This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help infected my laptop with a trojan!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, I would appreciate your guys' help with this…
So what happened was my mother was caught up with all this Michael Jackson stuff, and I guess she wanted to read something on his life. So she went on a yahoo search, and clicked the first link she thought legit. But it wasn't, far from it. The link led to an error page. Then I heard my Avast virus go off as I read about a Trojan in my computer. It couldn't remove it, so I come to you, both angry and a little saddened. sheesh MJ, you've let me down.

I've also found that whatever I save, the file becomes shared…

PS: Here's the site she went to, maybe you guys can do something about this?
DON'T CLICK: "http://fallapoblealginet.com/4images/includes/backup/cleansing-stones/michael-jackson-autobiography.html"

Here's my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:11:27 AM, on 7/14/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files (x86)\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O15 - Trusted Zone: http://rfonline-full.gscdn.com
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} (ccr_downloader Control) - http://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Sprint Con App Svc (CASprint) - Unknown owner - C:\Program Files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - Unknown owner - C:\Program Files (x86)\Sprint\Sprint SmartView\RcAppSvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14013 bytes
Hi bulletbarrage,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Here's the OTL and Extras log. I assume all options should be set on SafeList?
BTW the trojans detected by Avast were JS:Packed-AA [Trj] and JS:Redirector-E [Trj]

OTL.Txt

OTL logfile created on: 7/20/2009 5:30:13 PM - Run 4
OTL by OldTimer - Version 3.0.9.2 Folder = C:\Users\CODEC\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 61.27% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.78 Gb Total Space | 59.34 Gb Free Space | 27.00% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 19.24 Gb Free Space | 8.26% Space Free | Partition Type: NTFS
Drive E: | 13.11 Gb Total Space | 2.47 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PORTABLE-G
Current User Name: CODEC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Users\CODEC\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (AppHostSvc [Auto | Running]) – C:\Windows\SysNative\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt [On_Demand | Stopped]) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:64bit: - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:64bit: - (BthServ [Auto | Running]) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (btwdins [On_Demand | Stopped]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (CscService [Auto | Stopped]) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (Fax [On_Demand | Stopped]) – C:\Windows\SysNative\fxssvc.exe (Microsoft Corporation)
SRV:64bit: - (UmRdpService [On_Demand | Running]) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (usprserv [On_Demand | Stopped]) – C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (WAS [On_Demand | Stopped]) – C:\Windows\SysNative\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV:64bit: - (wbengine [On_Demand | Stopped]) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend [On_Demand | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (AppHostSvc [Auto | Running]) – C:\Windows\SysWow64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Automatic LiveUpdate Scheduler [Disabled | Stopped]) – C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (C-DillaCdaC11BA [Disabled | Stopped]) – C:\Windows\SysWow64\drivers\CDAC11BA.EXE (Macrovision)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4Qlb [On_Demand | Stopped]) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (EPSON_PM_RPCV4_01 [Auto | Running]) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (HP Health Check Service [On_Demand | Stopped]) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (KeyIso [On_Demand | Running]) – C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Disabled | Stopped]) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Macromedia Licensing Service [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (McciCMService [Auto | Running]) – C:\Program Files (x86)\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (MSDTC [Unknown | Stopped]) – C:\Windows\SysWow64\Msdtc [2006/11/02 06:34:14 | 00,000,000 | —D | M]
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (Netlogon [On_Demand | Stopped]) – C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (NMIndexingService [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (QPCapSvc [Auto | Running]) – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched [Auto | Running]) – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SmcService [Auto | Running]) – C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC [On_Demand | Stopped]) – C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE (Symantec Corporation)
SRV - (Steam Client Service [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (Symantec Core LC [Auto | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (vds [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vss.mof ()
SRV - (WAS [On_Demand | Stopped]) – C:\Windows\SysWow64\inetsrv\iisw3adm.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV:64bit: - (aswFsBlk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt [Auto | Running]) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (aswRdr [System | Running]) – C:\Windows\SysNative\drivers\aswRdr.sys (ALWIL Software)
DRV:64bit: - (aswSP [System | Running]) – C:\Windows\SysNative\drivers\aswSP.sys (ALWIL Software)
DRV:64bit: - (aswTdi [System | Running]) – C:\Windows\SysNative\drivers\aswTdi.sys (ALWIL Software)
DRV:64bit: - (BCM43XV [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:64bit: - (BthEnum [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:64bit: - (BthPan [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:64bit: - (BTHPORT [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:64bit: - (BTHUSB [On_Demand | Running]) – C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:64bit: - (btwaudio [On_Demand | Running]) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt [On_Demand | Running]) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (CmBatt [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (COH_Mon [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\COH_Mon.sys (Symantec Corporation)
DRV:64bit: - (CSC [System | Running]) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (elagopro [Auto | Running]) – C:\Windows\SysNative\DRIVERS\elagop64.sys (Gteko Ltd.)
DRV:64bit: - (elaunidr [Auto | Running]) – C:\Windows\SysNative\DRIVERS\elauni64.sys (Gteko Ltd.)
DRV:64bit: - (fvevol [Boot | Running]) – C:\Windows\SysNative\DRIVERS\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (HpqRemHid [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (iaStor [Boot | Running]) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw4v64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation)
DRV:64bit: - (NETw5v64 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (NuidFltr [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\nvm60x64.sys (NVIDIA Corporation)
DRV:64bit: - (NWADI [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NWADIenum.sys (Novatel Wireless Inc)
DRV:64bit: - (PCASp50a64 [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\PCASp50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:64bit: - (RFCOMM [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:64bit: - (rimmptsk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rimsptsk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (RimVSerPort [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (rismxdp [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (ROOTMODEM [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\RootMdm.sys (Microsoft Corporation)
DRV:64bit: - (RTL8169 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (SCDEmu [System | Running]) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (sdbus [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (smserial [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\smserial.sys (Motorola Inc.)
DRV:64bit: - (sptd [Boot | Running]) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (SRTSP [System | Running]) – C:\Windows\SysNative\Drivers\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPL [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\SRTSPL64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPX [System | Running]) – C:\Windows\SysNative\Drivers\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (swmx00 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\swmx00.sys (Sierra Wireless Inc.)
DRV:64bit: - (SWNC5E00 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\SWNC5E00.sys (Sierra Wireless Inc.)
DRV:64bit: - (SymEvent [On_Demand | Running]) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SynTP [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (Teefer2 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\teefer2.sys (Symantec Corporation)
DRV:64bit: - (UMPass [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64 [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (usbaudio [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo [On_Demand | Running]) – C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (vmm [System | Running]) – C:\Windows\SysNative\Drivers\vmm.sys (Microsoft Corporation)
DRV:64bit: - (VPCNetS2 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\VMNetSrv.sys (Microsoft Corporation)
DRV:64bit: - (winachsf [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (WpdUsb [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (WPS [System | Running]) – C:\Windows\SysNative\drivers\wpsdrvnt.sys (Symantec Corporation)
DRV:64bit: - (WpsHelper [On_Demand | Running]) – C:\Windows\SysNative\drivers\WpsHelper.sys (Symantec Corporation)
DRV:64bit: - (xusb21 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\xusb21.sys (Microsoft Corporation)
DRV - (CdaC15BA [Auto | Stopped]) – C:\Windows\SysWow64\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\Windows\SysWow64\drivers\COH_Mon.inf ()
DRV - (CSC [System | Running]) – C:\Windows\CSC [2008/07/02 04:51:03 | 00,000,000 | —D | M]
DRV - (eeCtrl [System | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (monitor [On_Demand | Running]) – C:\Program Files (x86)\Autodesk\Backburner\monitor.exe (Autodesk, Inc.)
DRV - (mpsdrv [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NAVENG [On_Demand | Running]) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090720.065\ENG64.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090720.065\EX64.SYS (Symantec Corporation)
DRV - (NPPTNT2 [On_Demand | Stopped]) – C:\Windows\SysWow64\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (SRTSP [System | Running]) – C:\Windows\SysWow64\Drivers\SRTSP64.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\Windows\SysWow64\Drivers\SRTSPL64.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\Windows\SysWow64\Drivers\SRTSPX64.SYS (Symantec Corporation)
DRV - (swmsflt [On_Demand | Stopped]) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (Tcpip [Boot | Running]) – C:\Windows\SysWow64\Wbem\tcpip.mof ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/23 17:50:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/06/18 13:08:24 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/06/18 13:08:23 | 00,000,000 | —D | M]

