Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: my logs after the six steps that were requested  (Read 7837 times)

0 Members and 1 Guest are viewing this topic.

Antonioaguilar

    Topic Starter


    Greenhorn

    • Experience: Beginner
    • OS: Unknown
    my logs after the six steps that were requested
    « on: November 23, 2010, 08:43:43 PM »
    i did all the six steps and this is what i came up with. the log for superantispyware is

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/23/2010 at 08:22 PM

    Application Version : 4.46.1000

    Core Rules Database Version : 5907
    Trace Rules Database Version: 3719

    Scan type       : Complete Scan
    Total Scan Time : 01:53:06

    Memory items scanned      : 761
    Memory threats detected   : 0
    Registry items scanned    : 13566
    Registry threats detected : 19
    File items scanned        : 199074
    File threats detected     : 34

    Adware.Gamevance
       (x86) HKLM\Software\Classes\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\InprocServer32
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\InprocServer32#ThreadingModel
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\ProgID
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\Programmable
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\TypeLib
       (x86) HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}\VersionIndependentProgID
       (x86) HKCR\GamevanceText.Linker.1
       (x86) HKCR\GamevanceText.Linker.1\CLSID
       (x86) HKCR\GamevanceText.Linker
       (x86) HKCR\GamevanceText.Linker\CLSID
       (x86) HKCR\GamevanceText.Linker\CurVer
       (x86) HKCR\TypeLib\{014C4232-6904-47B9-9144-7E0FB7277444}
       C:\PROGRAM FILES (X86)\GAMEVANCE\GVTL.DLL
       (x86) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
       (x86) HKU\S-1-5-21-2175598002-276824424-936044750-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
       (x86) HKCR\AppId\GamevanceText.DLL
       (x86) HKCR\AppId\GamevanceText.DLL#AppID

    Adware.Tracking Cookie
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .atdmt.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .doubleclick.net [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       ad.yieldmanager.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .atdmt.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .imrworldwide.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .imrworldwide.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .247realmedia.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .oasn04.247realmedia.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       www.googleadservices.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .serving-sys.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .serving-sys.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       ad.yieldmanager.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .steelhousemedia.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .steelhousemedia.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .advertising.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .stopzilla.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       www.stopzilla.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .stopzilla.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       www.googleadservices.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .stopzilla.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .stopzilla.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .tribalfusion.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .specificclick.net [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .specificclick.net [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .interclick.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .interclick.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .interclick.com [ C:\Users\Owner\AppData\Local\Google\Chrome\Application\7.0.517.44\Default\Cookies ]
       .doubleclick.net [ C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Cookies ]

    And the one for Malwarebytes is

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5178

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    11/23/2010 8:55:21 PM
    mbam-log-2010-11-23 (20-55-21).txt

    Scan type: Quick scan
    Objects scanned: 142464
    Time elapsed: 5 minute(s), 56 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 2
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\sezfile\shell\open\command\(default) (Rogue.MultipleAV) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (sezfile) Good: (exefile) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Users\Owner\Local Settings\Application Data\opRSK (Malware.Trace) -> Quarantined and deleted successfully.

    The log for hijackthis is

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 9:27:30 PM, on 11/23/2010
    Platform: Windows 7  (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16671)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
    C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Trend Micro\sniper.exe\sniper.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: 74.208.10.249 gs.apple.com
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"




    everything seems to be back tonormal after i did all of this. thanks for your help i appreciate it

    Antonioaguilar

      Topic Starter


      Greenhorn

      • Experience: Beginner
      • OS: Unknown
      Re: my logs after the six steps that were requested
      « Reply #1 on: November 24, 2010, 05:53:43 AM »
      Can somebody tell me if this is what everything is suppose to look like? And what do I do next?

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      Re: my logs after the six steps that were requested
      « Reply #2 on: November 24, 2010, 08:38:43 AM »
      re-run hjt and post a new log because you have not posted the full log , but it might be because you have 64bit , but have a go

      then you will have to wait for a malware expert

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: my logs after the six steps that were requested
      « Reply #3 on: November 25, 2010, 06:20:44 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
      ***********************************************
      Download OTL  to your Desktop
      • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
      • Under the Custom Scan box paste this in
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      %SYSTEMDRIVE%\*.exe
      %systemroot%\*. /mp /s
      c:\$recycle.bin\*.* /s
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      nvstor32.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      explorer.exe
      svchost.exe
      userinit.exe
      qmgr.dll
      ws2_32.dll
      proquota.exe
      imm32.dll
      kernel32.dll
      ndis.sys
      autochk.exe
      spoolsv.exe
      xmlprov.dll
      ntmssvc.dll
      mswsock.dll
      Beep.SYS
      ntfs.sys
      termsrv.dll
      sfcfiles.dll
      st3shark.sys
      ahcix86.sys
      srsvc.dll
      nvrd32.sys
      /md5stop
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles

      • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
        • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
        • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
      Windows 8 and Windows 10 dual boot with two SSD's

      Antonioaguilar

        Topic Starter


        Greenhorn

        • Experience: Beginner
        • OS: Unknown
        Re: my logs after the six steps that were requested
        « Reply #4 on: November 30, 2010, 08:16:26 PM »
        security check
         Results of screen317's Security Check version 0.99.6 
         Windows 7  (UAC is enabled)
         Internet Explorer 8 
        ``````````````````````````````
        Antivirus/Firewall Check:

         Windows Firewall Disabled! 
         WMI entry may not exist for antivirus; attempting automatic update.
        ```````````````````````````````
        Anti-malware/Other Utilities Check:

         Malwarebytes' Anti-Malware   
         Java(TM) 6 Update 22 
         Adobe Flash Player 10.0.32.18 
        Adobe Reader 9.1.2
        Out of date Adobe Reader installed!
        ````````````````````````````````
        Process Check: 
        objlist.exe by Laurent

         Trend Micro Internet Security SfCtlCom.exe 
         Trend Micro Internet Security UfSeAgnt.exe 
         Trend Micro Internet Security TmProxy.exe 
         Trend Micro Internet Security TmPfw.exe 
         Trend Micro BM TMBMSRV.exe 
        ````````````````````````````````
        DNS Vulnerability Check:

         GREAT! (Not vulnerable to DNS cache poisoning)

        ``````````End of Log````````````





        OTL.TXT log

        OTL logfile created on: 11/30/2010 8:54:40 PM - Run 1
        OTL by OldTimer - Version 3.2.17.3     Folder = C:\Users\Owner\Desktop
        64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
        Internet Explorer (Version = 8.0.7600.16385)
        Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
         
        4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
        8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
        Paging file location(s): ?:\pagefile.sys [binary data]
         
        %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
        Drive C: | 290.09 Gb Total Space | 227.41 Gb Free Space | 78.39% Space Free | Partition Type: NTFS
         
        Computer Name: OWNER-VAIO | User Name: Owner | Logged in as Administrator.
        Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
        Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
         
        ========== Processes (SafeList) ==========
         
        PRC - [2010/11/30 20:52:23 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
        PRC - [2010/11/30 20:46:01 | 000,869,086 | ---- | M] () -- C:\Users\Owner\Desktop\SecurityCheck.exe
        PRC - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
        PRC - [2009/08/26 18:11:50 | 000,173,368 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
        PRC - [2009/08/26 18:11:50 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
        PRC - [2009/08/26 18:11:50 | 000,017,408 | ---- | M] () -- C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
        PRC - [2009/08/26 18:11:48 | 000,017,920 | ---- | M] () -- C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
        PRC - [2009/07/23 11:39:38 | 000,313,264 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
        PRC - [2009/07/23 11:39:36 | 000,206,336 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
        PRC - [2009/07/22 16:03:04 | 000,642,920 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
        PRC - [2009/07/13 19:14:15 | 000,301,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
        PRC - [2009/07/01 12:49:34 | 000,204,648 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
        PRC - [2009/07/01 12:49:34 | 000,112,488 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
        PRC - [2009/06/04 20:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        PRC - [2009/06/04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
        PRC - [2009/05/26 10:23:14 | 000,317,288 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
        PRC - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
        PRC - [2008/09/18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
        PRC - [2007/01/04 20:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
         
         
        ========== Modules (SafeList) ==========
         
        MOD - [2010/11/30 20:52:23 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
        MOD - [2010/08/20 23:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
         
