/09/02 03:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SteelSeries
        [2010/09/02 03:25:38 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\InstallShield
        [2010/09/02 01:55:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
        [2010/09/01 02:42:10 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\Malwarebytes
        [2010/09/01 02:42:02 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
        [2010/09/01 02:42:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
        [2010/09/01 02:42:00 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
        [2010/09/01 02:42:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
        [2010/09/01 02:37:00 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\SUPERAntiSpyware.com
        [2010/09/01 02:37:00 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
        [2010/09/01 02:36:56 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
        [2010/09/01 02:36:55 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
        [2010/09/01 02:34:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
        [2010/08/31 22:27:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
        [2010/08/31 22:27:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
        [2010/08/31 18:17:58 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Local\MediaMonkey
        [2010/08/31 18:17:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MediaMonkey
        [2010/08/30 03:36:03 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
        [2010/08/30 03:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
        [2010/08/30 03:34:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
        [2010/08/30 03:34:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
        [2010/08/30 03:10:06 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\iPodder
        [2010/08/30 03:09:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Juice
        [2010/08/29 15:37:48 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\Red Kawa
        [2010/08/29 03:33:04 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Local\Geckofx
        [2010/08/29 03:32:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Common Share
        [2010/08/29 03:32:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Red Kawa
        [2010/08/28 23:07:10 | 000,000,000 | ---D | C] -- C:\ProgramData\eMule
        [2010/08/28 23:07:00 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Local\eMule
        [2010/08/28 07:00:34 | 000,035,200 | ---- | C] (SteelSeries Corporation) -- C:\Windows\SysNative\drivers\SAlpham64.sys
        [2010/08/27 14:45:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
        [2010/08/26 22:06:36 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\My Received Files
        [2010/08/24 16:49:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedFan
        [2010/08/22 12:54:31 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Desktop\Thingys
        [2010/08/17 19:03:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
        [2010/08/17 19:03:52 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
        [2010/08/17 19:03:47 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
        [2010/08/17 19:03:10 | 000,065,128 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
        [2010/08/17 19:03:10 | 000,056,936 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
        [2010/08/13 20:54:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
        [2010/08/13 03:32:00 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\Anime Gif's
        [2010/08/06 01:13:57 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\LolClient
        [2010/08/06 00:26:36 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Local\Adobe
        [2010/08/06 00:25:07 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
        [2010/08/06 00:25:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
        [2010/08/04 00:52:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
        [2010/08/04 00:52:34 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\Guild Wars
        [2010/07/22 15:53:58 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\DVDVideoSoft
        [2010/07/22 15:53:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
        [2010/07/22 15:53:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
        [2010/07/22 15:49:04 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\dwhelper
        [2010/07/18 09:51:36 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\Windows\SysWow64\lameACM.acm
        [2010/07/18 09:51:36 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\SysWow64\ac3acm.acm
        [2010/07/18 09:51:35 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\Windows\SysWow64\yv12vfw.dll
        [2010/07/18 09:51:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-Lite Codec Pack
        [2010/07/14 03:04:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindSolutions
        [2010/07/14 03:04:01 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\WindSolutions
        [2010/07/14 03:04:01 | 000,000,000 | ---D | C] -- C:\ProgramData\WindSolutions
        [2010/06/30 09:38:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\File Shredder
        [2010/06/29 00:03:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Seagate
        [2010/06/29 00:03:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
        [2010/06/29 00:02:02 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\1
        [2010/06/24 04:09:25 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\Documents\Cooking
        [2010/06/20 09:40:00 | 000,000,000 | ---D | C] -- C:\ProgramData\MySQL
        [2010/06/20 09:11:27 | 000,000,000 | ---D | C] -- C:\MySQL
        [2010/06/20 07:30:04 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
        [2010/06/20 07:25:07 | 000,000,000 | ---D | C] -- C:\Users\xxxxx\AppData\Roaming\SQLyog
        [2010/06/20 07:24:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SQLyog Community
         