[2008/07/22 00:09:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Extensions
[2008/07/22 00:09:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/14 22:50:26 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions
[2009/06/24 00:50:52 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/25 23:47:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/05/15 14:31:15 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/06/13 02:55:50 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/01/31 10:57:43 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2008/09/06 16:29:58 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/08 13:33:27 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/05/15 00:35:38 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/13 02:55:48 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/06/13 02:55:48 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/01/26 18:34:38 | 01,044,480 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files (x86)\mozilla firefox\plugins\libdivx.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2009/03/09 05:19:09 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2009/01/26 18:34:16 | 01,337,648 | —- | M] (DivX,Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll
[2009/02/02 15:57:16 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/06/13 02:55:49 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2008/10/14 22:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2005/08/09 11:42:53 | 00,057,344 | —- | M] (America Online, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npunagi2.dll
[2007/04/16 10:07:12 | 00,180,293 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npViewpoint.dll
[2009/01/26 18:34:38 | 00,200,704 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files (x86)\mozilla firefox\plugins\ssldivx.dll
[2008/11/14 10:13:15 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2008/11/14 10:13:15 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2008/11/14 10:13:15 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 10:13:15 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2008/11/14 10:13:15 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2008/11/14 10:13:15 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2008/11/14 10:13:15 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [ccApp] C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QlbCtrl] File not found
O4 - HKLM..\Run: [QPService] C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [EasyLinkAdvisor] File not found
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: gscdn.com ([rfonline-full] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} http://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab (ccr_downloader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/21 20:49:36 | 00,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 00,000,340 | -HS- | M] () - E:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{2ccab7db-ea51-11dd-abdd-0021866b5b7e}\Shell\AutoRun\command - "" = G:\LinksysConnectPC.exe – File not found
O33 - MountPoints2\{96433239-b788-11dd-98a1-0021866b5b7e}\Shell - "" = AutoRun
O33 - MountPoints2\{96433239-b788-11dd-98a1-0021866b5b7e}\Shell\AutoRun\command - "" = I:\LaunchU3.exe – File not found
O33 - MountPoints2\{a040a79c-57ba-11dd-bf51-001e68a08e67}\Shell - "" = AutoRun
O33 - MountPoints2\{a040a79c-57ba-11dd-bf51-001e68a08e67}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{c0016655-da2c-11dd-a5b7-0021866b5b7e}\Shell\AutoRun\command - "" = H:\WDSetup.exe – File not found
O33 - MountPoints2\{c3f222d6-4e13-11de-a255-b7381f7deff4}\Shell - "" = AutoRun
O33 - MountPoints2\{c3f222d6-4e13-11de-a255-b7381f7deff4}\Shell\AutoRun\command - "" = H:\WIN\setup.exe – File not found
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\WDSetup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchEAWG.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/20 17:04:34 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\CODEC\Desktop\OTL.exe
[2009/07/14 18:08:44 | 00,030,005 | —- | C] () – C:\Users\CODEC\Desktop\I molest dolphins in the shower.jpg
[2009/07/13 21:55:54 | 00,000,000 | —D | C] – C:\Users\CODEC\AppData\Local\Adobe
[2009/07/12 21:50:41 | 01,207,055 | —- | C] () – C:\Users\CODEC\Desktop\warhammer_b&t_4_014-015.jpg
[2009/07/12 20:32:04 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40,000 - Blood and Thunder
[2009/07/11 02:46:54 | 00,054,791 | —- | C] () – C:\Users\CODEC\Desktop\zakuawesome.jpg
[2009/07/10 13:33:28 | 05,012,956 | —- | C] () – C:\Users\CODEC\Desktop\MajorTom_160.mp3
[2009/07/10 00:39:27 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Top 40 singles Uk 30 11 2008 Plus Bonus DHZ Inc Release
[2009/07/10 00:27:20 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Ministry Of Sound - The Annual [2009]
[2009/07/08 22:34:29 | 01,878,888 | —- | C] (Adobe Systems Incorporated) – C:\Users\CODEC\Desktop\install_flash_player.exe
[2009/07/07 03:06:52 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Star Wars The Clone Wars S1E12-22
[2009/07/06 13:10:40 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Star Wars The Clone Wars S1E1-11
[2009/07/06 12:18:07 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40k Damnation Crusade
[2009/07/06 12:17:35 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40K -Lone Wolves
[2009/06/30 21:45:52 | 00,011,837 | —- | C] () – C:\Users\CODEC\Desktop\mj random cd.nra
[2009/06/29 14:49:13 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Michael Jackson complete Discography
[2009/06/27 01:45:25 | 00,002,425 | —- | C] () – C:\Users\CODEC\Desktop\Forged Alliance.lnk
[2009/06/26 23:06:31 | 04,750,466 | —- | C] () – C:\Users\CODEC\Desktop\Sonic_the_Hedgehog_Metamorphic_Rock_OC_ReMix.mp3
[2009/06/25 18:00:44 | 00,000,000 | —D | C] – C:\Scenario
[2009/06/25 12:18:54 | 00,001,919 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/06/23 16:25:36 | 00,001,988 | —- | C] () – C:\Users\CODEC\Desktop\Rise of Nations Thrones and Patriots.lnk
[2009/06/23 16:23:24 | 00,000,000 | —D | C] – C:\Users\CODEC\AppData\Roaming\Microsoft Games
[2009/06/23 16:21:30 | 00,000,948 | —- | C] () – C:\Users\CODEC\Desktop\Rise Of Nations.lnk
[2009/06/23 14:19:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\att-prt22
[2009/06/23 14:19:23 | 00,000,000 | —D | C] – C:\ProgramData\Motive
[2009/06/23 14:19:18 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Motive
[2009/06/23 14:19:16 | 00,000,000 | —D | C] – C:\Program Files (x86)\ATT-PRT22-WISE
[2009/06/22 23:59:47 | 00,001,990 | —- | C] () – C:\Users\Public\Desktop\Rise Of Legends.lnk
[2009/05/26 22:18:10 | 00,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/05/26 22:17:08 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/22 00:19:06 | 00,172,173 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/02/03 20:57:49 | 00,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/10/15 11:58:34 | 00,028,808 | —- | C] () – C:\Windows\SysWow64\drivers\swmsflt.sys
[2008/10/07 09:13:30 | 00,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/09/09 14:15:10 | 00,000,060 | —- | C] () – C:\Windows\entpack.ini
[2008/08/31 16:56:45 | 00,765,952 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2008/08/31 16:56:45 | 00,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2008/08/30 14:15:53 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/08/23 19:34:53 | 00,000,336 | —- | C] () – C:\Windows\game.ini
[2008/08/16 12:01:45 | 00,789,544 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/07/22 22:40:04 | 00,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2008/07/22 22:37:04 | 00,000,044 | —- | C] () – C:\Windows\EPSCX9000F.ini
[2008/01/20 19:49:10 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/07/26 12:01:50 | 00,114,688 | —- | C] () – C:\Windows\SysWow64\hppatusg01.dll
[2006/11/02 05:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 05:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini
[2006/04/30 01:34:04 | 00,049,152 | —- | C] () – C:\Windows\SysWow64\WbxRMenu.dll
[2006/04/14 00:18:24 | 00,196,608 | —- | C] () – C:\Windows\SysWow64\atonres.dll
[2006/04/14 00:18:24 | 00,131,072 | —- | C] () – C:\Windows\SysWow64\WbxMSAI.dll
[2006/04/14 00:18:24 | 00,098,304 | —- | C] () – C:\Windows\SysWow64\atonecli.dll
[1999/01/22 11:46:58 | 00,065,536 | —- | C] () – C:\Windows\SysWow64\MSRTEDIT.DLL
[1997/06/13 19:56:08 | 00,056,832 | —- | C] () – C:\Windows\SysWow64\iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\Users\CODEC\Documents\*.tmp files]
[2009/07/20 17:19:22 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\CODEC\Desktop\OTL.exe
[2009/07/20 16:56:03 | 00,082,171 | —- | M] () – C:\ProgramData\nvModes.001
[2009/07/20 16:55:42 | 00,000,253 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/07/20 16:54:34 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/07/20 16:54:31 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/07/20 16:54:31 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/07/20 16:54:23 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/07/18 23:26:51 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/07/18 23:26:35 | 04,912,774 | -H– | M] () – C:\Users\CODEC\AppData\Local\IconCache.db
[2009/07/18 23:26:27 | 00,082,171 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/07/14 18:08:44 | 00,030,005 | —- | M] () – C:\Users\CODEC\Desktop\I molest dolphins in the shower.jpg
[2009/07/11 16:18:25 | 01,878,888 | —- | M] (Adobe Systems Incorporated) – C:\Users\CODEC\Desktop\install_flash_player.exe
[2009/07/11 02:46:54 | 00,054,791 | —- | M] () – C:\Users\CODEC\Desktop\zakuawesome.jpg
[2009/07/10 13:33:38 | 05,012,956 | —- | M] () – C:\Users\CODEC\Desktop\MajorTom_160.mp3
[2009/07/07 15:03:42 | 00,097,792 | —- | M] () – C:\Users\CODEC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/30 21:45:52 | 00,011,837 | —- | M] () – C:\Users\CODEC\Desktop\mj random cd.nra
[2009/06/27 01:45:25 | 00,002,425 | —- | M] () – C:\Users\CODEC\Desktop\Forged Alliance.lnk
[2009/06/27 01:34:09 | 04,750,466 | —- | M] () – C:\Users\CODEC\Desktop\Sonic_the_Hedgehog_Metamorphic_Rock_OC_ReMix.mp3
[2009/06/25 12:18:54 | 00,001,919 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/06/23 16:25:37 | 00,001,988 | —- | M] () – C:\Users\CODEC\Desktop\Rise of Nations Thrones and Patriots.lnk
[2009/06/23 16:21:30 | 00,000,948 | —- | M] () – C:\Users\CODEC\Desktop\Rise Of Nations.lnk
[2009/06/23 11:46:39 | 00,089,392 | —- | M] () – C:\Users\CODEC\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/06/23 11:45:14 | 00,352,680 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2009/06/22 23:59:47 | 00,001,990 | —- | M] () – C:\Users\Public\Desktop\Rise Of Legends.lnk
< End of report >