         
        ========== Win32 Services (SafeList) ==========
         
        SRV:64bit: - [2010/09/07 06:57:56 | 000,836,504 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe -- (SfCtlCom)
        SRV:64bit: - [2010/06/29 11:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
        SRV:64bit: - [2009/09/24 15:53:24 | 000,570,632 | ---- | M] (Trend Micro Inc.) [On_Demand | Running] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
        SRV:64bit: - [2009/09/24 15:53:22 | 000,917,768 | ---- | M] (Trend Micro Inc.) [On_Demand | Running] -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe -- (TmProxy)
        SRV:64bit: - [2009/09/24 15:52:58 | 000,595,960 | ---- | M] (Trend Micro Inc.) [On_Demand | Running] -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe -- (TmPfw)
        SRV:64bit: - [2009/08/22 15:19:06 | 000,411,496 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
        SRV:64bit: - [2009/07/23 22:34:31 | 000,189,984 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService)
        SRV:64bit: - [2009/07/13 19:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
        SRV:64bit: - [2009/06/26 15:56:10 | 000,357,672 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
        SRV:64bit: - [2009/06/26 15:35:04 | 000,468,264 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
        SRV:64bit: - [2009/06/17 19:50:30 | 000,110,888 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
        SRV:64bit: - [2008/09/29 17:06:32 | 000,167,424 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Care\collsvc.exe -- (SampleCollector)
        SRV - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
        SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
        SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
        SRV - [2009/07/31 14:09:12 | 000,436,736 | ---- | M] (Conexant Systems, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
        SRV - [2009/07/27 17:58:40 | 000,091,432 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe -- (SOHPlMgr)
        SRV - [2009/07/27 17:58:38 | 000,427,304 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
        SRV - [2009/07/27 17:58:38 | 000,075,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
        SRV - [2009/07/27 17:58:38 | 000,070,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe -- (SOHDBSvr)
        SRV - [2009/07/27 17:58:36 | 000,120,104 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
        SRV - [2009/07/23 11:39:38 | 000,313,264 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw)
        SRV - [2009/07/23 11:39:38 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
        SRV - [2009/07/23 11:39:36 | 000,206,336 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
        SRV - [2009/07/22 16:03:04 | 000,642,920 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
        SRV - [2009/07/01 12:49:34 | 000,204,648 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
        SRV - [2009/06/26 12:25:36 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
        SRV - [2009/06/26 12:25:24 | 000,313,840 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
        SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
        SRV - [2009/06/04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
        SRV - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
        SRV - [2008/09/18 11:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
        SRV - [2007/01/04 20:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
         
         
        ========== Driver Services (SafeList) ==========
         
        DRV:64bit: - [2010/07/30 11:30:26 | 000,309,840 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmxpflt.sys -- (tmxpflt)
        DRV:64bit: - [2010/07/30 11:30:20 | 000,042,576 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmpreflt.sys -- (tmpreflt)
        DRV:64bit: - [2010/07/30 11:24:14 | 001,988,176 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vsapint.sys -- (vsapint)
        DRV:64bit: - [2010/04/19 19:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
        DRV:64bit: - [2010/04/19 19:29:18 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
        DRV:64bit: - [2010/02/17 12:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
        DRV:64bit: - [2010/02/17 12:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
        DRV:64bit: - [2009/09/24 15:54:10 | 000,339,984 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmwfp.sys -- (tmwfp)
        DRV:64bit: - [2009/09/24 15:54:10 | 000,200,720 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tmlwf.sys -- (tmlwf)
        DRV:64bit: - [2009/09/24 15:54:10 | 000,107,536 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tmtdi.sys -- (tmtdi)
        DRV:64bit: - [2009/08/04 19:22:40 | 000,139,264 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
        DRV:64bit: - [2009/08/04 19:20:51 | 007,345,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
        DRV:64bit: - [2009/08/03 14:06:34 | 000,250,928 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
        DRV:64bit: - [2009/07/31 14:29:11 | 001,484,800 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
        DRV:64bit: - [2009/07/31 14:14:14 | 000,076,288 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsn64.sys -- (risdptsk)
        DRV:64bit: - [2009/07/31 14:13:51 | 000,086,528 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssn64.sys -- (rimsptsk)
        DRV:64bit: - [2009/07/31 14:09:12 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
        DRV:64bit: - [2009/07/31 14:09:08 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
        DRV:64bit: - [2009/07/31 14:02:03 | 000,393,216 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
        DRV:64bit: - [2009/07/27 14:27:10 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
        DRV:64bit: - [2009/07/23 23:24:03 | 000,201,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
        DRV:64bit: - [2009/07/13 19:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
        DRV:64bit: - [2009/07/13 19:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
        DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
        DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
        DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
        DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
        DRV:64bit: - [2009/07/13 17:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
        DRV:64bit: - [2009/06/11 14:19:09 | 000,011,392 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
        DRV:64bit: - [2009/06/10 15:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
        DRV:64bit: - [2009/06/10 15:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
        DRV:64bit: - [2009/06/10 15:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
        DRV:64bit: - [2009/06/10 14:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
        DRV:64bit: - [2009/06/10 14:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel(R)
        DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
        DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
        DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
        DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
        DRV:64bit: - [2009/06/04 19:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
        DRV:64bit: - [2009/05/26 15:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
        DRV:64bit: - [2009/05/20 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
        DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
        DRV:64bit: - [2007/04/16 21:51:50 | 000,014,112 | R--- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
         