        ========== Files - Modified Within 90 Days ==========
         
        [2010/09/05 01:04:54 | 006,291,456 | -HS- | M] () -- C:\Users\xxxxx\NTUSER.DAT
        [2010/09/05 01:02:48 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\xxxxx\Desktop\OTL.exe
        [2010/09/05 00:07:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
        [2010/09/04 19:27:03 | 000,020,624 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
        [2010/09/04 19:27:03 | 000,020,624 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
        [2010/09/04 19:26:18 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
        [2010/09/04 19:26:18 | 000,628,024 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
        [2010/09/04 19:26:18 | 000,110,208 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
        [2010/09/04 19:21:58 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
        [2010/09/04 19:21:49 | 2717,310,976 | -HS- | M] () -- C:\hiberfil.sys
        [2010/09/04 01:11:24 | 005,835,046 | -H-- | M] () -- C:\Users\xxxxx\AppData\Local\IconCache.db
        [2010/09/02 02:51:08 | 000,038,400 | ---- | M] () -- C:\Users\xxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
        [2010/08/31 22:34:37 | 000,416,980 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
        [2010/08/31 22:27:10 | 000,001,282 | ---- | M] () -- C:\Users\xxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
        [2010/08/29 03:18:51 | 000,000,037 | ---- | M] () -- C:\Windows\avitoiPodconverter.ini
        [2010/08/29 03:18:40 | 000,000,001 | ---- | M] () -- C:\Windows\SysWow64\SysAVItoiPod.dat
        [2010/08/29 00:13:12 | 000,000,967 | ---- | M] () -- C:\Users\xxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
        [2010/08/28 07:00:34 | 000,035,200 | ---- | M] (SteelSeries Corporation) -- C:\Windows\SysNative\drivers\SAlpham64.sys
        [2010/08/24 16:49:46 | 000,000,045 | ---- | M] () -- C:\Windows\SysWow64\initdebug.nfo
        [2010/08/16 14:36:30 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
        [2010/07/14 09:00:00 | 000,108,032 | ---- | M] () -- C:\Windows\SysWow64\ff_vfw.dll
        [2010/07/14 09:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini
        [2010/07/09 23:38:00 | 000,065,128 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
        [2010/07/09 23:38:00 | 000,056,936 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
        [2010/07/09 23:38:00 | 000,012,264 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
        [2010/06/20 09:40:46 | 000,007,607 | ---- | M] () -- C:\Users\xxxxx\AppData\Local\Resmon.ResmonCfg
        [2010/06/20 07:24:23 | 000,001,122 | ---- | M] () -- C:\Users\xxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\SQLyog Community.lnk
        [2010/06/08 17:10:50 | 000,790,528 | ---- | M] () -- C:\Windows\SysWow64\xvidcore.dll
        [2010/06/08 17:10:50 | 000,134,144 | ---- | M] () -- C:\Windows\SysWow64\xvidvfw.dll
         
        ========== Files Created - No Company Name ==========
         
        [2010/08/31 22:27:10 | 000,001,282 | ---- | C] () -- C:\Users\xxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
        [2010/08/29 03:18:44 | 000,000,037 | ---- | C] () -- C:\Windows\avitoiPodconverter.ini
        [2010/08/29 03:18:39 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SysAVItoiPod.dat
        [2010/08/24 16:49:46 | 000,000,045 | ---- | C] () -- C:\Windows\SysWow64\initdebug.nfo
        [2010/07/18 09:51:37 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
        [2010/07/18 09:51:36 | 000,000,414 | ---- | C] () -- C:\Windows\SysWow64\lame_acm.xml
        [2010/07/18 09:51:36 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
        [2010/07/18 09:51:35 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
        [2010/07/18 09:51:35 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
        [2010/07/18 09:51:35 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
        [2010/07/18 09:51:35 | 000,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
        [2010/07/14 03:05:45 | 000,038,400 | ---- | C] () -- C:\Users\xxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
        [2010/06/20 08:19:42 | 000,007,607 | ---- | C] () -- C:\Users\xxxxx\AppData\Local\Resmon.ResmonCfg
        [2010/06/20 07:24:23 | 000,001,122 | ---- | C] () -- C:\Users\xxxxx\Application Data\Microsoft\Internet Explorer\Quick Launch\SQLyog Community.lnk
        [2010/06/03 10:52:15 | 000,000,000 | ---- | C] () -- C:\ProgramData\driverinfo.txt
        [2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
        [2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
         