Extras.Txt

OTL Extras logfile created on: 7/20/2009 5:30:13 PM - Run 4
OTL by OldTimer - Version 3.0.9.2 Folder = C:\Users\CODEC\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 61.27% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.78 Gb Total Space | 59.34 Gb Free Space | 27.00% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 19.24 Gb Free Space | 8.26% Space Free | Partition Type: NTFS
Drive E: | 13.11 Gb Total Space | 2.47 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PORTABLE-G
Current User Name: CODEC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = C2 FE 8D 6A DC 5B C8 01 [binary data]
"VistaSp2" = 14 07 E8 A1 91 DE C9 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F08D2A-548F-4B61-92B8-ED140DA56336}" = rport=10244 | protocol=6 | dir=out | app=system |
"{05F95530-E1A9-4A4F-ABB3-198CB740C84F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0BC90162-E917-4F22-BD8A-6488C52BF74E}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{14EC0CE2-E760-4165-B361-3D6C4142F61E}" = rport=138 | protocol=17 | dir=out | app=system |
"{21D5DAC4-FDFA-4305-8534-744D437855B7}" = lport=445 | protocol=6 | dir=in | app=system |
"{23FDC079-49A8-4630-82E1-175114536CDF}" = rport=137 | protocol=17 | dir=out | app=system |
"{38B76183-F39F-4A25-9795-E2EAADD2E5E8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4B51B214-3207-4A96-88FD-6FD7346991ED}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{68EFFD0A-5449-4B4A-A9F9-7BF524D124F4}" = lport=10244 | protocol=6 | dir=in | app=system |
"{6DB50A41-650A-4478-B9F1-4E2D92FD41D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6F5733F6-9BA7-4A20-8A52-3F6AC000D205}" = lport=139 | protocol=6 | dir=in | app=system |
"{791EB5B7-86CE-4C48-A9C8-08B7C18FBAE4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7B00C0F4-E60A-4632-AB5E-E984EEBDC220}" = lport=3390 | protocol=6 | dir=in | app=system |
"{7D0ADA2D-C2D8-4EC5-91C9-09FB37C91AB2}" = rport=445 | protocol=6 | dir=out | app=system |
"{7D80A354-D63A-4644-91B4-1EB84F80468E}" = rport=139 | protocol=6 | dir=out | app=system |
"{7F256B24-349A-42B9-961F-BA965624E122}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{80882A72-EB4E-450F-AA95-2C07C733F1ED}" = lport=137 | protocol=17 | dir=in | app=system |
"{81C266FF-D6B8-43DC-B783-B3D478887C78}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{984D89FD-329C-41C6-99AB-CEFA2A6239FB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9C521D47-F763-4B4D-901C-67397D7A23A7}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{A18532BE-A5CF-4201-AAA3-37E80351DBAE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2DCE109-3B59-41C9-B39D-A67B57C3CDD2}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B38C91B9-A897-4340-A871-6DB8302E8829}" = rport=10244 | protocol=6 | dir=out | app=system |
"{C0D5DF60-1CB2-4E77-B249-63B5A1061072}" = lport=138 | protocol=17 | dir=in | app=system |
"{C67C0D59-215D-4E72-81AD-C7E6D7BFF8C1}" = lport=3390 | protocol=6 | dir=in | app=system |
"{D154506C-C865-43B4-AF88-2C49DD5512CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D382CCB9-2A84-4833-8CF0-9BD0370224CC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E8C8DF2F-FC7A-4C1A-8ACD-2EE97FB769E7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F688A7D9-1E57-4DA0-BD56-77E698453B4A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA141D02-1363-4398-850E-B1CB1277ADEB}" = lport=10244 | protocol=6 | dir=in | app=system |
"{FB436E38-9CBC-4B8A-AB7A-C3F493B24F5A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FE37AA13-AD05-4400-A22A-16ED557EF95F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{008A4D69-9D21-4AD0-8048-E7E62C737543}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{04ED0249-72DA-4D1A-BAA0-3CFF26541D15}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{089C188C-CBB6-44DE-B895-588E650ECA82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe |
"{0AD5A9D3-A85C-405C-903B-DE7CD9469BE7}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{0D0C6E6D-9859-490D-9BB0-6F76B363A849}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{0F5775E8-18FC-48DA-B4A8-392602D103E5}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{129FAA59-C39C-4EDF-A049-AC078D684FD2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{13320DB1-EF44-4B6D-8AE4-FB55A54FD89E}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{13CC58D9-33FE-4427-BB31-DB33D19CBB2E}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\symantec shared\ccapp.exe |
"{1493BA12-6201-47E2-9CB7-CC28F05BA237}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{1BD2C1FB-B7D0-4DFB-AA65-091B732CFE31}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40kwa.exe |
"{1C7F4043-0253-4C96-A128-8AF0E56A1F75}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\smc.exe |
"{1EAE0103-4144-4925-9827-742BA799E18A}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\symantec shared\ccapp.exe |
"{2636755A-902D-4605-8EC2-B9077D76F011}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{2C510222-BA86-4E6D-AAA0-40D87C490C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\smc.exe |
"{3005A6F4-12E8-4CBD-B08D-BBB795665B39}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{326D808E-3B8A-4946-BC09-3598EC12EB83}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{33C034F5-B8F1-4F10-89DA-6898B076B36D}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{342A9E1E-CBD5-4CF2-8973-4FE8340C24F5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3FF8991A-CC89-4739-A025-D2ED9EE5D46E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{47F5DEA0-A201-437B-866B-825E6904F3C2}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{4BD54462-57BC-44CB-880A-D66DD7E1986A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40kwa.exe |
"{4EC0C756-C6B8-4782-8159-023E0C6C0E00}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{4F5CF9D3-BEDF-4DFA-BFFE-8CA04CB8DB33}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{55AA4FCA-B22C-4A58-B2B9-A694363B9A85}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe |
"{5A2A5AAB-10BD-4624-8749-2C7AA1E3B7F1}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{6847D6FB-9E7B-4158-A46B-0B2716812D57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe |
"{6B75E66A-1C4B-4485-BB33-5134AA013617}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6C67B824-EE33-462F-B4CF-19B1ABA05AFD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{6DFA1038-225B-4F77-ABBF-247914898AF2}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{711BBB19-5E08-4BC6-A847-FC23E0880E35}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{81635AD4-5953-4BB7-9E5F-1CE847184588}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{82445A69-FE2B-43A3-886E-CF53EBABD72C}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{831C8631-A7E2-467F-95DD-3504B2B77D5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{864B71F8-5CA8-477A-BAF8-407A5B5EF723}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceempiresv\se5\se5.exe |
"{89ECFE29-5971-4345-BA2B-7B1F48C7CE74}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{957AC5E3-24B8-47EB-AC8E-909CA6FA1EB8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96BF49FB-D8FF-497E-9238-3121F8421502}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{9A8D9EFA-805D-4EDF-A134-D02CADABB206}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{9DB9AB1F-C89F-4190-9DDD-38B64AE5AE3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe |
"{A0A28924-4D5A-4647-9069-290665C43406}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{A0A4D238-58F2-4810-811C-F812FC591145}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{A56B9FF2-643B-4C0E-85DC-AB7F33AAF041}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{A766C4D8-083F-4F5B-A674-F51B6585AB95}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AC31A460-88A6-4542-8C1A-262BB3B2B9D8}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander - forged alliance\bin\forgedalliance.exe |
"{B26734E8-FE8C-40B6-9208-D8CC9E6CBA33}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{B5A7CE3D-7C25-44D0-9F52-FE65B4E7EE48}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B895492E-FAA1-4DBD-BF6C-E800165812C1}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{BA7450A5-355A-476B-8F57-905E992114BF}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{BA787A0D-31E8-4614-B543-C1F96B51B499}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{BB037E5D-278B-49BA-A48B-F6CA1455E3D3}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{BBADEFD6-F43C-4707-82B3-E862C45C25A9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{BC7C03AC-6E02-48A8-8C2D-F4D58BEDD41B}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{C0041FAA-D980-4728-A0F4-A556C3A25398}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{C2C7FB1B-1004-47D9-BB47-06DBC9DDB584}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C2F0E36C-BD11-46AF-B80C-490752D297E1}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{C3EE8E3B-7ED5-4C3A-9C13-920E46386789}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\snac64.exe |
"{C54CEB72-31E2-4AA0-9FB9-ED6F45770F4E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\hp1006mc.exe |
"{CB3145F5-9623-41B1-9830-5FF912C1AFB2}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{D125FC29-D05E-49CE-A9F6-9C11FDFBD965}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{D1DBA2CC-DD18-4B92-9CA8-445D4D3EAD97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe |
"{D55F1728-ED30-4EA6-8218-B87463A50C5A}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{D76452A3-3EB2-4A12-942A-89086D29DCCA}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{D9356147-08A9-4EE9-95A0-2FD5D466FE57}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe |
"{D9426C56-399C-490E-9B52-48075EFBEE23}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceempiresv\se5\se5.exe |
"{DAA9207F-92FF-418B-841A-84791B922E6A}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\snac64.exe |
"{DCDC4CF4-9506-4724-803E-475280F8BDCD}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{DD470243-A844-4BF8-A705-24CA437C0200}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\bulletbarrage\space empires iv deluxe\se4\se4.exe |
"{E5D522D0-BF36-46F2-B728-3E74BAC45A16}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{EE322945-5371-49F6-886A-412A6B4F1582}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{EE7F9411-4D08-458B-9742-08BFD2AF84D9}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{F07920C9-B740-4D6D-9FF5-49EED95D9846}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{F3D72A2B-0E40-4891-8B5E-A28AF98B3481}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander - forged alliance\bin\forgedalliance.exe |
"{F4629845-AF27-4801-BBDF-86BAEAFC3F42}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{FAD66503-0961-48DF-B14A-A74E3C448143}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\bulletbarrage\space empires iv deluxe\se4\se4.exe |
"{FBA3E2C1-1DB5-4A65-9BFB-8ADC48D5FC5D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{FDD5C893-4077-44B8-A40F-7BBF153CFED6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FF9A129D-F7C9-49EF-9AC5-34D87E41723D}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\hp1006mc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E6C415F-7708-4A8F-9509-11C98988BDCA}" = Apple Mobile Device Support
"{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{43602F34-1AA3-44FB-AEB2-D08C2C737440}" = Paint.NET v3.36
"{5AB0C6D3-E546-44C2-8B63-C9044FCC9AC0}" = iTunes
"{8A837C47-2B21-4FDF-8370-41A1EB6A26E8}" = Microsoft Xbox 360 Accessories 1.1
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{E8B5E073-4FB3-4976-B4A8-0DF3CE91E744}" = Symantec Endpoint Protection
"EPSON Printer and Utilities" = EPSON Printer Software
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"SMSERIAL" = Motorola SM56 Data Fax Modem
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UltSounds" = Windows Sound Schemes
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02C85EC5-E864-4847-AF55-42730861004C}" = MrvlUsgTracking
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2D8ECB5E-9F6C-4332-AEE6-0E4EE1DEC926}" = Maya 8.5 Personal Learning Edition
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2008.1
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A829DA3-E377-4BC0-938F-F453C6BB3F67}" = Maya 8.5 Personal Learning Edition Documentation (en_US)
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C8B5E63-821A-4DFB-BDFA-19854D88EC5C}" = 3dsmax ancillary install
"{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088
"{86C7336D-0E3A-4953-ADF4-F4B5E0096278}" = Command & Conquer 3 Tiberium Wars™ MOD SDK
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E72B982-D54F-486F-B35A-C24B6F171033}" = Nero 7 Essentials
"{8ED6D4D2-6B9F-4B0E-A1AE-A94C20256BC4}" = Lords of the Realm 2
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C194D333-B84A-4BB7-B35E-060732D98DC4}" = GPGNet
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{D3A04D2F-28C4-4D9C-8487-DAB75992AE09}" = AIM Pro
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F6A3F605-7B10-4939-8D3D-4594332C1649}" = Red Alert 3 Mod SDK
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"ATT-PRT22" = ATT-PRT22
"Autodesk FBX Plugin 2009.4 - 3ds Max 2010" = Autodesk FBX Plugin 2009.4 - 3ds Max 2010
"avast!" = avast! Antivirus
"AviSynth" = AviSynth 2.5
"CdaC13Ba" = SafeCast Shared Components
"CDisplay_is1" = CDisplay 1.8
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"EADM" = EA Download Manager
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0032)
"Fallout 2_is1" = Fallout 2
"Fallout Mod Manager_is1" = Fallout Mod Manager 0.9.9
"FBX Plugin 2006.08 for Max 9.0" = FBX Plugin 2006.08 for Max 9.0
"FL Studio 7" = FL Studio 7
"GENS" = GENS
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP LaserJet P1000 series" = HP LaserJet P1000 series
"HP Smart Web Printing" = HP Smart Web Printing
"IL Download Manager" = IL Download Manager
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mideast Crisis 2" = Mideast Crisis 2
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"OpenAL" = OpenAL
"PowerISO" = PowerISO
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"RiseofNationsExpansion 1.0" = Rise of Nations Thrones and Patriots
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Spring" = Spring 0.78.2.1
"Steam App 1610" = Space Empires IV Deluxe
"Steam App 1690" = Space Empires V
"Steam App 220" = Half-Life 2
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 400" = Portal
"Steam App 440" = Team Fortress 2
"Steam App 4570" = Dawn of War Gold
"Steam App 4580" = Dawn of War: Dark Crusade
"Steam App 500" = Left 4 Dead
"Steam App 70" = Half-Life
"Steam App 9450" = Dawn of War: Soulstorm
"SystemRequirementsLab" = System Requirements Lab
"Videora iPod touch Converter" = Videora iPod touch Converter 4.07
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6i
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{25A1E6A4-2DBD-4AC0-8650-8EA9A45B183D}" = Supreme Commander
"{31D95937-B237-405D-920C-A3EF4E482395}" = Supreme Commander - Forged Alliance
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 7/2/2009 4:52:35 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/3/2009 4:28:25 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Ahead\Nero Home\is2.db failed, 00000005.