        ========== Standard Registry (SafeList) ==========
         
         
        ========== Internet Explorer ==========
         
        IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SNNT&bmod=SNNT
        IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
        IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=SNNT&bmod=SNNT
         
        IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
        IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
        IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
         
         
        [2010/11/13 17:23:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
         
        O1 HOSTS File: ([2010/09/01 16:57:46 | 000,000,853 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
        O1 - Hosts: 74.208.10.249    gs.apple.com
        O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
        O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
        O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
        O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
        O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
        O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
        O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
        O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
        O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
        O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
        O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
        O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
        O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
        O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
        O4 - HKLM..\Run: [SmartWiHelper] C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe (Sony Electronics Corporation)
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
        O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
        O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
        O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
        O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
        O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
        O13 - gopher Prefix: missing
        O13 - gopher Prefix: missing
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
        O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
        O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
        O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
        O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.7.167 172.16.7.167 8.8.8.8
        O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
        O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
        O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
        O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
        O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
        O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
        O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
        O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
        O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
        O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
        O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
        O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
        O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
        O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
        O32 - HKLM CDRom: AutoRun - 1
        O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
        O35:64bit: - HKLM\..comfile [open] -- "%1" %*
        O35:64bit: - HKLM\..exefile [open] -- "%1" %*
        O35 - HKLM\..comfile [open] -- "%1" %*
        O35 - HKLM\..exefile [open] -- "%1" %*
        O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
        O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
        O37 - HKLM\...com [@ = comfile] -- "%1" %*
        O37 - HKLM\...exe [@ = exefile] -- "%1" %*
        O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
         
         
         
        SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
        SafeBootMin:64bit: AppMgmt - Service
        SafeBootMin:64bit: Base - Driver Group
        SafeBootMin:64bit: Boot Bus Extender - Driver Group
        SafeBootMin:64bit: Boot file system - Driver Group
        SafeBootMin:64bit: File system - Driver Group
        SafeBootMin:64bit: Filter - Driver Group
        SafeBootMin:64bit: HelpSvc - Service
        SafeBootMin:64bit: PCI Configuration - Driver Group
        SafeBootMin:64bit: PNP Filter - Driver Group
        SafeBootMin:64bit: Primary disk - Driver Group
        SafeBootMin:64bit: sacsvr - Service
        SafeBootMin:64bit: SCSI Class - Driver Group
        SafeBootMin:64bit: System Bus Extender - Driver Group
        SafeBootMin:64bit: vmms - Service
        SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
        SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
        SafeBootMin: AppMgmt - Service
        SafeBootMin: Base - Driver Group
        SafeBootMin: Boot Bus Extender - Driver Group
        SafeBootMin: Boot file system - Driver Group
        SafeBootMin: File system - Driver Group
        SafeBootMin: Filter - Driver Group
        SafeBootMin: HelpSvc - Service
        SafeBootMin: PCI Configuration - Driver Group
        SafeBootMin: PNP Filter - Driver Group
        SafeBootMin: Primary disk - Driver Group
        SafeBootMin: sacsvr - Service
        SafeBootMin: SCSI Class - Driver Group
        SafeBootMin: System Bus Extender - Driver Group
        SafeBootMin: vmms - Service
        SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
         
        SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
        SafeBootNet:64bit: AppMgmt - Service
        SafeBootNet:64bit: Base - Driver Group
        SafeBootNet:64bit: Boot Bus Extender - Driver Group
        SafeBootNet:64bit: Boot file system - Driver Group
        SafeBootNet:64bit: File system - Driver Group
        SafeBootNet:64bit: Filter - Driver Group
        SafeBootNet:64bit: HelpSvc - Service
        SafeBootNet:64bit: NDIS Wrapper - Driver Group
        SafeBootNet:64bit: NetBIOSGroup - Driver Group
        SafeBootNet:64bit: NetDDEGroup - Driver Group
        SafeBootNet:64bit: Network - Driver Group
        SafeBootNet:64bit: NetworkProvider - Driver Group
        SafeBootNet:64bit: PCI Configuration - Driver Group
        SafeBootNet:64bit: PNP Filter - Driver Group
        SafeBootNet:64bit: PNP_TDI - Driver Group
        SafeBootNet:64bit: Primary disk - Driver Group
        SafeBootNet:64bit: rdsessmgr - Service
        SafeBootNet:64bit: sacsvr - Service
        SafeBootNet:64bit: SCSI Class - Driver Group
        SafeBootNet:64bit: Streams Drivers - Driver Group
        SafeBootNet:64bit: System Bus Extender - Driver Group
        SafeBootNet:64bit: TDI - Driver Group
        SafeBootNet:64bit: vmms - Service
        SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
        SafeBootNet:64bit: WudfUsbccidDriver - Driver
        SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
        SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
        SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
        SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
        SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
        SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
        SafeBootNet: AppMgmt - Service
        SafeBootNet: Base - Driver Group
        SafeBootNet: Boot Bus Extender - Driver Group
        SafeBootNet: Boot file system - Driver Group
        SafeBootNet: File system - Driver Group
        SafeBootNet: Filter - Driver Group
        SafeBootNet: HelpSvc - Service
        SafeBootNet: NDIS Wrapper - Driver Group
        SafeBootNet: NetBIOSGroup - Driver Group
        SafeBootNet: NetDDEGroup - Driver Group
        SafeBootNet: Network - Driver Group
        SafeBootNet: NetworkProvider - Driver Group
        SafeBootNet: PCI Configuration - Driver Group
        SafeBootNet: PNP Filter - Driver Group
        SafeBootNet: PNP_TDI - Driver Group
        SafeBootNet: Primary disk - Driver Group
        SafeBootNet: rdsessmgr - Service
        SafeBootNet: sacsvr - Service
        SafeBootNet: SCSI Class - Driver Group
        SafeBootNet: Streams Drivers - Driver Group
        SafeBootNet: System Bus Extender - Driver Group
        SafeBootNet: TDI - Driver Group
        SafeBootNet: vmms - Service
        SafeBootNet: WudfUsbccidDriver - Driver
        SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
        SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
        SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
        SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
        SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
        SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
        SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
        SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
        SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
        SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
        SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
        SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
        SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
        SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
        SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
        SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
        SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
        SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
        SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
        SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
        SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
        SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
         
        ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
        ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
        ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
        ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
        ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
        ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
        ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
        ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
        ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
        ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
        ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
        ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
        ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
        ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
        ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
        ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
        ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
        ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
        ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
        ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
        ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
        ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
        ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
        ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
        ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
        ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
        ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
        ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
        ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
        ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
        ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
        ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
        ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
        ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
        ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
        ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
        ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
        ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
        ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
        ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
        ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
        ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
        ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
        ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
        ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
        ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
        ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
        ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
        ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
        ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
        ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
        ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
         
        Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
        Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
        Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
         
        ========== Files/Folders - Created Within 30 Days ==========
         
        [2010/11/30 20:52:18 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
        [2010/11/23 21:13:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
        [2010/11/23 21:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
        [2010/11/23 21:05:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
        [2010/11/23 20:47:44 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
        [2010/11/23 20:47:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
        [2010/11/23 17:47:36 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
        [2010/11/23 17:47:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
        [2010/11/23 17:47:16 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
        [2010/11/23 17:47:14 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
        [2010/11/23 17:45:31 | 009,852,776 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Owner\Desktop\SUPERAntiSpyware.exe
        [2010/11/23 17:25:39 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
        [2010/11/23 17:23:49 | 001,943,584 | ---- | C] (Piriform Ltd) -- C:\Users\Owner\Desktop\ccsetup300_slim.exe
        [2010/11/22 21:50:17 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Threat Expert
        [2010/11/22 21:42:48 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
        [2010/11/22 21:42:35 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
        [2010/11/22 21:42:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
        [2010/11/21 21:56:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
        [2010/11/21 21:56:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spyware Doctor
        [2010/11/21 21:55:53 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
        [2010/11/21 19:19:06 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\adrian
        [2010/11/16 18:22:51 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\BOA
        [2010/11/16 18:18:11 | 000,000,000 | R--D | C] -- C:\Users\Owner\Documents\Scanned Documents
        [2010/11/16 18:18:10 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Fax
        [2010/11/13 18:01:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast
        [2010/11/13 17:23:29 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Mozilla
        [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
        [1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
         
