Malwarebytes log and OTL
Ok first let inform you of other issues to I can not install or unistall anything. I get windows installer has failed, Windows installer service is not running or access denied. I tried to start service under services.msc I get access denied. Also sound services not working either. CD, DVD will not load anything I get program cannot be found. This one is radmon somtime cd dvd works.
Alright now that you know all systems I am not sure if that will help or not here is the requested logs.
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5288
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
12/10/2010 12:14:20 PM
mbam-log-2010-12-10 (12-14-20).txt
Scan type: Quick scan
Objects scanned: 151303
Time elapsed: 5 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 12/10/2010 12:21:21 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\owner\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.70 Gb Total Space | 34.10 Gb Free Space | 24.58% Space Free | Partition Type: NTFS
Drive E: | 2.53 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: SHAWN-WANAMAKER | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\StormII\stormliv.exe (北京暴风网际科技有限公司)
========== Modules (SafeList) ==========
MOD - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) -- C:\Program Files\CyberLink\Shared files\RichVideo.exe File not found
SRV - (Recovery Service for Windows) -- C:\Program Files\SMINST\BLService.exe File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (gupdate) Google Update Service (gupdate) -- C:\Program Files\Google\Update\GoogleUpdate.exe File not found
SRV - (GameConsoleService) -- C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe File not found
SRV - (Akamai) -- c:\Program Files\Common Files\Akamai\netsession_win_aeec0f0.dll ()
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (npggsvc) -- C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (ccosm) -- C:\Program Files\StormII\stormliv.exe (北京暴风网际科技有限公司)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (XDva349) -- C:\Windows\System32\XDva349.sys File not found
DRV - (XDva285) -- C:\Windows\System32\XDva285.sys File not found
DRV - (NwlnkFwd) -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (F-Secure Standalone Minifilter) -- C:\Users\owner\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys File not found
DRV - (EagleNT) -- C:\Users\owner\AppData\Local\Temp\EagleNT.sys File not found
DRV - (ByakkoDriver) -- C:\Users\owner\AppData\Local\Temp\100581145.06- File not found
DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcHdmiAddService) Intel(R) -- C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation)
DRV - (RTL8192su) -- C:\Windows\System32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (netr28u) -- C:\Windows\System32\drivers\netr28u.sys (Ralink Technology Corp.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (SynTP) -- C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (msloop) -- C:\Windows\System32\drivers\loop.sys (Microsoft Corporation)
DRV - (NETw3v32) Intel(R) -- C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (HSF_DPV) -- C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) -- C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8777;https=127.0.0.1:8777
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.msn.com/"
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:1.0.3.116
FF - prefs.js..extensions.enabledItems:
toolbar@ask.com:3.8.0.99999
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..network.proxy.http: "10.81.0.1"
FF - prefs.js..network.proxy.http_port: 8080
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/10 07:44:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/10 07:44:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b6\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 6\components [2010/10/30 14:29:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b6\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 6\plugins [2010/11/25 09:15:33 | 000,000,000 | ---D | M]
[2009/03/13 16:20:01 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Extensions
[2010/12/09 17:54:03 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\zbsxu33u.default\extensions
[2010/09/18 12:30:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\zbsxu33u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/26 11:01:51 | 000,000,000 | ---D | M] () -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\zbsxu33u.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2010/11/23 20:48:31 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\zbsxu33u.default\extensions\toolbar@ask.com
[2010/10/23 22:58:39 | 000,001,832 | ---- | M] () -- C:\Users\owner\AppData\Roaming\Mozilla\FireFox\Profiles\zbsxu33u.default\searchplugins\bing.xml
[2010/10/22 11:08:09 | 000,001,553 | ---- | M] () -- C:\Users\owner\AppData\Roaming\Mozilla\FireFox\Profiles\zbsxu33u.default\searchplugins\wowhead.xml