Error - 7/3/2009 4:28:33 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat failed,
00000005.

Error - 7/4/2009 12:30:23 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/6/2009 5:10:32 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/9/2009 5:00:37 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Roaming\Microsoft\Windows\Cookies\index.dat failed, 00000005.


Error - 7/11/2009 5:47:18 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Ahead\Nero Home\is2.db failed, 00000005.

Error - 7/13/2009 8:42:32 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/16/2009 3:13:11 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Ahead\NERO HOME\is2.db failed, 00000005.

Error - 7/19/2009 2:26:47 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

[ Application Events ]
Error - 7/11/2009 3:06:59 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/11/2009 7:00:53 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/12/2009 12:11:00 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/12/2009 1:25:40 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/12/2009 1:35:21 PM | Computer Name = Portable-G | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 7/12/2009 9:32:50 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/13/2009 10:35:26 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/14/2009 6:44:42 AM | Computer Name = Portable-G | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 7/14/2009 2:44:38 PM | Computer Name = Portable-G | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 7/14/2009 10:44:37 PM | Computer Name = Portable-G | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

[ System Events ]
Error - 7/13/2009 10:35:26 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/13/2009 10:35:26 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =

Error - 7/14/2009 2:54:18 PM | Computer Name = Portable-G | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 0.0.0.0 with
the system having network hardware address 00-00-00-00-00-CF. Network operations
on this system may be disrupted as a result.

Error - 7/15/2009 4:03:25 PM | Computer Name = Portable-G | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 7/17/2009 1:32:42 PM | Computer Name = Portable-G | Source = Application Popup | ID = 1060
Description = \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 7/17/2009 1:34:00 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/17/2009 1:34:00 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =

Error - 7/20/2009 7:54:35 PM | Computer Name = Portable-G | Source = Application Popup | ID = 1060
Description = \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 7/20/2009 7:55:24 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/20/2009 7:55:24 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =


< End of report >

Thanks for the reply!

BTW the trojans detected by Avast were JS:Packed-AA [Trj] and JS:Redirector-E [Trj]

Hi,

In which locations were the detections made?

You seem to have some p2p file sharing software installed there. I recommend to uninstall such things since big part of infections are coming from p2p networks nowadays.


Uninstall these vulnerable Javas:
Java™ 6 Update 2
Java™ 6 Update 7


and this vulnerable Flash:
Adobe Flash Player ActiveX

You seem to have both avast! Antivirus and Symantec Endpoint Protection installed. It's recommended to have one antivirus only in same system. Decide which one you want to uninstall.


Uninstall old Adobe Reader versions and get the latest one (9.1 + update 9.1.2 for it) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.

Then start OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log


Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Read the requirements and privacy statement then click on the Accept button.

  • The program will launch and start to download the latest definition files.

  • You will be prompted to install an application from Kaspersky. Click Run

  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
  • Spyware, Adware, Dialers, and other potentially dangerous programs
    Archives

  • Click on My Computer under Scan.

  • Once the scan is complete, it will display the results. Click on View Scan Report.

  • Click on Save Report As….

  • Change the Files of type to Text file (.txt) before clicking on the Save button.

  • Save this report to a convenient place.

  • Copy and paste that information into your topic. How's the system running?

  • The scan will take a while so be patient and let it run. As it scans your machine very deeply it could take hours to complete, Kaspersky suggests running it during a time of low activity.
If you need a tutorial, see here
The Redirector-E was detected on the website at the top I listed and on my computer at "C:\Users\[MyUserName]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGJLJ5FG\michael-jackson-autobiography[1].htm". The Packed-AA was detected on a website, also, but not on my computer. And hey, two hidden "desktop.ini" files just popped up on my desktop…Should I delete them? Anyway, here is the OTL fix log: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: CODEC File delete failed. C:\Users\CODEC\AppData\Local\Temp\ehmsas.txt scheduled to be deleted on reboot. File delete failed. C:\Users\CODEC\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot. ->Temp folder emptied: 32585 bytes File delete failed. C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 23521429 bytes ->Java cache emptied: 55326761 bytes ->FireFox cache emptied: 58116883 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Mcx1 ->Temp folder emptied: 2 bytes ->Temporary Internet Files folder emptied: 70584 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes File delete failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 130.72 mb OTL by OldTimer - Version 3.0.9.2 log created on 07212009_113810 Files\Folders moved on Reboot… C:\Users\CODEC\AppData\Local\Temp\ehmsas.txt moved successfully. C:\Users\CODEC\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…
Hi,

The Redirector-E was detected on the website at the top I listed and on my computer at "C:\Users\[MyUserName]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGJLJ5FG\michael-jackson-autobiography[1].htm".

Delete that file if it still exists.

And hey, two hidden "desktop.ini" files just popped up on my desktop…Should I delete them?

You may leave those. You didn't see them earlier cos files were set hidden.


Shall wait for Kaspersky online scanner report.
Ok, I'll leave the two desktop.ini alone, but one of them has, under "group or user names", something called "uuid: 10000000-0000-0000-0200-00123AE5B8A7" which has "Special permissions" and something called "INTERACTIVE" which has "Read & execute" and "Read". I have also found those under a few other desktop icons and I am a bit paranoid about it. Also, there is another account called "ASP.Net Machine Account" but I'm not sure if that's a good or bad thing… Anyway, here's the Kapersky report. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, July 21, 2009 Operating System: Microsoft Windows Vista Ultimate Edition, 64-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, July 21, 2009 19:36:35 Records in database: 2508191 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ Scan statistics: Files scanned: 324955 Threat name: 2 Infected objects: 3 Suspicious objects: 0 Duration of the scan: 06:11:55 File name / Threat name / Threats count C:\ProgramData\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600000\4DE24DF5.VBN Infected: Exploit.JS.Pdfka.hg 1 C:\Users\All Users\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C600000\4DE24DF5.VBN Infected: Exploit.JS.Pdfka.hg 1 D:\Games\Full\cc95v106b_full.exe Infected: Hoax.Win32.BadJoke.MovingMouse.v 1 The selected area was scanned.
Hi,

Delete Kaspersky findings.

Ok, I'll leave the two desktop.ini alone, but one of them has, under "group or user names",
something called "uuid: 10000000-0000-0000-0200-00123AE5B8A7" which has "Special permissions" and something called "INTERACTIVE" which has "Read & execute" and "Read". I have also found those under a few other desktop icons and I am a bit paranoid about it.