        ========== Files - Modified Within 30 Days ==========
         
        [2010/11/30 20:58:17 | 000,000,853 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
        [2010/11/30 20:57:17 | 000,000,853 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
        [2010/11/30 20:52:23 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
        [2010/11/30 20:46:01 | 000,869,086 | ---- | M] () -- C:\Users\Owner\Desktop\SecurityCheck.exe
        [2010/11/30 20:29:30 | 000,019,443 | ---- | M] () -- C:\Users\Owner\Desktop\animal cell.GIF
        [2010/11/30 20:10:07 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2175598002-276824424-936044750-1000UA.job
        [2010/11/30 19:10:50 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
        [2010/11/30 19:10:50 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
        [2010/11/30 19:02:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
        [2010/11/26 18:10:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2175598002-276824424-936044750-1000Core.job
        [2010/11/23 21:22:45 | 000,002,975 | ---- | M] () -- C:\Users\Owner\Desktop\sniper (2).lnk
        [2010/11/23 21:16:51 | 000,001,356 | ---- | M] () -- C:\Users\Owner\Desktop\sniper.exe - Shortcut.lnk
        [2010/11/23 21:13:36 | 000,002,975 | ---- | M] () -- C:\Users\Owner\Desktop\sniper.lnk
        [2010/11/23 21:12:18 | 001,402,880 | ---- | M] () -- C:\Users\Owner\Desktop\sniper.msi
        [2010/11/23 21:06:23 | 000,205,540 | ---- | M] () -- C:\Users\Owner\Desktop\JavaRa.zip
        [2010/11/23 21:03:44 | 000,778,150 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
        [2010/11/23 21:03:44 | 000,659,818 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
        [2010/11/23 21:03:44 | 000,120,714 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
        [2010/11/23 20:47:46 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
        [2010/11/23 17:47:16 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
        [2010/11/23 17:46:01 | 009,852,776 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Owner\Desktop\SUPERAntiSpyware.exe
        [2010/11/23 17:25:47 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
        [2010/11/23 17:23:58 | 001,943,584 | ---- | M] (Piriform Ltd) -- C:\Users\Owner\Desktop\ccsetup300_slim.exe
        [2010/11/21 18:01:40 | 000,064,313 | ---- | M] () -- C:\Users\Owner\Documents\adrian's school project.pptx
        [2010/11/20 20:53:57 | 000,557,892 | ---- | M] () -- C:\test.xml
        [2010/11/13 18:01:10 | 000,000,991 | ---- | M] () -- C:\Users\Owner\Desktop\SopCast.lnk
        [2010/11/13 15:11:52 | 000,002,359 | ---- | M] () -- C:\Users\Owner\Desktop\Google Chrome.lnk
        [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
        [1 C:\Users\Public\Documents\*.tmp files -> C:\Users\Public\Documents\*.tmp -> ]
         
        ========== Files Created - No Company Name ==========
         
        [2010/11/30 20:45:56 | 000,869,086 | ---- | C] () -- C:\Users\Owner\Desktop\SecurityCheck.exe
        [2010/11/30 20:29:43 | 000,019,443 | ---- | C] () -- C:\Users\Owner\Desktop\animal cell.GIF
        [2010/11/23 21:22:45 | 000,002,975 | ---- | C] () -- C:\Users\Owner\Desktop\sniper (2).lnk
        [2010/11/23 21:16:51 | 000,001,356 | ---- | C] () -- C:\Users\Owner\Desktop\sniper.exe - Shortcut.lnk
        [2010/11/23 21:13:36 | 000,002,975 | ---- | C] () -- C:\Users\Owner\Desktop\sniper.lnk
        [2010/11/23 21:12:13 | 001,402,880 | ---- | C] () -- C:\Users\Owner\Desktop\sniper.msi
        [2010/11/23 21:06:22 | 000,205,540 | ---- | C] () -- C:\Users\Owner\Desktop\JavaRa.zip
        [2010/11/23 20:47:46 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
        [2010/11/23 17:47:16 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
        [2010/11/23 17:25:47 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
        [2010/11/21 17:19:01 | 000,064,313 | ---- | C] () -- C:\Users\Owner\Documents\adrian's school project.pptx
        [2010/11/13 18:01:10 | 000,000,991 | ---- | C] () -- C:\Users\Owner\Desktop\SopCast.lnk
        [2010/09/01 16:34:55 | 000,772,430 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
        [2010/03/28 13:58:17 | 000,000,000 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\wklnhst.dat
        [2010/01/11 20:38:16 | 000,000,360 | ---- | C] () -- C:\ProgramData\hpzinstall.log
        [2009/12/02 21:50:20 | 000,004,608 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
        [2009/09/03 03:15:27 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI
        [2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
        [2009/07/13 15:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
         
        ========== LOP Check ==========
         
        [2010/02/22 18:00:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Auslogics
        [2010/01/11 21:03:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EurekaLog
        [2009/12/06 20:45:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\InterVideo
        [2010/03/28 13:58:25 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Template
        [2010/07/07 16:25:18 | 000,032,568 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
         