        ========== LOP Check ==========
         
        [2010/05/25 11:02:58 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\DAEMON Tools Lite
        [2010/05/23 20:37:58 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\DAEMON Tools Pro
        [2010/08/30 03:10:06 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\iPodder
        [2010/08/06 01:13:57 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\LolClient
        [2010/08/29 15:37:48 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\Red Kawa
        [2010/05/23 00:24:23 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\Sony
        [2010/05/23 00:21:22 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\Sony Setup
        [2010/06/20 10:14:47 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\SQLyog
        [2010/09/02 03:26:07 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\SteelSeries
        [2010/05/21 04:40:12 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\SystemRequirementsLab
        [2010/08/29 21:51:22 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\uTorrent
        [2010/08/30 02:52:52 | 000,000,000 | ---D | M] -- C:\Users\xxxxx\AppData\Roaming\WindSolutions
        [2010/08/12 04:58:42 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
         
        ========== Purity Check ==========
         
         
         
        ========== Custom Scans ==========
         
         
        < %SYSTEMDRIVE%\*.exe >
         
        < %systemroot%\*. /mp /s >
         
        < c:\$recycle.bin\*.* /s >
        [2010/08/30 03:17:30 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-20\desktop.ini
        [2010/08/30 04:10:50 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4174808901-4266007266-811681905-1001\$I0JC9DH.jpg
        [2010/08/31 23:44:57 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-4174808901-4266007266-811681905-1001\$IO5GBKK.lnk
        [2010/05/20 19:10:48 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-4174808901-4266007266-811681905-1001\desktop.ini
         
        < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
         
         
        < MD5 for: AGP440.SYS  >
        [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
        [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
         
        < MD5 for: ATAPI.SYS  >
        [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
        [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
         
        < MD5 for: AUTOCHK.EXE  >
        [2009/07/14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
        [2009/07/14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
        [2009/07/14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
        [2009/07/14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
         
        < MD5 for: BEEP.SYS  >
        [2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys
         
        < MD5 for: CNGAUDIT.DLL  >
        [2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
        [2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
        [2009/07/14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
        [2009/07/14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
         
        < MD5 for: EXPLORER.EXE  >
        [2009/07/14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
        [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
        [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
        [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
        [2009/08/03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
        [2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
        [2009/10/31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
        [2009/08/03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
        [2009/10/31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
        [2009/08/03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
        [2009/07/14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
        [2009/10/31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
        [2009/08/03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
         
        < MD5 for: IASTORV.SYS  >
        [2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
        [2009/07/14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
         
        < MD5 for: IMM32.DLL  >
        [2009/07/14 02:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\SysWOW64\imm32.dll
        [2009/07/14 02:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\SysWOW64\imm32.dll
        [2009/07/14 02:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\winsxs\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7600.16385_none_c29fba0fc87cc5a4\imm32.dll
        [2009/07/14 02:41:09 | 000,167,424 | ---- | M] (Microsoft Corporation) MD5=AA2C08CE85653B1A0D2E4AB407FA176C -- C:\Windows\winsxs\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7600.16385_none_b84b0fbd941c03a9\imm32.dll
         
        < MD5 for: KERNEL32.DLL  >
        [2009/07/14 02:41:13 | 001,162,240 | ---- | M] (Microsoft Corporation) MD5=5B4B379AD10DEDA4EDA01B8C6961B193 -- C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.16385_none_efb2d6e86ffc8f55\kernel32.dll
        [2009/07/14 02:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\SysWOW64\kernel32.dll
        [2009/07/14 02:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\SysWOW64\kernel32.dll
        [2009/07/14 02:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.16385_none_fa07813aa45d5150\kernel32.dll
         