Those are usually normal. You may read more about desktop.ini files here.

Also, there is another account called "ASP.Net Machine Account" but I'm not sure if that's a good or bad thing…

That's normal account in system with Microsoft .NET Framework installed. More information here.

Please post a fresh OTL log and let me know how's the system running.
OTL logfile created on: 7/22/2009 3:09:17 PM - Run 5
OTL by OldTimer - Version 3.0.9.2 Folder = C:\Users\CODEC\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 59.54% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.78 Gb Total Space | 50.60 Gb Free Space | 23.02% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 19.34 Gb Free Space | 8.30% Space Free | Partition Type: NTFS
Drive E: | 13.11 Gb Total Space | 2.47 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PORTABLE-G
Current User Name: CODEC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Users\CODEC\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (AppHostSvc [Auto | Running]) – C:\Windows\SysNative\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt [On_Demand | Stopped]) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:64bit: - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:64bit: - (BthServ [Auto | Running]) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (btwdins [On_Demand | Stopped]) – C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (CscService [Auto | Stopped]) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (Fax [On_Demand | Stopped]) – C:\Windows\SysNative\fxssvc.exe (Microsoft Corporation)
SRV:64bit: - (UmRdpService [On_Demand | Running]) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (usprserv [On_Demand | Stopped]) – C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (WAS [On_Demand | Stopped]) – C:\Windows\SysNative\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV:64bit: - (wbengine [On_Demand | Stopped]) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend [On_Demand | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (AppHostSvc [Auto | Running]) – C:\Windows\SysWow64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Automatic LiveUpdate Scheduler [Disabled | Stopped]) – C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (C-DillaCdaC11BA [Disabled | Stopped]) – C:\Windows\SysWow64\drivers\CDAC11BA.EXE (Macrovision)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4Qlb [On_Demand | Stopped]) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (EPSON_PM_RPCV4_01 [Auto | Running]) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (HP Health Check Service [On_Demand | Stopped]) – c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (KeyIso [On_Demand | Running]) – C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Disabled | Stopped]) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Macromedia Licensing Service [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (McciCMService [Auto | Running]) – C:\Program Files (x86)\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (MSDTC [Unknown | Stopped]) – C:\Windows\SysWow64\Msdtc [2006/11/02 06:34:14 | 00,000,000 | —D | M]
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (Netlogon [On_Demand | Stopped]) – C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (NMIndexingService [On_Demand | Running]) – C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (QPCapSvc [Auto | Running]) – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched [Auto | Running]) – C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
SRV - (Steam Client Service [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Symantec Core LC [Auto | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (vds [On_Demand | Stopped]) – C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\vss.mof ()
SRV - (WAS [On_Demand | Stopped]) – C:\Windows\SysWow64\inetsrv\iisw3adm.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV:64bit: - (aswFsBlk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:64bit: - (aswMonFlt [Auto | Running]) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:64bit: - (aswRdr [System | Running]) – C:\Windows\SysNative\drivers\aswRdr.sys (ALWIL Software)
DRV:64bit: - (aswSP [System | Running]) – C:\Windows\SysNative\drivers\aswSP.sys (ALWIL Software)
DRV:64bit: - (aswTdi [System | Running]) – C:\Windows\SysNative\drivers\aswTdi.sys (ALWIL Software)
DRV:64bit: - (BCM43XV [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:64bit: - (BthEnum [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:64bit: - (BthPan [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:64bit: - (BTHPORT [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:64bit: - (BTHUSB [On_Demand | Running]) – C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:64bit: - (btwaudio [On_Demand | Running]) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt [On_Demand | Running]) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV:64bit: - (CmBatt [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (CSC [System | Running]) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (elagopro [Auto | Running]) – C:\Windows\SysNative\DRIVERS\elagop64.sys (Gteko Ltd.)
DRV:64bit: - (elaunidr [Auto | Running]) – C:\Windows\SysNative\DRIVERS\elauni64.sys (Gteko Ltd.)
DRV:64bit: - (fvevol [Boot | Running]) – C:\Windows\SysNative\DRIVERS\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HdAudAddService [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (HpqRemHid [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (iaStor [Boot | Running]) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (NETw4v64 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\NETw4v64.sys (Intel Corporation)
DRV:64bit: - (NETw5v64 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (NuidFltr [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\nvm60x64.sys (NVIDIA Corporation)
DRV:64bit: - (NWADI [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\NWADIenum.sys (Novatel Wireless Inc)
DRV:64bit: - (PCASp50a64 [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\PCASp50a64.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:64bit: - (RFCOMM [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:64bit: - (rimmptsk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rimsptsk [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (RimVSerPort [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (rismxdp [Auto | Running]) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (ROOTMODEM [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\RootMdm.sys (Microsoft Corporation)
DRV:64bit: - (RTL8169 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (SCDEmu [System | Running]) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (sdbus [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (smserial [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\smserial.sys (Motorola Inc.)
DRV:64bit: - (sptd [Boot | Running]) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (swmx00 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\swmx00.sys (Sierra Wireless Inc.)
DRV:64bit: - (SWNC5E00 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\SWNC5E00.sys (Sierra Wireless Inc.)
DRV:64bit: - (SynTP [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (UMPass [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\umpass.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64 [On_Demand | Stopped]) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (usbaudio [On_Demand | Stopped]) – C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:64bit: - (usbvideo [On_Demand | Running]) – C:\Windows\SysNative\Drivers\usbvideo.sys (Microsoft Corporation)
DRV:64bit: - (vmm [System | Running]) – C:\Windows\SysNative\Drivers\vmm.sys (Microsoft Corporation)
DRV:64bit: - (VPCNetS2 [On_Demand | Running]) – C:\Windows\SysNative\DRIVERS\VMNetSrv.sys (Microsoft Corporation)
DRV:64bit: - (winachsf [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (WpdUsb [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (xusb21 [On_Demand | Stopped]) – C:\Windows\SysNative\DRIVERS\xusb21.sys (Microsoft Corporation)
DRV - (CdaC15BA [Auto | Stopped]) – C:\Windows\SysWow64\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (CSC [System | Running]) – C:\Windows\CSC [2008/07/02 04:51:03 | 00,000,000 | —D | M]
DRV - (eeCtrl [System | Running]) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (monitor [On_Demand | Running]) – C:\Program Files (x86)\Autodesk\Backburner\monitor.exe (Autodesk, Inc.)
DRV - (mpsdrv [On_Demand | Running]) – C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NPPTNT2 [On_Demand | Stopped]) – C:\Windows\SysWow64\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (swmsflt [On_Demand | Stopped]) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (Tcpip [Boot | Running]) – C:\Windows\SysWow64\Wbem\tcpip.mof ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/23 17:50:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/06/18 13:08:24 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/07/21 01:57:15 | 00,000,000 | —D | M]