        ========== Purity Check ==========
         
         
         
        ========== Custom Scans ==========
         
         
        < %SYSTEMDRIVE%\*.exe >
         
        < %systemroot%\*. /mp /s >
         
        < c:\$recycle.bin\*.* /s >
        [2009/11/19 12:11:02 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2175598002-276824424-936044750-1000\desktop.ini
        [2009/10/08 11:49:38 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2175598002-276824424-936044750-500\desktop.ini
        [2009/09/03 03:33:39 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-3742182765-3865631874-2057292574-500\desktop.ini
        [2009/08/18 16:57:15 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-4202448831-3548699750-2901498775-500\desktop.ini
         
        < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
         
         
        < MD5 for: AGP440.SYS  >
        [2009/07/13 19:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
        [2009/07/13 19:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
         
        < MD5 for: ATAPI.SYS  >
        [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
        [2009/07/13 19:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
         
        < MD5 for: AUTOCHK.EXE  >
        [2009/07/13 19:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
        [2009/07/13 19:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
        [2009/07/13 19:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
        [2009/07/13 19:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
         
        < MD5 for: BEEP.SYS  >
        [2009/07/13 18:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys
         
        < MD5 for: CNGAUDIT.DLL  >
        [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
        [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
        [2009/07/13 19:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
        [2009/07/13 19:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
         
        < MD5 for: EXPLORER.EXE  >
        [2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
        [2009/10/30 23:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
        [2009/10/30 23:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
        [2009/10/30 23:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
        [2009/08/03 00:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
        [2009/10/31 00:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
        [2009/10/31 00:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
        [2009/08/02 23:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
        [2009/10/31 00:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
        [2009/08/02 23:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
        [2009/07/13 19:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
        [2009/10/31 00:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
        [2009/08/03 00:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
         
        < MD5 for: IASTOR.SYS  >
        [2009/06/04 19:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
        [2009/06/04 19:54:36 | 000,408,600 | ---- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 -- C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
        [2009/06/04 19:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
         
        < MD5 for: IASTORV.SYS  >
        [2009/07/13 19:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
        [2009/07/13 19:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
         
        < MD5 for: IMM32.DLL  >
        [2009/07/13 19:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\SysWOW64\imm32.dll
        [2009/07/13 19:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\SysWOW64\imm32.dll
        [2009/07/13 19:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) MD5=0DE3069D6E09BA262856EF31C941BEFE -- C:\Windows\winsxs\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7600.16385_none_c29fba0fc87cc5a4\imm32.dll
        [2009/07/13 19:41:09 | 000,167,424 | ---- | M] (Microsoft Corporation) MD5=AA2C08CE85653B1A0D2E4AB407FA176C -- C:\Windows\winsxs\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7600.16385_none_b84b0fbd941c03a9\imm32.dll
         
        < MD5 for: KERNEL32.DLL  >
        [2009/07/13 19:41:13 | 001,162,240 | ---- | M] (Microsoft Corporation) MD5=5B4B379AD10DEDA4EDA01B8C6961B193 -- C:\Windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.16385_none_efb2d6e86ffc8f55\kernel32.dll
        [2009/07/13 19:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\SysWOW64\kernel32.dll
        [2009/07/13 19:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\SysWOW64\kernel32.dll
        [2009/07/13 19:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) MD5=606ECB76A424CC535407E7A24E2A34BC -- C:\Windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7600.16385_none_fa07813aa45d5150\kernel32.dll
         
        < MD5 for: MSWSOCK.DLL  >
        [2009/07/13 19:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\SysWOW64\mswsock.dll
        [2009/07/13 19:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\SysWOW64\mswsock.dll
        [2009/07/13 19:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_b829ad298e9f53ff\mswsock.dll
        [2009/07/13 19:41:34 | 000,320,000 | ---- | M] (Microsoft Corporation) MD5=FC76FE3C1E1FDB761244D4F74EF560FD -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_144848ad46fcc535\mswsock.dll
         
        < MD5 for: NDIS.SYS  >
        [2009/07/13 19:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys
         
        < MD5 for: NETLOGON.DLL  >
        [2009/07/13 19:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
        [2009/07/13 19:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
        [2009/07/13 19:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
        [2009/07/13 19:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
         
        < MD5 for: NTFS.SYS  >
        [2009/07/13 19:48:27 | 001,659,984 | ---- | M] (Microsoft Corporation) MD5=356698A13C4630D5B31C37378D469196 -- C:\Windows\winsxs\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.1.7600.16385_none_02661b64369ca03a\ntfs.sys
         
        < MD5 for: NVSTOR.SYS  >
        [2009/07/13 19:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
        [2009/07/13 19:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
         
        < MD5 for: PROQUOTA.EXE  >
        [200

        Antonioaguilar

          Topic Starter


          Greenhorn

          • Experience: Beginner
          • OS: Unknown
          Re: my logs after the six steps that were requested
          « Reply #5 on: November 30, 2010, 08:19:04 PM »
          Thanks. now that that is done whats next?