        < MD5 for: MSWSOCK.DLL  >
        [2009/07/14 02:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\SysWOW64\mswsock.dll
        [2009/07/14 02:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\SysWOW64\mswsock.dll
        [2009/07/14 02:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_b829ad298e9f53ff\mswsock.dll
        [2009/07/14 02:41:34 | 000,320,000 | ---- | M] (Microsoft Corporation) MD5=FC76FE3C1E1FDB761244D4F74EF560FD -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_144848ad46fcc535\mswsock.dll
         
        < MD5 for: NDIS.SYS  >
        [2009/07/14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys
         
        < MD5 for: NETLOGON.DLL  >
        [2009/07/14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
        [2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
        [2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
        [2009/07/14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
         
        < MD5 for: NTFS.SYS  >
        [2009/07/14 02:48:27 | 001,659,984 | ---- | M] (Microsoft Corporation) MD5=356698A13C4630D5B31C37378D469196 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7600.16385_none_02661b64369ca03a\ntfs.sys
         
        < MD5 for: NVSTOR.SYS  >
        [2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
        [2009/07/14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
         
        < MD5 for: PROQUOTA.EXE  >
        [2009/07/14 02:39:28 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=19117589BA265AAF89BEBE1E9040000C -- C:\Windows\winsxs\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.1.7600.16385_none_83bbe97eac162e90\proquota.exe
        [2009/07/14 02:14:29 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=8CDF71E78469BE54C29C1AD2FC8DE611 -- C:\Windows\SysWOW64\proquota.exe
        [2009/07/14 02:14:29 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=8CDF71E78469BE54C29C1AD2FC8DE611 -- C:\Windows\SysWOW64\proquota.exe
        [2009/07/14 02:14:29 | 000,028,160 | ---- | M] (Microsoft Corporation) MD5=8CDF71E78469BE54C29C1AD2FC8DE611 -- C:\Windows\winsxs\x86_microsoft-windows-proquota_31bf3856ad364e35_6.1.7600.16385_none_279d4dfaf3b8bd5a\proquota.exe
         
        < MD5 for: QMGR.DLL  >
        [2009/07/14 02:41:53 | 000,848,384 | ---- | M] (Microsoft Corporation) MD5=7F0C323FE3DA28AA4AA1BDA3F575707F -- C:\Windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7600.16385_none_7f85b69413231233\qmgr.dll
         
        < MD5 for: SCECLI.DLL  >
        [2009/07/14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation)

        Commoner

          Topic Starter


          Greenhorn

          Re: msconfig.exe has stopped working
          « Reply #5 on: September 04, 2010, 06:29:22 PM »
          Extras.txt
          Quote
          OTL Extras logfile created on: 05/09/2010 01:04:00 - Run 1
          OTL by OldTimer - Version 3.2.11.0     Folder = C:\Users\xxxxx\Desktop
          64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
          Internet Explorer (Version = 8.0.7600.16385)
          Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
           
          3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 77.00% Memory free
          7.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
          Paging file location(s): ?:\pagefile.sys [binary data]
           
          %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
          Drive C: | 37.80 Gb Total Space | 9.49 Gb Free Space | 25.10% Space Free | Partition Type: NTFS
          D: Drive not present or media not loaded
          E: Drive not present or media not loaded
          F: Drive not present or media not loaded
          G: Drive not present or media not loaded
          H: Drive not present or media not loaded
          I: Drive not present or media not loaded
          Drive K: | 152.67 Gb Total Space | 95.09 Gb Free Space | 62.29% Space Free | Partition Type: NTFS
           
          Computer Name: xxxxx-PC
          Current User Name: xxxxx
          Logged in as Administrator.
           
          Current Boot Mode: Normal
          Scan Mode: Current user
          Include 64bit Scans
          Company Name Whitelist: On
          Skip Microsoft Files: On
          File Age = 90 Days
          Output = Standard
          Quick Scan
           
          ========== Extra Registry (SafeList) ==========
           
           
          ========== File Associations ==========
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
           
          [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
          .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
           
          [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
          .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
           
          ========== Shell Spawning ==========
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
          batfile [open] -- "%1" %* File not found
          cmdfile [open] -- "%1" %* File not found
          comfile [open] -- "%1" %* File not found
          exefile [open] -- "%1" %* File not found
          helpfile [open] -- Reg Error: Key error.
          htmlfile [edit] -- Reg Error: Key error.
          htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
          inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
          InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
          piffile [open] -- "%1" %* File not found
          regfile [merge] -- Reg Error: Key error.
          scrfile [config] -- "%1" File not found
          scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
          scrfile [open] -- "%1" /S File not found
          txtfile [edit] -- Reg Error: Key error.
          Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
          Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
          Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
          Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
          Folder [explore] -- Reg Error: Value error.
          Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
           
          [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
          batfile [open] -- "%1" %*
          cmdfile [open] -- "%1" %*
          comfile [open] -- "%1" %*
          cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
          exefile [open] -- "%1" %*
          helpfile [open] -- Reg Error: Key error.
          htmlfile [edit] -- Reg Error: Key error.
          htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
          inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
          InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
          piffile [open] -- "%1" %*
          regfile [merge] -- Reg Error: Key error.
          scrfile [config] -- "%1"
          scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
          scrfile [open] -- "%1" /S
          txtfile [edit] -- Reg Error: Key error.
          Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
          Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
          Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
          Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
          Folder [explore] -- Reg Error: Value error.
          Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
           
          ========== Security Center Settings ==========
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
          "cval" = 1
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
          "VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
          "AntiVirusOverride" = 0
          "AntiSpywareOverride" = 0
          "FirewallOverride" = 0
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
           
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
           
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
           
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
          "DisableNotifications" = 0
          "EnableFirewall" = 1
           
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
          "DisableNotifications" = 0
          "EnableFirewall" = 1
           
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
          "DisableNotifications" = 0
          "EnableFirewall" = 1
           
          ========== Authorized Applications List ==========
           
           
          ========== HKEY_LOCAL_MACHINE Uninstall List ==========
           
          64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
          "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
          "{8A837C47-2B21-4FDF-8370-41A1EB6A26E8}" = Microsoft Xbox 360 Accessories 1.1
          "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
          "{CAB5FD57-A8FF-4842-A060-CA04892848A5}" = MySQL Server 5.1
          "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
          "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
          "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
          "NVIDIA Display Control Panel" = NVIDIA Display Control Panel
          "NVIDIA Drivers" = NVIDIA Drivers
          "WinRAR archiver" = WinRAR archiver
           
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
          "{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
          "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
          "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
          "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 21
          "{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.011.00
          "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
          "{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
          "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
          "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
          "{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
          "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
          "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
          "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
          "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
          "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
          "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
          "{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
          "{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
          "{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
          "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
          "{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
          "{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
          "{C9DF0468-5F31-4799-B4FE-CBAD37FFB8DE}" = World of Warcraft MMO Gaming Mouse
          "{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
          "{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
          "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
          "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
          "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
          "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
          "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
          "CCleaner" = CCleaner
          "DivX Setup.divx.com" = DivX Setup
          "File Shredder_is1" = File Shredder 2.0
          "Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.6
          "Guild Wars" = Guild Wars
          "JDownloader" = JDownloader
          "KLiteCodecPack_is1" = K-Lite Codec Pack 6.2.0 (Full)
          "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
          "Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
          "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
          "SpeedFan" = SpeedFan (remove only)
          "SQLyog Community" = SQLyog Community 8.5
          "SystemRequirementsLab" = System Requirements Lab
          "uTorrent" = µTorrent
          "Videora iPod Converter" = Videora iPod Converter 5.04
          "WinLiveSuite_Wave3" = Windows Live Essentials
          "Winrar 3.93" = Winrar 3.93
          "World of Warcraft" = World of Warcraft
          "World of Warcraft Beta" = World of Warcraft Beta
           
          ========== HKEY_CURRENT_USER Uninstall List ==========
           
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
          "CopyTrans Suite" = CopyTrans Suite Remove Only
           
          ========== Last 10 Event Log Errors ==========
           
          [ Application Events ]
          Error - 31/08/2010 21:45:42 | Computer Name = xxxxx-PC | Source = Application Error | ID = 1000
          Description = Faulting application name: msconfig.exe, version: 0.0.0.0, time stamp:
           0x4a5bc3eb  Faulting module name: ntdll.dll, version: 6.1.7600.16559, time stamp:
           0x4ba9b802  Exception code: 0xc0000005  Fault offset: 0x000000000003d9e7  Faulting process
           id: 0xb38  Faulting application start time: 0x01cb4977606d8f23  Faulting application
           path: C:\Windows\system32\msconfig.exe  Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
          Report
           Id: a0a6530e-b56a-11df-a907-001d606f7d63
           
          Error - 01/09/2010 17:03:09 | Computer Name = xxxxx-PC | Source = Application Error | ID = 1000
          Description = Faulting application name: msconfig.exe, version: 0.0.0.0, time stamp:
           0x4a5bc3eb  Faulting module name: ntdll.dll, version: 6.1.7600.16559, time stamp:
           0x4ba9b802  Exception code: 0xc0000005  Fault offset: 0x000000000003d9e7  Faulting process
           id: 0xd5c  Faulting application start time: 0x01cb4a1913ef90c9  Faulting application
           path: C:\Windows\system32\msconfig.exe  Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
          Report
           Id: 52914965-b60c-11df-9afb-001d606f7d63
           
          Error - 01/09/2010 19:00:38 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842787
          Description = Activation context generation failed for "c:\program files (x86)\windows
           live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
           files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8.  Component identity
           found in manifest does not match the identity of the component requested.  Reference
           is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".  Definition
           is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Please use
           sxstrace.exe for detailed diagnosis.
           
          Error - 01/09/2010 19:00:45 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842815
          Description = Activation context generation failed for "c:\program files (x86)\spybot
           - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
          files (x86)\spybot - search & destroy\DelZip179.dll" on line 8.  The value "*" of
          attribute "language" in element "assemblyIdentity" is invalid.
           
          Error - 01/09/2010 21:40:15 | Computer Name = xxxxx-PC | Source = Application Error | ID = 1000
          Description = Faulting application name: MEDIAM~1.EXE, version: 3.2.2.1300, time
           stamp: 0x2a425e19  Faulting module name: QuickTime.qts_unloaded, version: 0.0.0.0,
           time stamp: 0x4ba307c0  Exception code: 0xc0000005  Fault offset: 0x6dc1bb69  Faulting
           process id: 0xc4c  Faulting application start time: 0x01cb4a3fc3a4f69b  Faulting application
           path: C:\PROGRA~2\MEDIAM~1\MEDIAM~1.EXE  Faulting module path: QuickTime.qts  Report
           Id: 08ab6372-b633-11df-9afb-001d606f7d63
           
          Error - 01/09/2010 22:41:09 | Computer Name = xxxxx-PC | Source = Application Error | ID = 1000
          Description = Faulting application name: msconfig.exe, version: 0.0.0.0, time stamp:
           0x4a5bc3eb  Faulting module name: ntdll.dll, version: 6.1.7600.16559, time stamp:
           0x4ba9b802  Exception code: 0xc0000005  Fault offset: 0x000000000003d9e7  Faulting process
           id: 0x274  Faulting application start time: 0x01cb4a484aaa9509  Faulting application
           path: C:\Windows\system32\msconfig.exe  Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
          Report
           Id: 8a333320-b63b-11df-a92c-001d606f7d63
           
          Error - 03/09/2010 12:53:10 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842787
          Description = Activation context generation failed for "c:\program files (x86)\windows
           live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
           files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8.  Component identity
           found in manifest does not match the identity of the component requested.  Reference
           is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".  Definition
           is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Please use
           sxstrace.exe for detailed diagnosis.
           
          Error - 03/09/2010 12:53:17 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842815
          Description = Activation context generation failed for "c:\program files (x86)\spybot
           - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
          files (x86)\spybot - search & destroy\DelZip179.dll" on line 8.  The value "*" of
          attribute "language" in element "assemblyIdentity" is invalid.
           
          Error - 04/09/2010 17:25:21 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842787
          Description = Activation context generation failed for "c:\program files (x86)\windows
           live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
           files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8.  Component identity
           found in manifest does not match the identity of the component requested.  Reference
           is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".  Definition
           is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Please use
           sxstrace.exe for detailed diagnosis.
           
          Error - 04/09/2010 17:25:27 | Computer Name = xxxxx-PC | Source = SideBySide | ID = 16842815
          Description = Activation context generation failed for "c:\program files (x86)\spybot
           - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
          files (x86)\spybot - search & destroy\DelZip179.dll" on line 8.  The value "*" of
          attribute "language" in element "assemblyIdentity" is invalid.
           
          [ System Events ]
          Error - 03/09/2010 14:07:33 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7023
          Description = The Peer Name Resolution Protocol service terminated with the following
           error:   %%-2140993535
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = PNRPSvc | ID = 102
          Description =
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = PNRPSvc | ID = 102
          Description =
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7001
          Description = The Peer Networking Grouping service depends on the Peer Name Resolution
           Protocol service which failed to start because of the following error:   %%-2140993535
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7023
          Description = The Peer Name Resolution Protocol service terminated with the following
           error:   %%-2140993535
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7023
          Description = The Peer Name Resolution Protocol service terminated with the following
           error:   %%-2140993535
           
          Error - 03/09/2010 14:07:44 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7001
          Description = The Peer Networking Grouping service depends on the Peer Name Resolution
           Protocol service which failed to start because of the following error:   %%-2140993535
           
          Error - 03/09/2010 20:11:26 | Computer Name = xxxxx-PC | Source = PNRPSvc | ID = 102
          Description =
           
          Error - 03/09/2010 20:11:26 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7001
          Description = The Peer Networking Grouping service depends on the Peer Name Resolution
           Protocol service which failed to start because of the following error:   %%-2140993535
           
          Error - 03/09/2010 20:11:26 | Computer Name = xxxxx-PC | Source = Service Control Manager | ID = 7023
          Description = The Peer Name Resolution Protocol service terminated with the following
           error:   %%-2140993535
           
           
          < End of report >

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: msconfig.exe has stopped working
          « Reply #6 on: September 05, 2010, 06:29:03 PM »
          P2P - I see you have P2P software installed on your machine (uTorrent). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

          Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

          I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
          *************************************
          * Open OTL
          * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

          Code: [Select]
          :OTL

          IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - Reg Error: Key error. File not found
          O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
          O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
          O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWow64\StikyNot.exe File not found

          :RESETHOSTS

          :COMMANDS
          [resethosts]
          [purity]
          [clearrestorepoints]
          [emptytemp]
          [start explorer]

          * Click Run Fix
          * OTLI2 may ask to reboot the machine. Please do so if asked.
          * Click OK
          * A report will open. Copy and Paste that report in your next reply.
          ***************************************

          I'd like to scan your machine with ESET OnlineScan

          •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
          ESET OnlineScan
          •Click the button.
          •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          • Click on to download the ESET Smart Installer. Save it to your desktop.
          • Double click on the icon on your desktop.
          •Check
          •Click the button.
          •Accept any security warnings from your browser.
          •Check
          •Push the Start button.
          •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
          •When the scan completes, push
          •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
          •Push the button.
          •Push
          A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
          Windows 8 and Windows 10 dual boot with two SSD's