[2008/07/22 00:09:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Extensions
[2008/07/22 00:09:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/21 11:36:38 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions
[2009/06/24 00:50:52 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/25 23:47:40 | 00,000,000 | —D | M] – C:\Users\CODEC\AppData\Roaming\mozilla\Firefox\Profiles\j9umoekv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/07/21 20:44:06 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/06/13 02:55:50 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/01/31 10:57:43 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/03/08 13:33:27 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/05/15 00:35:38 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/13 02:55:48 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/06/13 02:55:48 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/01/26 18:34:38 | 01,044,480 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files (x86)\mozilla firefox\plugins\libdivx.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2009/03/09 05:19:09 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2009/01/26 18:34:16 | 01,337,648 | —- | M] (DivX,Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll
[2009/02/02 15:57:16 | 00,098,304 | —- | M] (DivX, Inc) – C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/06/13 02:55:49 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/18 13:08:22 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/18 13:08:23 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2005/08/09 11:42:53 | 00,057,344 | —- | M] (America Online, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npunagi2.dll
[2007/04/16 10:07:12 | 00,180,293 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npViewpoint.dll
[2009/01/26 18:34:38 | 00,200,704 | —- | M] (The OpenSSL Project, http://www.openssl.org/) – C:\Program Files (x86)\mozilla firefox\plugins\ssldivx.dll
[2008/11/14 10:13:15 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2008/11/14 10:13:15 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2008/11/14 10:13:15 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 10:13:15 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2008/11/14 10:13:15 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2008/11/14 10:13:15 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2008/11/14 10:13:15 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QlbCtrl] File not found
O4 - HKLM..\Run: [QPService] C:\Program Files (x86)\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [EasyLinkAdvisor] File not found
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWow64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: gscdn.com ([rfonline-full] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} http://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab (ccr_downloader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/21 20:49:36 | 00,000,000 | —D | M] - C:\Autodesk – [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 00,000,340 | -HS- | M] () - E:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{2ccab7db-ea51-11dd-abdd-0021866b5b7e}\Shell\AutoRun\command - "" = G:\LinksysConnectPC.exe – File not found
O33 - MountPoints2\{96433239-b788-11dd-98a1-0021866b5b7e}\Shell - "" = AutoRun
O33 - MountPoints2\{96433239-b788-11dd-98a1-0021866b5b7e}\Shell\AutoRun\command - "" = I:\LaunchU3.exe – File not found
O33 - MountPoints2\{a040a79c-57ba-11dd-bf51-001e68a08e67}\Shell - "" = AutoRun
O33 - MountPoints2\{a040a79c-57ba-11dd-bf51-001e68a08e67}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{c0016655-da2c-11dd-a5b7-0021866b5b7e}\Shell\AutoRun\command - "" = H:\WDSetup.exe – File not found
O33 - MountPoints2\{c3f222d6-4e13-11de-a255-b7381f7deff4}\Shell - "" = AutoRun
O33 - MountPoints2\{c3f222d6-4e13-11de-a255-b7381f7deff4}\Shell\AutoRun\command - "" = H:\WIN\setup.exe – File not found
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\WDSetup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchEAWG.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/22 12:00:19 | 00,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2009/07/22 12:00:19 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2009/07/22 12:00:19 | 00,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2009/07/22 12:00:18 | 00,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2009/07/22 12:00:18 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2009/07/22 12:00:18 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2009/07/22 12:00:18 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dciman32.dll
[2009/07/22 12:00:18 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dciman32.dll
[2009/07/21 21:35:06 | 00,015,112 | —- | C] () – C:\ProgramData\LuUninstall.LiveUpdate
[2009/07/21 02:00:47 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/21 01:58:30 | 06,653,952 | —- | C] () – C:\Users\CODEC\Desktop\AdbeRdrUpd912_all_incr.msp
[2009/07/21 01:57:15 | 00,001,919 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/07/21 01:56:43 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2009/07/21 01:56:43 | 00,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2009/07/21 01:53:13 | 26,739,584 | —- | C] ( ) – C:\Users\CODEC\Desktop\AdbeRdr910_en_US.exe
[2009/07/21 01:51:25 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/07/20 17:04:34 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\CODEC\Desktop\OTL.exe
[2009/07/14 18:08:44 | 00,030,005 | —- | C] () – C:\Users\CODEC\Desktop\I molest dolphins in the shower.jpg
[2009/07/13 21:55:54 | 00,000,000 | —D | C] – C:\Users\CODEC\AppData\Local\Adobe
[2009/07/12 21:50:41 | 01,207,055 | —- | C] () – C:\Users\CODEC\Desktop\warhammer_b&t_4_014-015.jpg
[2009/07/12 20:32:04 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40,000 - Blood and Thunder
[2009/07/11 02:46:54 | 00,054,791 | —- | C] () – C:\Users\CODEC\Desktop\zakuawesome.jpg
[2009/07/10 13:33:28 | 05,012,956 | —- | C] () – C:\Users\CODEC\Desktop\MajorTom_160.mp3
[2009/07/10 00:39:27 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Top 40 singles Uk 30 11 2008 Plus Bonus DHZ Inc Release
[2009/07/10 00:27:20 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Ministry Of Sound - The Annual [2009]
[2009/07/08 22:34:29 | 01,878,888 | —- | C] (Adobe Systems Incorporated) – C:\Users\CODEC\Desktop\install_flash_player.exe
[2009/07/07 03:06:52 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Star Wars The Clone Wars S1E12-22
[2009/07/06 13:10:40 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Star Wars The Clone Wars S1E1-11
[2009/07/06 12:18:07 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40k Damnation Crusade
[2009/07/06 12:17:35 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Warhammer 40K -Lone Wolves
[2009/06/30 21:45:52 | 00,011,837 | —- | C] () – C:\Users\CODEC\Desktop\mj random cd.nra
[2009/06/29 14:49:13 | 00,000,000 | —D | C] – C:\Users\CODEC\Desktop\Michael Jackson complete Discography
[2009/06/27 01:45:25 | 00,002,425 | —- | C] () – C:\Users\CODEC\Desktop\Forged Alliance.lnk
[2009/06/26 23:06:31 | 04,750,466 | —- | C] () – C:\Users\CODEC\Desktop\Sonic_the_Hedgehog_Metamorphic_Rock_OC_ReMix.mp3
[2009/06/25 18:00:44 | 00,000,000 | —D | C] – C:\Scenario
[2009/06/23 16:25:36 | 00,001,988 | —- | C] () – C:\Users\CODEC\Desktop\Rise of Nations Thrones and Patriots.lnk
[2009/06/23 16:23:24 | 00,000,000 | —D | C] – C:\Users\CODEC\AppData\Roaming\Microsoft Games
[2009/06/23 16:21:30 | 00,000,948 | —- | C] () – C:\Users\CODEC\Desktop\Rise Of Nations.lnk
[2009/06/23 14:19:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\att-prt22
[2009/06/23 14:19:23 | 00,000,000 | —D | C] – C:\ProgramData\Motive
[2009/06/23 14:19:18 | 00,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Motive
[2009/06/23 14:19:16 | 00,000,000 | —D | C] – C:\Program Files (x86)\ATT-PRT22-WISE
[2009/06/22 23:59:47 | 00,001,990 | —- | C] () – C:\Users\Public\Desktop\Rise Of Legends.lnk
[2009/05/26 22:18:10 | 00,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/05/26 22:17:08 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/22 00:19:06 | 00,172,173 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/02/03 20:57:49 | 00,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/10/15 11:58:34 | 00,028,808 | —- | C] () – C:\Windows\SysWow64\drivers\swmsflt.sys
[2008/10/07 09:13:30 | 00,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/09/09 14:15:10 | 00,000,060 | —- | C] () – C:\Windows\entpack.ini
[2008/08/31 16:56:45 | 00,765,952 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2008/08/31 16:56:45 | 00,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2008/08/30 14:15:53 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/08/23 19:34:53 | 00,000,336 | —- | C] () – C:\Windows\game.ini
[2008/08/16 12:01:45 | 00,789,544 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/07/22 22:40:04 | 00,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2008/07/22 22:37:04 | 00,000,044 | —- | C] () – C:\Windows\EPSCX9000F.ini
[2008/01/20 19:49:10 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/07/26 12:01:50 | 00,114,688 | —- | C] () – C:\Windows\SysWow64\hppatusg01.dll
[2006/11/02 05:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 05:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini
[2006/04/30 01:34:04 | 00,049,152 | —- | C] () – C:\Windows\SysWow64\WbxRMenu.dll
[2006/04/14 00:18:24 | 00,196,608 | —- | C] () – C:\Windows\SysWow64\atonres.dll
[2006/04/14 00:18:24 | 00,131,072 | —- | C] () – C:\Windows\SysWow64\WbxMSAI.dll
[2006/04/14 00:18:24 | 00,098,304 | —- | C] () – C:\Windows\SysWow64\atonecli.dll
[1999/01/22 11:46:58 | 00,065,536 | —- | C] () – C:\Windows\SysWow64\MSRTEDIT.DLL
[1997/06/13 19:56:08 | 00,056,832 | —- | C] () – C:\Windows\SysWow64\iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\Users\CODEC\Documents\*.tmp files]
[2009/07/22 15:04:23 | 00,082,171 | —- | M] () – C:\ProgramData\nvModes.001
[2009/07/22 15:04:18 | 00,000,253 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/07/22 15:00:23 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/07/22 15:00:23 | 00,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/07/22 15:00:23 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/07/22 15:00:20 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/07/22 12:39:45 | 00,001,076 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/07/22 12:15:42 | 00,352,680 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2009/07/22 12:03:21 | 02,638,040 | -H– | M] () – C:\Users\CODEC\AppData\Local\IconCache.db
[2009/07/22 11:54:38 | 00,082,171 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/07/21 21:58:55 | 00,015,112 | —- | M] () – C:\ProgramData\LuUninstall.LiveUpdate
[2009/07/21 01:59:02 | 00,001,919 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/07/21 01:58:37 | 06,653,952 | —- | M] () – C:\Users\CODEC\Desktop\AdbeRdrUpd912_all_incr.msp
[2009/07/21 01:53:51 | 26,739,584 | —- | M] ( ) – C:\Users\CODEC\Desktop\AdbeRdr910_en_US.exe
[2009/07/20 17:19:22 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\CODEC\Desktop\OTL.exe
[2009/07/14 18:08:44 | 00,030,005 | —- | M] () – C:\Users\CODEC\Desktop\I molest dolphins in the shower.jpg
[2009/07/11 16:18:25 | 01,878,888 | —- | M] (Adobe Systems Incorporated) – C:\Users\CODEC\Desktop\install_flash_player.exe
[2009/07/11 02:46:54 | 00,054,791 | —- | M] () – C:\Users\CODEC\Desktop\zakuawesome.jpg
[2009/07/10 13:33:38 | 05,012,956 | —- | M] () – C:\Users\CODEC\Desktop\MajorTom_160.mp3
[2009/07/07 15:03:42 | 00,097,792 | —- | M] () – C:\Users\CODEC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/07 08:43:31 | 26,410,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mrt.exe
[2009/06/30 21:45:52 | 00,011,837 | —- | M] () – C:\Users\CODEC\Desktop\mj random cd.nra
[2009/06/27 01:45:25 | 00,002,425 | —- | M] () – C:\Users\CODEC\Desktop\Forged Alliance.lnk
[2009/06/27 01:34:09 | 04,750,466 | —- | M] () – C:\Users\CODEC\Desktop\Sonic_the_Hedgehog_Metamorphic_Rock_OC_ReMix.mp3
[2009/06/23 16:25:37 | 00,001,988 | —- | M] () – C:\Users\CODEC\Desktop\Rise of Nations Thrones and Patriots.lnk
[2009/06/23 16:21:30 | 00,000,948 | —- | M] () – C:\Users\CODEC\Desktop\Rise Of Nations.lnk
[2009/06/23 11:46:39 | 00,089,392 | —- | M] () – C:\Users\CODEC\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/06/22 23:59:47 | 00,001,990 | —- | M] () – C:\Users\Public\Desktop\Rise Of Legends.lnk
< End of report >