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: my logs after the six steps that were requested
          « Reply #6 on: December 01, 2010, 12:41:54 PM »
          Please download the newest version of Adobe Acrobat Reader from Adobe.com

          Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
          Go to the Control Panel and enter Add or Remove Programs.
          Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

          Once old versions are gone, please install the newest version.
          *****************************************************
          How is your computer running now?

          I'd like to scan your machine with ESET OnlineScan

          •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
          ESET OnlineScan
          •Click the button.
          •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          • Click on to download the ESET Smart Installer. Save it to your desktop.
          • Double click on the icon on your desktop.
          •Check
          •Click the button.
          •Accept any security warnings from your browser.
          •Check
          •Push the Start button.
          •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
          •When the scan completes, push
          •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
          •Push the button.
          •Push
          A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
          Windows 8 and Windows 10 dual boot with two SSD's

          Antonioaguilar

            Topic Starter


            Greenhorn

            • Experience: Beginner
            • OS: Unknown
            Re: my logs after the six steps that were requested
            « Reply #7 on: December 02, 2010, 04:51:01 PM »
            exported file

            C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]\components\gvtlf.dll   Win32/Adware.Gamevance.AO application   cleaned by deleting - quarantined


            log


            ESETSmartInstaller@High as downloader log:
            all ok
            ESETSmartInstaller@High as downloader log:
            all ok
            # version=7
            # OnlineScannerApp.exe=1.0.0.1
            # OnlineScanner.ocx=1.0.0.6211
            # api_version=3.0.2
            # EOSSerial=c15176e8d5112b49af4fa667f50de8d7
            # end=finished
            # remove_checked=true
            # archives_checked=true
            # unwanted_checked=true
            # unsafe_checked=false
            # antistealth_checked=true
            # utc_time=2010-12-02 11:45:18
            # local_time=2010-12-02 05:45:18 (-0600, Central Standard Time)
            # country="United States"
            # lang=1033
            # osver=6.1.7600 NT
            # compatibility_mode=513 16777085 100 97 0 37416460 0 0
            # compatibility_mode=5893 16776574 100 94 31760811 42870938 0 0
            # compatibility_mode=8192 67108863 100 0 0 0 0 0
            # scanned=201209
            # found=1
            # cleaned=1
            # scan_time=6030
            C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]\components\gvtlf.dll   Win32/Adware.Gamevance.AO application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C

            my computer seems to be working fine. thanks

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: my logs after the six steps that were requested
            « Reply #8 on: December 03, 2010, 12:53:25 PM »
            Quote
            my computer seems to be working fine. thanks
            Good to hear. Let's do some cleanup.

            To remove all of the tools we used and the files and folders they created do the following:
            Double click OTL.exe.
            • Click the CleanUp button.
            • Select Yes when the "Begin cleanup Process?" prompt appears.
            • If you are prompted to Reboot during the cleanup, select Yes.
            • The tool will delete itself once it finishes.
            Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
            ***********************************************
            To set a new Restore Point.

            Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
            Click the Start button , click Control Panel, click System and Maintenance, and then click System.
            In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
            To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
            *********************************************
            Clean out your temporary internet files and temp files.

            Download TFC by OldTimer to your desktop.

            Double-click TFC.exe to run it.

            Note: If you are running on Vista, right-click on the file and choose Run As Administrator

            TFC will close all programs when run, so make sure you have saved all your work before you begin.

            * Click the Start button to begin the cleaning process.
            * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
            * Please let TFC run uninterrupted until it is finished.

            Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
            ************************************************
            Use the Secunia Software Inspector to check for out of date software.

            •Click Start Now

            •Check the box next to Enable thorough system inspection.

            •Click Start

            •Allow the scan to finish and scroll down to see if any updates are needed.
            •Update anything listed.
            .
            ----------

            Go to Microsoft Windows Update and get all critical updates.

            ----------

            I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

            SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
            Safe Surfing!

            Windows 8 and Windows 10 dual boot with two SSD's