[2010/12/09 17:54:03 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/03/30 11:57:04 | 000,098,304 | ---- | M] (NHN USA Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2007/03/09 18:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [DriverMax] File not found
O4 - HKCU..\Run: [DriverMax_RESTART] File not found
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/11/02 15:00:00 | 000,000,043 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{72408b52-7e89-11df-b2a3-001f165f6049}\Shell - "" = AutoRun
O33 - MountPoints2\{72408b52-7e89-11df-b2a3-001f165f6049}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{74dd9dcd-f0c4-11dd-ba2e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{74dd9dcd-f0c4-11dd-ba2e-806e6f6e6963}\Shell\AutoRun\command - "" = E:\ffxivsetup.exe -- File not found
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\SETUP.EXE -- [2006/11/02 15:00:00 | 000,109,160 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/12/09 09:06:25 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Vuze Downloads
[2010/12/07 20:33:59 | 000,000,000 | ---D | C] -- C:\ProgramData\SecTaskMan
[2010/12/07 20:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
[2010/12/03 21:48:18 | 000,038,848 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/12/03 21:48:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010/12/03 21:48:15 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/12/03 21:37:16 | 000,000,000 | ---D | C] -- C:\43fd38b79586b12192672f43
[2010/12/03 21:18:04 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2010/12/02 20:40:58 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure
[2010/12/02 19:48:30 | 000,000,000 | ---D | C] -- C:\SWSetup
[2010/12/01 09:25:02 | 000,000,000 | ---D | C] -- C:\Program Files\Belkin
[2010/12/01 09:24:40 | 000,000,000 | ---D | C] -- C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08}
[2010/12/01 09:04:54 | 000,651,264 | ---- | C] (Ralink Technology Corp.) -- C:\Windows\System32\drivers\netr28u.sys
[2010/12/01 09:04:54 | 000,221,184 | ---- | C] (Ralink Technology, Inc.) -- C:\Windows\System32\RaCoInst.dll
[2010/11/30 12:41:55 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\owner\Desktop\ATF-Cleaner.exe
[2010/11/28 15:25:11 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\My Drivers
[2010/11/28 15:25:11 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\Innovative Solutions
[2010/11/28 15:25:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Innovative Solutions
[2010/11/28 15:25:07 | 000,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2010/11/25 13:22:49 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\customclassitemfixer_v1
[2010/11/25 09:15:07 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\DivX
[2010/11/25 09:14:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2010/11/25 09:14:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2010/11/25 09:11:36 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2010/11/25 09:10:40 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2010/07/19 15:39:04 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/10 12:05:39 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/10 12:05:28 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/10 12:05:28 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/10 12:05:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/12/10 12:05:23 | 2073,251,840 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/10 11:55:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/09 22:53:33 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml
[2010/12/09 22:53:33 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml
[2010/12/09 16:29:24 | 000,006,016 | ---- | M] () -- C:\Users\owner\Desktop\DDS.zip
[2010/12/09 16:15:00 | 199,527,180 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/12/09 16:06:30 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForowner.job
[2010/12/07 06:09:12 | 000,032,256 | ---- | M] () -- C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/04 11:55:01 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2010/12/02 11:42:12 | 000,613,270 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/12/02 11:42:12 | 000,108,196 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/12/02 08:56:43 | 000,001,079 | ---- | M] () -- C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/02 08:56:43 | 000,001,055 | ---- | M] () -- C:\Users\owner\Desktop\Spybot - Search & Destroy.lnk
[2010/11/29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/11/28 15:25:09 | 000,000,919 | ---- | M] () -- C:\Users\owner\Desktop\DriverMax.lnk
[2010/11/25 13:22:15 | 000,128,434 | ---- | M] () -- C:\Users\owner\Documents\customclassitemfixer_v1.zip
[2010/11/25 09:15:37 | 000,001,432 | ---- | M] () -- C:\Users\owner\Desktop\DivX Movies.lnk
[2010/11/25 09:14:58 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/11/25 09:14:37 | 000,000,957 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/09 22:48:15 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml
[2010/12/09 22:48:15 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml
[2010/12/09 16:29:24 | 000,006,016 | ---- | C] () -- C:\Users\owner\Desktop\DDS.zip
[2010/12/09 16:00:37 | 000,296,448 | ---- | C] () -- C:\Users\owner\Desktop\gmer.exe
[2010/12/04 12:12:05 | 2073,251,840 | -HS- | C] () -- C:\hiberfil.sys
[2010/12/02 08:56:43 | 000,001,079 | ---- | C] () -- C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/02 08:56:43 | 000,001,055 | ---- | C] () -- C:\Users\owner\Desktop\Spybot - Search & Destroy.lnk
[2010/12/01 09:04:54 | 000,015,312 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
[2010/11/30 12:34:27 | 199,527,180 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/11/28 15:25:09 | 000,000,919 | ---- | C] () -- C:\Users\owner\Desktop\DriverMax.lnk
[2010/11/25 13:22:13 | 000,128,434 | ---- | C] () -- C:\Users\owner\Documents\customclassitemfixer_v1.zip
[2010/11/25 09:15:37 | 000,001,432 | ---- | C] () -- C:\Users\owner\Desktop\DivX Movies.lnk
[2010/11/25 09:14:58 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/11/25 09:14:37 | 000,000,957 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/10/21 08:37:53 | 000,000,032 | ---- | C] () -- C:\ProgramData\io.ini
[2010/10/21 08:37:53 | 000,000,000 | ---- | C] () -- C:\ProgramData\k98417kepujtzpw2tf4poi79ey7dsn4z.ini
[2010/09/29 09:14:26 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2010/09/29 09:14:26 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010/09/26 17:35:45 | 000,000,056 | ---- | C] () -- C:\Windows\SpeederXP.INI
[2010/09/18 12:27:52 | 000,000,008 | ---- | C] () -- C:\Users\owner\AppData\Roaming\DofusAppId0_3
[2010/08/31 13:19:28 | 000,061,440 | ---- | C] () -- C:\Windows\System32\cygz.dll
[2010/08/31 13:19:28 | 000,007,196 | ---- | C] () -- C:\Windows\System32\INI_Pro_3GP_AAC.ini
[2010/08/31 13:19:28 | 000,006,490 | ---- | C] () -- C:\Windows\System32\INI_Pro_PSP.ini
[2010/08/31 13:19:28 | 000,005,028 | ---- | C] () -- C:\Windows\System32\INI_Pro_3GP2_AAC.ini
[2010/08/31 13:19:28 | 000,004,296 | ---- | C] () -- C:\Windows\System32\INI_Pro_Zune.ini
[2010/08/31 13:19:28 | 000,003,045 | ---- | C] () -- C:\Windows\System32\INI_Pro_iPod.ini
[2010/08/31 13:19:28 | 000,002,956 | ---- | C] () -- C:\Windows\System32\INI_Pro_PMP.ini
[2010/08/31 13:19:28 | 000,002,910 | ---- | C] () -- C:\Windows\System32\INI_Pro_3GP_AMR.ini
[2010/08/31 13:19:28 | 000,002,516 | ---- | C] () -- C:\Windows\System32\INI_Pro_PPC.ini
[2010/08/31 13:19:28 | 000,002,175 | ---- | C] () -- C:\Windows\System32\INI_Pro_iPhone.ini
[2010/08/31 13:19:28 | 000,001,964 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP2_QVGA_AAC.ini
[2010/08/31 13:19:28 | 000,001,964 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP2_QCIF_AAC.ini
[2010/08/31 13:19:28 | 000,001,878 | ---- | C] () -- C:\Windows\System32\INI_Pro_Xbox.ini
[2010/08/31 13:19:28 | 000,001,814 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP_QVGA_AMR.ini
[2010/08/31 13:19:28 | 000,001,814 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP_QVGA_AAC.ini
[2010/08/31 13:19:28 | 000,001,814 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP_QCIF_AMR.ini
[2010/08/31 13:19:28 | 000,001,814 | ---- | C] () -- C:\Windows\System32\INI_QT_3GPP_QCIF_AAC.ini
[2010/08/31 13:19:28 | 000,001,739 | ---- | C] () -- C:\Windows\System32\INI_Pro_AppleTV.ini
[2010/08/31 13:19:28 | 000,000,036 | ---- | C] () -- C:\Windows\System32\INI_Add_mfra.ini
[2010/08/31 13:19:27 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2010/07/19 15:33:54 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2010/07/19 15:33:54 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2010/07/04 15:29:22 | 000,000,281 | ---- | C] () -- C:\ProgramData\Local Disk (C) - Shortcut.lnk
[2010/06/18 14:08:09 | 000,000,096 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/06/10 15:09:16 | 000,000,029 | ---- | C] () -- C:\Windows\Index.ini
[2010/06/07 11:11:33 | 000,000,008 | ---- | C] () -- C:\Users\owner\AppData\Roaming\DofusAppId0_1
[2010/06/07 11:10:43 | 000,000,169 | ---- | C] () -- C:\Users\owner\AppData\Roaming\D2Info0
[2010/06/07 11:10:43 | 000,000,008 | ---- | C] () -- C:\Users\owner\AppData\Roaming\DofusAppId0_2
[2010/06/04 13:53:34 | 000,000,093 | ---- | C] () -- C:\Users\owner\AppData\Local\fusioncache.dat
[2010/05/22 12:59:20 | 000,009,728 | ---- | C] () -- C:\Windows\System32\uc_karos_launching.dll
[2010/05/17 13:19:25 | 000,139,336 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/03/15 07:44:34 | 000,005,120 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2009/10/22 10:00:45 | 000,000,148 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2009/10/20 13:25:51 | 000,001,215 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2009/09/18 20:18:48 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/17 20:53:18 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/08 20:03:02 | 000,058,880 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2009/06/28 20:20:36 | 000,001,356 | ---- | C] () -- C:\Users\owner\AppData\Local\d3d9caps.dat
[2009/05/04 19:47:37 | 000,000,021 | ---- | C] () -- C:\ProgramData\hpqp.txt
[2009/02/04 10:20:10 | 000,032,256 | ---- | C] () -- C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/01 15:18:49 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/02/01 12:07:45 | 000,000,000 | ---- | C] () -- C:\Users\owner\AppData\Local\QSwitch.txt
[2009/02/01 12:07:45 | 000,000,000 | ---- | C] () -- C:\Users\owner\AppData\Local\DSwitch.txt
[2009/02/01 12:07:45 | 000,000,000 | ---- | C] () -- C:\Users\owner\AppData\Local\AtStart.txt
[2009/01/05 15:51:11 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/01/05 15:51:03 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/01/05 15:50:43 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/01/05 15:50:14 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/01/05 15:48:06 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/01/05 15:47:38 | 000,000,284 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2008/10/23 01:44:13 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/10/23 01:38:23 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/10/23 01:36:27 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/10/23 01:35:06 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2008/07/06 15:29:46 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1518.dll
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/09 04:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/08/29 23:00:00 | 000,781,312 | ---- | C] () -- C:\Windows\System32\RGSS102J.dll
[2005/08/29 23:00:00 | 000,778,752 | ---- | C] () -- C:\Windows\System32\RGSS102E.dll
[2005/08/29 23:00:00 | 000,771,584 | ---- | C] () -- C:\Windows\System32\RGSS100J.dll
========== LOP Check ==========
[2010/11/28 14:26:27 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\.minecraft
[2009/11/16 19:24:52 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\.purple
[2010/08/21 11:56:02 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\AnvSoft
[2010/06/07 11:11:37 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\app
[2010/05/17 14:07:16 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Application Data
[2010/12/10 11:59:50 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Azureus
[2010/12/10 12:06:47 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\BitTorrent
[2010/06/25 15:11:38 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Crayon Physics Deluxe
[2010/05/24 14:56:45 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\DNA
[2010/10/29 08:58:58 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Dofus 2
[2010/06/07 11:10:43 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/09/18 12:27:52 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/06/07 11:11:34 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/10/22 16:06:23 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\EternalEden
[2010/05/17 13:35:45 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\FOG Downloader
[2010/08/08 14:06:18 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\GameTuts
[2010/05/29 08:53:28 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\GetRightToGo
[2010/05/17 09:40:18 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\GrabPro
[2010/08/19 15:32:20 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ImTOO Software Studio
[2009/04/18 19:14:26 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\iWin
[2010/09/29 09:20:49 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ManyCam
[2010/06/09 13:55:36 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\NeopleLauncherDFO
[2009/04/10 14:23:10 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\OpenOffice.org
[2010/12/07 20:16:11 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Orbit
[2009/05/03 18:46:50 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\PlayFirst
[2010/10/31 19:14:52 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ProgSense
[2010/08/21 12:01:40 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Red Kawa
[2010/06/07 11:11:37 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010/07/22 20:05:16 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Regensoft
[2010/10/31 19:49:44 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\runic games
[2010/09/29 09:25:38 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Secret of the Solstice
[2010/09/22 15:29:39 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\SystemRequirementsLab
[2010/06/04 13:53:49 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Turbine
[2009/02/01 20:37:28 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\WildTangent
[2010/12/10 12:04:09 | 000,032,638 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:661DFA1C
@Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp

06A4C76
< End of report >