OTL Extras logfile created on: 7/22/2009 3:09:17 PM - Run 5
OTL by OldTimer - Version 3.0.9.2 Folder = C:\Users\CODEC\Desktop
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 59.54% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 219.78 Gb Total Space | 50.60 Gb Free Space | 23.02% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 19.34 Gb Free Space | 8.30% Space Free | Partition Type: NTFS
Drive E: | 13.11 Gb Total Space | 2.47 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PORTABLE-G
Current User Name: CODEC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = JSFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.txt[@ = txtfile] – C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] – C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = C2 FE 8D 6A DC 5B C8 01 [binary data]
"VistaSp2" = 14 07 E8 A1 91 DE C9 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F08D2A-548F-4B61-92B8-ED140DA56336}" = rport=10244 | protocol=6 | dir=out | app=system |
"{05F95530-E1A9-4A4F-ABB3-198CB740C84F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{0BC90162-E917-4F22-BD8A-6488C52BF74E}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{14EC0CE2-E760-4165-B361-3D6C4142F61E}" = rport=138 | protocol=17 | dir=out | app=system |
"{21D5DAC4-FDFA-4305-8534-744D437855B7}" = lport=445 | protocol=6 | dir=in | app=system |
"{23FDC079-49A8-4630-82E1-175114536CDF}" = rport=137 | protocol=17 | dir=out | app=system |
"{38B76183-F39F-4A25-9795-E2EAADD2E5E8}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4B51B214-3207-4A96-88FD-6FD7346991ED}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{68EFFD0A-5449-4B4A-A9F9-7BF524D124F4}" = lport=10244 | protocol=6 | dir=in | app=system |
"{6DB50A41-650A-4478-B9F1-4E2D92FD41D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6F5733F6-9BA7-4A20-8A52-3F6AC000D205}" = lport=139 | protocol=6 | dir=in | app=system |
"{791EB5B7-86CE-4C48-A9C8-08B7C18FBAE4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7B00C0F4-E60A-4632-AB5E-E984EEBDC220}" = lport=3390 | protocol=6 | dir=in | app=system |
"{7D0ADA2D-C2D8-4EC5-91C9-09FB37C91AB2}" = rport=445 | protocol=6 | dir=out | app=system |
"{7D80A354-D63A-4644-91B4-1EB84F80468E}" = rport=139 | protocol=6 | dir=out | app=system |
"{7F256B24-349A-42B9-961F-BA965624E122}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{80882A72-EB4E-450F-AA95-2C07C733F1ED}" = lport=137 | protocol=17 | dir=in | app=system |
"{81C266FF-D6B8-43DC-B783-B3D478887C78}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{984D89FD-329C-41C6-99AB-CEFA2A6239FB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9C521D47-F763-4B4D-901C-67397D7A23A7}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{A18532BE-A5CF-4201-AAA3-37E80351DBAE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2DCE109-3B59-41C9-B39D-A67B57C3CDD2}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B38C91B9-A897-4340-A871-6DB8302E8829}" = rport=10244 | protocol=6 | dir=out | app=system |
"{C0D5DF60-1CB2-4E77-B249-63B5A1061072}" = lport=138 | protocol=17 | dir=in | app=system |
"{C67C0D59-215D-4E72-81AD-C7E6D7BFF8C1}" = lport=3390 | protocol=6 | dir=in | app=system |
"{D154506C-C865-43B4-AF88-2C49DD5512CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D382CCB9-2A84-4833-8CF0-9BD0370224CC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E8C8DF2F-FC7A-4C1A-8ACD-2EE97FB769E7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F688A7D9-1E57-4DA0-BD56-77E698453B4A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA141D02-1363-4398-850E-B1CB1277ADEB}" = lport=10244 | protocol=6 | dir=in | app=system |
"{FB436E38-9CBC-4B8A-AB7A-C3F493B24F5A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FE37AA13-AD05-4400-A22A-16ED557EF95F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{008A4D69-9D21-4AD0-8048-E7E62C737543}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{04ED0249-72DA-4D1A-BAA0-3CFF26541D15}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{089C188C-CBB6-44DE-B895-588E650ECA82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe |
"{0AD5A9D3-A85C-405C-903B-DE7CD9469BE7}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{0D0C6E6D-9859-490D-9BB0-6F76B363A849}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{0F5775E8-18FC-48DA-B4A8-392602D103E5}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{129FAA59-C39C-4EDF-A049-AC078D684FD2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{13320DB1-EF44-4B6D-8AE4-FB55A54FD89E}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{13CC58D9-33FE-4427-BB31-DB33D19CBB2E}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\symantec shared\ccapp.exe |
"{1493BA12-6201-47E2-9CB7-CC28F05BA237}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{1BD2C1FB-B7D0-4DFB-AA65-091B732CFE31}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40kwa.exe |
"{1C7F4043-0253-4C96-A128-8AF0E56A1F75}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\smc.exe |
"{1EAE0103-4144-4925-9827-742BA799E18A}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\symantec shared\ccapp.exe |
"{2636755A-902D-4605-8EC2-B9077D76F011}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{2C510222-BA86-4E6D-AAA0-40D87C490C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\smc.exe |
"{3005A6F4-12E8-4CBD-B08D-BBB795665B39}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{326D808E-3B8A-4946-BC09-3598EC12EB83}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{33C034F5-B8F1-4F10-89DA-6898B076B36D}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{342A9E1E-CBD5-4CF2-8973-4FE8340C24F5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3FF8991A-CC89-4739-A025-D2ED9EE5D46E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{47F5DEA0-A201-437B-866B-825E6904F3C2}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{4BD54462-57BC-44CB-880A-D66DD7E1986A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40kwa.exe |
"{4EC0C756-C6B8-4782-8159-023E0C6C0E00}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{4F5CF9D3-BEDF-4DFA-BFFE-8CA04CB8DB33}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{55AA4FCA-B22C-4A58-B2B9-A694363B9A85}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe |
"{5A2A5AAB-10BD-4624-8749-2C7AA1E3B7F1}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{6847D6FB-9E7B-4158-A46B-0B2716812D57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war dark crusade\darkcrusade.exe |
"{6B75E66A-1C4B-4485-BB33-5134AA013617}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6C67B824-EE33-462F-B4CF-19B1ABA05AFD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{6DFA1038-225B-4F77-ABBF-247914898AF2}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{711BBB19-5E08-4BC6-A847-FC23E0880E35}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{81635AD4-5953-4BB7-9E5F-1CE847184588}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{82445A69-FE2B-43A3-886E-CF53EBABD72C}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{831C8631-A7E2-467F-95DD-3504B2B77D5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{864B71F8-5CA8-477A-BAF8-407A5B5EF723}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceempiresv\se5\se5.exe |
"{89ECFE29-5971-4345-BA2B-7B1F48C7CE74}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{957AC5E3-24B8-47EB-AC8E-909CA6FA1EB8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96BF49FB-D8FF-497E-9238-3121F8421502}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\manager.exe |
"{9A8D9EFA-805D-4EDF-A134-D02CADABB206}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{9DB9AB1F-C89F-4190-9DDD-38B64AE5AE3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe |
"{A0A28924-4D5A-4647-9069-290665C43406}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{A0A4D238-58F2-4810-811C-F812FC591145}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{A56B9FF2-643B-4C0E-85DC-AB7F33AAF041}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{A766C4D8-083F-4F5B-A674-F51B6585AB95}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{AC31A460-88A6-4542-8C1A-262BB3B2B9D8}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander - forged alliance\bin\forgedalliance.exe |
"{B26734E8-FE8C-40B6-9208-D8CC9E6CBA33}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{B5A7CE3D-7C25-44D0-9F52-FE65B4E7EE48}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B895492E-FAA1-4DBD-BF6C-E800165812C1}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{BA7450A5-355A-476B-8F57-905E992114BF}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{BA787A0D-31E8-4614-B543-C1F96B51B499}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{BB037E5D-278B-49BA-A48B-F6CA1455E3D3}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{BBADEFD6-F43C-4707-82B3-E862C45C25A9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{BC7C03AC-6E02-48A8-8C2D-F4D58BEDD41B}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{C0041FAA-D980-4728-A0F4-A556C3A25398}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{C2C7FB1B-1004-47D9-BB47-06DBC9DDB584}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C2F0E36C-BD11-46AF-B80C-490752D297E1}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{C3EE8E3B-7ED5-4C3A-9C13-920E46386789}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\snac64.exe |
"{C54CEB72-31E2-4AA0-9FB9-ED6F45770F4E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\hp1006mc.exe |
"{CB3145F5-9623-41B1-9830-5FF912C1AFB2}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{D125FC29-D05E-49CE-A9F6-9C11FDFBD965}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{D1DBA2CC-DD18-4B92-9CA8-445D4D3EAD97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe |
"{D55F1728-ED30-4EA6-8218-B87463A50C5A}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{D76452A3-3EB2-4A12-942A-89086D29DCCA}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{D9356147-08A9-4EE9-95A0-2FD5D466FE57}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war gold\w40k.exe |
"{D9426C56-399C-490E-9B52-48075EFBEE23}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceempiresv\se5\se5.exe |
"{DAA9207F-92FF-418B-841A-84791B922E6A}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\snac64.exe |
"{DCDC4CF4-9506-4724-803E-475280F8BDCD}" = protocol=6 | dir=in | app=c:\program files (x86)\autodesk\backburner\server.exe |
"{DD470243-A844-4BF8-A705-24CA437C0200}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\bulletbarrage\space empires iv deluxe\se4\se4.exe |
"{E5D522D0-BF36-46F2-B728-3E74BAC45A16}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{EE322945-5371-49F6-886A-412A6B4F1582}" = protocol=17 | dir=in | app=c:\program files (x86)\autodesk\backburner\monitor.exe |
"{EE7F9411-4D08-458B-9742-08BFD2AF84D9}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{F07920C9-B740-4D6D-9FF5-49EED95D9846}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{F3D72A2B-0E40-4891-8B5E-A28AF98B3481}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\gas powered games\supreme commander - forged alliance\bin\forgedalliance.exe |
"{F4629845-AF27-4801-BBDF-86BAEAFC3F42}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{FAD66503-0961-48DF-B14A-A74E3C448143}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\bulletbarrage\space empires iv deluxe\se4\se4.exe |
"{FBA3E2C1-1DB5-4A65-9BFB-8ADC48D5FC5D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{FDD5C893-4077-44B8-A40F-7BBF153CFED6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FF9A129D-F7C9-49EF-9AC5-34D87E41723D}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\hp1006mc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E6C415F-7708-4A8F-9509-11C98988BDCA}" = Apple Mobile Device Support
"{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{43602F34-1AA3-44FB-AEB2-D08C2C737440}" = Paint.NET v3.36
"{5AB0C6D3-E546-44C2-8B63-C9044FCC9AC0}" = iTunes
"{8A837C47-2B21-4FDF-8370-41A1EB6A26E8}" = Microsoft Xbox 360 Accessories 1.1
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"EPSON Printer and Utilities" = EPSON Printer Software
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"SMSERIAL" = Motorola SM56 Data Fax Modem
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UltSounds" = Windows Sound Schemes
"UltSounds2" = Ultimate Extras sounds from Microsoft® Tinker™

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{02C85EC5-E864-4847-AF55-42730861004C}" = MrvlUsgTracking
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2D8ECB5E-9F6C-4332-AEE6-0E4EE1DEC926}" = Maya 8.5 Personal Learning Edition
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2008.1
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A829DA3-E377-4BC0-938F-F453C6BB3F67}" = Maya 8.5 Personal Learning Edition Documentation (en_US)
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C8B5E63-821A-4DFB-BDFA-19854D88EC5C}" = 3dsmax ancillary install
"{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088
"{86C7336D-0E3A-4953-ADF4-F4B5E0096278}" = Command & Conquer 3 Tiberium Wars™ MOD SDK
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E72B982-D54F-486F-B35A-C24B6F171033}" = Nero 7 Essentials
"{8ED6D4D2-6B9F-4B0E-A1AE-A94C20256BC4}" = Lords of the Realm 2
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C194D333-B84A-4BB7-B35E-060732D98DC4}" = GPGNet
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{D3A04D2F-28C4-4D9C-8487-DAB75992AE09}" = AIM Pro
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E583ED6F-BD99-4066-A420-C815BF692B69}" = Macromedia Fireworks MX 2004
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F6A3F605-7B10-4939-8D3D-4594332C1649}" = Red Alert 3 Mod SDK
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"ATT-PRT22" = ATT-PRT22
"Autodesk FBX Plugin 2009.4 - 3ds Max 2010" = Autodesk FBX Plugin 2009.4 - 3ds Max 2010
"avast!" = avast! Antivirus
"AviSynth" = AviSynth 2.5
"CdaC13Ba" = SafeCast Shared Components
"CDisplay_is1" = CDisplay 1.8
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"EADM" = EA Download Manager
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0032)
"Fallout 2_is1" = Fallout 2
"Fallout Mod Manager_is1" = Fallout Mod Manager 0.9.9
"FBX Plugin 2006.08 for Max 9.0" = FBX Plugin 2006.08 for Max 9.0
"FL Studio 7" = FL Studio 7
"GENS" = GENS
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP LaserJet P1000 series" = HP LaserJet P1000 series
"HP Smart Web Printing" = HP Smart Web Printing
"IL Download Manager" = IL Download Manager
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mideast Crisis 2" = Mideast Crisis 2
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"OpenAL" = OpenAL
"PowerISO" = PowerISO
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RiseOfNations 1.0" = Microsoft Rise Of Nations
"RiseofNationsExpansion 1.0" = Rise of Nations Thrones and Patriots
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Spring" = Spring 0.78.2.1
"Steam App 1610" = Space Empires IV Deluxe
"Steam App 1690" = Space Empires V
"Steam App 220" = Half-Life 2
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 400" = Portal
"Steam App 440" = Team Fortress 2
"Steam App 4570" = Dawn of War Gold
"Steam App 4580" = Dawn of War: Dark Crusade
"Steam App 500" = Left 4 Dead
"Steam App 70" = Half-Life
"Steam App 9450" = Dawn of War: Soulstorm
"SystemRequirementsLab" = System Requirements Lab
"Videora iPod touch Converter" = Videora iPod touch Converter 4.07
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6i
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{25A1E6A4-2DBD-4AC0-8650-8EA9A45B183D}" = Supreme Commander
"{31D95937-B237-405D-920C-A3EF4E482395}" = Supreme Commander - Forged Alliance
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 7/16/2009 3:13:11 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Ahead\NERO HOME\is2.db failed, 00000005.

Error - 7/19/2009 2:26:47 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/21/2009 2:00:51 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\ProgramData\Symantec\Common Client\settings.dat failed, 00000005.

Error - 7/21/2009 2:29:20 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
failed, 00000005.

Error - 7/21/2009 2:38:10 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\ProgramData\Symantec\Common Client\settings.dat failed, 00000005.

Error - 7/21/2009 2:38:10 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll failed,
00000005.

Error - 7/21/2009 2:46:45 PM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat failed,
00000005.

Error - 7/22/2009 12:35:00 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\ProgramData\Symantec\LIVEUPDATE\Settings.LiveUpdate failed, 00000005.

Error - 7/22/2009 12:58:59 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Local\Temp\hsperfdata_CODEC\4616 failed, 00000005.

Error - 7/22/2009 12:59:07 AM | Computer Name = Portable-G | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\CODEC\AppData\Roaming\Microsoft\Windows\Cookies\index.dat failed, 00000005.


[ Application Events ]
Error - 7/21/2009 4:07:42 AM | Computer Name = Portable-G | Source = SescLU | ID = 13
Description =

Error - 7/21/2009 5:46:38 AM | Computer Name = Portable-G | Source = Application Error | ID = 1000
Description = Faulting application OTL.exe, version 3.0.9.2, time stamp 0x2a425e19,
faulting module user32.dll, version 6.0.6002.18005, time stamp 0x49e03825, exception
code 0xc0000005, fault offset 0x00018293, process id 0xf38, application start time
0x01ca09e01ddfffc0.

Error - 7/21/2009 2:16:18 PM | Computer Name = Portable-G | Source = Application Error | ID = 1000
Description = Faulting application OTL.exe, version 3.0.9.2, time stamp 0x2a425e19,
faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03824, exception
code 0xc0000005, fault offset 0x0004e252, process id 0x1934, application start time
0x01ca0a2d27f94c80.

Error - 7/21/2009 2:31:40 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/21/2009 2:50:01 PM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

Error - 7/21/2009 3:10:43 PM | Computer Name = Portable-G | Source = Windows Search Service | ID = 3013
Description =

Error - 7/21/2009 3:15:07 PM | Computer Name = Portable-G | Source = Windows Search Service | ID = 3013
Description =

Error - 7/21/2009 3:15:07 PM | Computer Name = Portable-G | Source = Windows Search Service | ID = 3013
Description =

Error - 7/22/2009 12:31:34 AM | Computer Name = Portable-G | Source = Application Error | ID = 1000
Description = Faulting application ProtectionUtilSurrogate.exe, version 11.0.2000.1253,
time stamp 0x47f6d566, faulting module ole32.dll, version 6.0.6002.18005, time
stamp 0x49e037d7, exception code 0xc0000005, fault offset 0x0004b1bd, process id
0x103c, application start time 0x01ca0a340086e89e.

Error - 7/22/2009 1:02:01 AM | Computer Name = Portable-G | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 7/22/2009 2:53:56 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/22/2009 2:53:56 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =

Error - 7/22/2009 2:54:16 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7009
Description =

Error - 7/22/2009 2:54:16 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =

Error - 7/22/2009 3:15:49 PM | Computer Name = Portable-G | Source = Application Popup | ID = 1060
Description = \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 7/22/2009 3:16:48 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/22/2009 3:16:48 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =

Error - 7/22/2009 6:00:24 PM | Computer Name = Portable-G | Source = Application Popup | ID = 1060
Description = \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 7/22/2009 6:01:40 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7023
Description =

Error - 7/22/2009 6:01:40 PM | Computer Name = Portable-G | Source = Service Control Manager | ID = 7000
Description =


< End of report >

Every time I get to my desktop after logging in, it says Windows Defender can't start. I've updated it but still not sure about it. Anyway, it all seems fine, no lag or anything, but those other two groups with the special permissions and stuff still worry me.
Thanks for the help!

Anyway, it all seems fine, no lag or anything, but those other two groups with the special permissions and stuff still worry me.

As I said, those desktop.ini files are probably harmless. However, if they bother you then delete them :)

Every time I get to my desktop after logging in, it says Windows Defender can't start.

Does it give any specific error message? Are you able to start Windows Defender thru control panel?
The error says: "Application failed to initialize: 0x800106ba. A problem caused this program's service to stop. To start the service, restart your computer or search Help and Support for how to start a service manually."
Hi,

Press window button+R to open run box. Write services.msc and click ok.

Double click Windows Defender service and check that its startup type is automatic and that service is started. Change the startup type and start the service if needed.

Do you still get the error after reboot?
Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

A To disable the System Restore feature:

1. Click on the Start button.
2. Hover over the Computer option, right click on it and then click Properties.
3. On the left hand side, click Advanced Settings.
4. If asked to permit the action, click on Allow.
5. Click on the System Protection tab.
6. Uncheck any checkboxes listed for your hard drives.
7. Press OK.


B. Reboot.

C Turn ON System Restore.
Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.

Let's uninstall OTL.
  • Double-click OTL.exe.
  • Click the CleanUp! button.
  • Select Yes when the
    Begin cleanup Process?
    prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • hosts file:
  • Every version of windows has a hosts file as part of them.
  • In a very basic sense, they are used to locate webpages.
  • We can customize a hosts file so that it blocks certain webpages.
  • However, it can slow down certain computers.
  • This is why using a hosts file is optional!!
Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
  • Click the start button (at the lower left hand corner of your screen)
  • Click run
  • In the dialog box, type services.msc
  • hit enter, then locate dns client
  • Highlight it, then double-click it.
  • On the dropdown box, change the setting from automatic to manual.
  • Click ok


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system… problems etc.

Have a great day,
Blade B)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI