This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Can't open programs normally

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! I'm so sorry, I had posted a while back trying to get my problem fixed here, but my fiance "took over" and tried fixing my problems by installing Norton 360 (version 3.0) and then problems got even worse. Now it doesn't seem that I have the supposed "antivirus" pop up, but for some reason, any time I try to run a program by double clicking the icon, or even clicking the option in my start menu, it pops up asking which program I want to open the .exe file in. I thought I wasn't going to be able to do ANYTHING but later realized that I can run a program by right clicking the icon, and it has 3 options at the top of the menu: "open", "run as", and "start" and I can get the programs to run by choosing start.

But now, I'm having more problems, because nothing else will run properly. For one, my World of Warcraft will not update. For two, I have Adobe Acrobat Distiller so that I can print to a PDF file, but when I try to print to a pdf from firefox or internet explorer (instead of wasting paper and ink), the "which program do you want to run this from" thing pops up again. And I can't figure out what to choose to make it work.

Norton 360 has supposedly been catching a lot of stuff according to its log, but…I just don't know.

Can this be fixed without me having to reformat my computer? I can not afford to lose programs that I have on it because I have no idea where the original program discs are. Please help! And this time I will not let my fiance interfere!

Here is my hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:45:33 PM, on 3/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thottbot.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://update.microsoft.com/microsoftupdate
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Celebrity Toolbar\tbhelper.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Celebrity Toolbar\tbcore3.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Celebrity Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Celebrity Toolbar\tbcore3.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://software-dl.real.com/01b0a56a42b912…ne_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1266350072375
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} - http://phughescw.hughes.motive.com/wizlet/…/Mcci_6-1-0.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/astropo…aploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://linksyssupport.webex.com/client/T26…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A63351D3-F6CC-483E-AFC2-396ABD641DED}: NameServer = 93.188.162.95,93.188.161.78
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.162.95,93.188.161.78
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.162.95,93.188.161.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.95,93.188.161.78
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1caa52fa3a86ad0) (gupdate1caa52fa3a86ad0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12290 bytes
Ok, here is my GMER log…when I clicked save, it said that I could not save it to desktop, or my documents or anywhere, so I copied it and pasted it.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-26 21:00:28
Windows 5.1.2600 Service Pack 3
Running: q1t1qs1x.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uftyyfow.sys


—- System - GMER 1.0.15 —-

SSDT 85B14710 ZwAlertResumeThread
SSDT 85B176D8 ZwAlertThread
SSDT 85B24700 ZwAllocateVirtualMemory
SSDT 85B046D0 ZwAssignProcessToJobObject
SSDT 8634F120 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xF40F9130]
SSDT 85B0F700 ZwCreateMutant
SSDT 85AFE700 ZwCreateSymbolicLinkObject
SSDT 85BC36F0 ZwCreateThread
SSDT 85B066D0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xF40F93B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF40F9910]
SSDT 85B28700 ZwDuplicateObject
SSDT 85B20700 ZwFreeVirtualMemory
SSDT 85B11710 ZwImpersonateAnonymousToken
SSDT 85B146D8 ZwImpersonateThread
SSDT 863F4F00 ZwLoadDriver
SSDT 86223228 ZwMapViewOfSection
SSDT 85B116D8 ZwOpenEvent
SSDT 85B2C700 ZwOpenProcess
SSDT 85B26710 ZwOpenProcessToken
SSDT 85B0C6D8 ZwOpenSection
SSDT 85B2A700 ZwOpenThread
SSDT 85B01700 ZwProtectVirtualMemory
SSDT 861A87E0 ZwResumeThread
SSDT 85B1A710 ZwSetContextThread
SSDT 85B1C700 ZwSetInformationProcess
SSDT 85B086D0 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF40F9B60]
SSDT 85B0C710 ZwSuspendProcess
SSDT 85B17710 ZwSuspendThread
SSDT 855A3748 ZwTerminateProcess
SSDT 85B1A6D8 ZwTerminateThread
SSDT 85B266D8 ZwUnmapViewOfSection
SSDT 85B22700 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
—- Processes - GMER 1.0.15 —-

Library C:\Documents and Settings\Owner\My Documents\Downloads\q1t1qs1x.exe (*** hidden *** ) @ C:\Documents and Settings\Owner\My Documents\Downloads\q1t1qs1x.exe [4000] 0x00400000

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths
Reg HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@DisplayNameFile %SystemRoot%\System32\els.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@DisplayNameID 257
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@File %SystemRoot%\System32\config\SecEvent.Evt
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@MaxSize 524288
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@PrimaryModule Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@Retention 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@Sources Spooler?ServiceModel 3.0.0.0?Security Account Manager?SC Manager?NetDDE Object?LSA?DS?Security?
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security@RestrictGuestAccess 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\DS\ObjectNames@Directory Service Object 7680
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@PolicyObject 5632
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@SecretObject 5648
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@TrustedDomainObject 5664
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\LSA\ObjectNames@UserAccountObject 5680
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\NetDDE Object\ObjectNames@DDE Share 7424
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames@SC_MANAGER Object 7168
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\SC Manager\ObjectNames@SERVICE Object 7184
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@CategoryCount 9
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@CategoryMessageFile %SystemRoot%\System32\MsAuditE.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@GuidMessageFile %SystemRoot%\System32\NtMarta.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@EventMessageFile %SystemRoot%\System32\MsAuditE.dll;%SystemRoot%\System32\xpsp2res.dll;%SystemRoot%\System32\xpsp3res.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security@TypesSupported 28
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Channel 5120
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Desktop 6672
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Device 4352
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Directory 4368
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Event 4384
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@EventPair 4400
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@File 4416
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@IoCompletion 4864
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Job 5136
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Key 4432
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@MailSlot 4416
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Mutant 4448
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@NamedPipe 4416
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Port 4464
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Process 4480
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Profile 4496
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Section 4512
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Semaphore 4528
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@SymbolicLink 4544
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Thread 4560
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Timer 4576
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Token 4592
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@Type 4608
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@WaitablePort 4464
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security\ObjectNames@WindowStation 6656
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_ALIAS 5424
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_DOMAIN 5392
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_GROUP 5408
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_SERVER 5376
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_USER 5440
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventMessageFile c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@TypesSupported 31
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@ParameterMessageFile c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryCount 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventSourceFlags 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryMessageFile %SystemRoot%\System32\MsAuditE.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Document 6944
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Printer 6928
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Security\Spooler\ObjectNames@Server 6912
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Library C:\WINDOWS\system32\wbem\wmiaprpl.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Open WmiOpenPerfData
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Collect WmiCollectPerfData
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Close WmiClosePerfData
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Last Counter 7492
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Last Help 7493
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@First Counter 7480
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@First Help 7481
Reg HKLM\SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance@Object List 7480 7486
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg@Description Registry Server
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg\AllowedPaths (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\SecurePipeServers\winreg\AllowedPaths@Machine System\CurrentControlSet\Control\ProductOptions?System\CurrentControlSet\Control\Print\Printers?System\CurrentControlSet\Control\Server Applications?System\CurrentControlSet\Services\Eventlog?Software\Microsoft\OLAP Server?Software\Microsoft\Windows NT\CurrentVersion?System\CurrentControlSet\Control\ContentIndex?System\CurrentControlSet\Control\Terminal Server?System\CurrentControlSet\Control\Terminal Server\UserConfig?System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration?
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@DisplayNameFile %SystemRoot%\System32\els.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@DisplayNameID 257
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@File %SystemRoot%\System32\config\SecEvent.Evt
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@MaxSize 524288
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@PrimaryModule Security
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@Retention 0
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@Sources Spooler?ServiceModel 3.0.0.0?Security Account Manager?SC Manager?NetDDE Object?LSA?DS?Security?
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security@RestrictGuestAccess 1
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\DS (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\DS@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\DS\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\DS\ObjectNames@Directory Service Object 7680
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA\ObjectNames@PolicyObject 5632
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA\ObjectNames@SecretObject 5648
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA\ObjectNames@TrustedDomainObject 5664
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\LSA\ObjectNames@UserAccountObject 5680
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\NetDDE Object (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\NetDDE Object@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\NetDDE Object\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\NetDDE Object\ObjectNames@DDE Share 7424
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\SC Manager (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\SC Manager@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\SC Manager\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\SC Manager\ObjectNames@SC_MANAGER Object 7168
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\SC Manager\ObjectNames@SERVICE Object 7184
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@CategoryCount 9
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@CategoryMessageFile %SystemRoot%\System32\MsAuditE.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@GuidMessageFile %SystemRoot%\System32\NtMarta.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@EventMessageFile %SystemRoot%\System32\MsAuditE.dll;%SystemRoot%\System32\xpsp2res.dll;%SystemRoot%\System32\xpsp3res.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security@TypesSupported 28
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Channel 5120
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Desktop 6672
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Device 4352
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Directory 4368
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Event 4384
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@EventPair 4400
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@File 4416
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@IoCompletion 4864
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Job 5136
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Key 4432
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@MailSlot 4416
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Mutant 4448
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@NamedPipe 4416
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Port 4464
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Process 4480
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Profile 4496
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Section 4512
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Semaphore 4528
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@SymbolicLink 4544
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Thread 4560
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Timer 4576
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Token 4592
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@Type 4608
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@WaitablePort 4464
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security\ObjectNames@WindowStation 6656
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_ALIAS 5424
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_DOMAIN 5392
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_GROUP 5408
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_SERVER 5376
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Security Account Manager\ObjectNames@SAM_USER 5440
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventMessageFile c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@TypesSupported 31
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@ParameterMessageFile c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll.mui
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryCount 3
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@EventSourceFlags 1
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\ServiceModel 3.0.0.0@CategoryMessageFile %SystemRoot%\System32\MsAuditE.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler@ParameterMessageFile %SystemRoot%\System32\MsObjs.dll
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler\ObjectNames (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler\ObjectNames@Document 6944
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler\ObjectNames@Printer 6928
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Security\Spooler\ObjectNames@Server 6912
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Library C:\WINDOWS\system32\wbem\wmiaprpl.dll
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Open WmiOpenPerfData
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Collect WmiCollectPerfData
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Close WmiClosePerfData
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Last Counter 7492
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Last Help 7493
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@First Counter 7480
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@First Help 7481
Reg HKLM\SYSTEM\ControlSet002\Services\WmiApRpl\Performance@Object List 7480 7486
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Wdf@
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogEnable 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogKd 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogFlags 16777215
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogLevel 3
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@HostFailKdDebugBreak 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@DefaultHostProcessGUID {193a1820-d9ac-4997-8c55-be817523f6aa}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@NumDeviceStacksMax 3
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogFlushPeriodSeconds 300
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF@LogMinidumpType 288
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services@
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}@HostProcessImagePath C:\WINDOWS\System32\wudfhost.exe
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services\{193a1820-d9ac-4997-8c55-be817523f6aa}@HostProcessDbgBreakOnStart 0

—- EOF - GMER 1.0.15 —-



When I ran OTL as instructed, it scanned for a bit and then said: "Directory Does Not Exist" and wouldn't do anything after I clicked OK.
Ok, I ran it and at the bottom it said "Scan complete!" the notepads did not pop up, but I did find them where OTL was saved. Here is what I got:

File named OTL:

OTL logfile created on: 3/27/2010 6:35:44 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 500.00 Mb Available Physical Memory | 49.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 265.98 Gb Free Space | 71.38% Space Free | Partition Type: NTFS
Drive D: | 200.01 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADMIN-AEF638EE6
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe (Adobe Systems Incorporated)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\3.8.0.41\asOEHook.dll (Symantec Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Ventrilo) – File not found
SRV - (N360) – C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (AdobeVersionCue) – C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe (Adobe Sytems)


========== Driver Services (SafeList) ==========

DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0308000.029\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0308000.029\SRTSP.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0308000.029\SRTSPX.SYS (Symantec Corporation)
DRV - (SymIMMP) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\System32\Drivers\N360\0308000.029\ccHPx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\WINDOWS\System32\Drivers\N360\0308000.029\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100326.019\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100326.019\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys (Symantec Corporation)
DRV - (npkcrypt) – C:\Nexon\MapleStory\npkcrypt.sys (INCA Internet Co., Ltd.)
DRV - (USB_RNDIS) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Alpham1) – C:\WINDOWS\system32\drivers\Alpham1.sys (Ideazon Corporation)
DRV - (Alpham2) – C:\WINDOWS\system32\drivers\Alpham2.sys (Ideazon Corporation)
DRV - (PRISM) – C:\WINDOWS\system32\drivers\PRISMNDS.sys (GlobespanVirata, Inc.)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (ADIHdAudAddService) – C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (Alpham) – C:\WINDOWS\system32\drivers\Alpham.sys (Ideazon Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://thottbot.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 29 12 8C 2C A5 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Celebrity Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-msgr&p;="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB}:1.0.3
FF - prefs.js..extensions.enabledItems: {2104C0F5-952D-443c-AFCD-8F892F991F55}:2.0.0.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {fa8cb1bd-1442-439c-8225-b8b16983d9b7}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..keyword.URL: "http://search.myheritage.com/?orig=ds&q;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/03/27 18:30:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/22 17:51:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/22 17:51:43 | 000,000,000 | —D | M]

[2010/01/19 08:43:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/06/22 02:20:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/03/26 22:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\extensions
[2009/10/12 19:41:15 | 000,000,000 | —D | M] (Charter Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\extensions\{2104C0F5-952D-443c-AFCD-8F892F991F55}
[2007/10/18 23:01:54 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/10/12 19:41:14 | 000,000,000 | —D | M] (Charter Update) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\extensions\{fa8cb1bd-1442-439c-8225-b8b16983d9b7}
[2009/12/31 21:28:18 | 000,000,681 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\searchplugins\ask.xml
[2010/01/28 20:18:26 | 000,002,171 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\searchplugins\bing.xml
[2008/12/12 13:23:54 | 000,002,158 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6sy4bjku.default\searchplugins\MySpace.xml
[2010/03/27 18:30:30 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/07 09:35:31 | 000,000,000 | —D | M] (Celebrity Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
[2009/07/11 20:57:56 | 000,239,432 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010/02/07 09:35:27 | 000,003,803 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\MyHeritage.xml

O1 HOSTS File: ([2003/03/31 10:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Celebrity Toolbar\tbcore3.dll ()
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Celebrity Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Celebrity Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Celebrity Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Celebrity Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} http://software-dl.real.com/01b0a56a42b912…ne_Inst_Win.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1266350072375 (WUWebControl Class)
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab (PlayerOCX Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} http://www.linksysfix.com/netcheck/67/install/gtdownls.cab (LinkSys Content Update)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} http://phughescw.hughes.motive.com/wizlet/…/Mcci_6-1-0.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://chill.comcast.net/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://games.pogo.com/online2/pogo/astropo…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://linksyssupport.webex.com/client/T26…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.0.41\CoIEPlg.dll (Symantec Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/18 16:13:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1998/04/14 11:24:55 | 000,000,000 | R–D | M] - D:\AUTORUN – [ CDFS ]
O32 - AutoRun File - [1998/04/04 05:35:53 | 000,000,063 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\ave.exe" /START "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/03/26 22:40:49 | 000,000,000 | —D | C] – C:\Program Files\3DO
[2010/03/18 20:47:50 | 000,000,000 | —D | C] – C:\Avenger
[2010/03/17 20:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Facebook
[2010/03/11 01:01:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Symantec
[2010/03/10 22:29:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\N360_BACKUP
[2010/03/10 18:59:15 | 000,217,136 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symtdi.sys
[2010/03/10 18:59:14 | 000,482,432 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\cchpx86.sys
[2010/03/10 18:59:14 | 000,310,320 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.sys
[2010/03/10 18:59:14 | 000,308,272 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.sys
[2010/03/10 18:59:14 | 000,259,632 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.sys
[2010/03/10 18:59:14 | 000,089,904 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symfw.sys
[2010/03/10 18:59:14 | 000,048,688 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symndisv.sys
[2010/03/10 18:59:14 | 000,043,696 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.sys
[2010/03/10 18:59:14 | 000,036,400 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symndis.sys
[2010/03/10 18:59:14 | 000,033,072 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symids.sys
[2010/03/10 18:58:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0308000.029
[2010/03/10 18:23:16 | 000,036,400 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2010/03/10 18:23:10 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/03/10 18:23:10 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/03/10 18:23:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/03/10 18:23:10 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/03/10 18:22:39 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2010/03/10 18:22:37 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/03/10 18:22:37 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/03/10 18:22:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2010/03/10 18:21:33 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2010/03/10 18:21:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/03/06 12:33:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\NCSoft
[2010/03/05 20:53:11 | 000,000,000 | —D | C] – C:\Program Files\City of Heroes
[2010/03/02 21:59:44 | 000,000,000 | —D | C] – C:\Program Files\Guild Wars
[2010/02/25 22:42:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\WordWeb
[2010/02/11 18:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2010/02/04 18:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/03 19:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/01/20 00:16:35 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/10/31 23:33:05 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/06 03:13:14 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/12/18 16:19:47 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/09/24 01:49:16 | 000,012,288 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
[5 C:\Documents and Settings\Owner\*.tmp files -> C:\Documents and Settings\Owner\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/03/27 18:30:51 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/27 18:30:21 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/27 18:30:16 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/27 18:30:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/27 18:30:08 | 1073,074,176 | -HS- | M] () – C:\hiberfil.sys
[2010/03/26 23:30:49 | 005,505,024 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/03/26 23:30:49 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/03/26 23:30:42 | 001,579,590 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/03/26 22:49:39 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Might and Magic® VI.lnk
[2010/03/26 22:43:29 | 000,001,675 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Might and Magic® VII.lnk
[2010/03/26 22:43:04 | 102,567,607 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Warcraft3_Demo.zip
[2010/03/26 22:43:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/26 22:06:10 | 000,000,805 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/03/25 07:46:17 | 000,001,819 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/03/19 16:23:33 | 000,014,776 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\6pnFj01o
[2010/03/19 16:23:32 | 000,014,776 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\6pnFj01o
[2010/03/19 16:23:31 | 000,081,191 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/03/17 20:35:04 | 000,144,640 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/14 22:25:30 | 000,444,358 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/14 22:25:30 | 000,072,108 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/14 22:25:26 | 000,525,946 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/11 07:09:37 | 000,563,102 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\Cat.DB
[2010/03/11 07:09:16 | 000,001,906 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/03/11 07:08:50 | 000,586,640 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/10 18:58:37 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\isolate.ini
[2010/03/10 18:23:10 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/03/10 18:23:10 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/03/10 18:23:10 | 000,007,456 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/03/10 18:23:10 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/03/10 18:23:04 | 000,310,320 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.sys
[2010/03/10 18:23:04 | 000,308,272 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.sys
[2010/03/10 18:23:04 | 000,217,136 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symtdi.sys
[2010/03/10 18:23:04 | 000,089,904 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symfw.sys
[2010/03/10 18:23:04 | 000,048,688 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symndisv.sys
[2010/03/10 18:23:04 | 000,043,696 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.sys
[2010/03/10 18:23:04 | 000,036,400 | R— | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SymIM.sys
[2010/03/10 18:23:04 | 000,036,400 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symndis.sys
[2010/03/10 18:23:04 | 000,033,072 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\symids.sys
[2010/03/10 18:23:03 | 000,482,432 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\cchpx86.sys
[2010/03/10 18:23:03 | 000,259,632 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.sys
[2010/03/10 18:22:54 | 000,107,368 | R— | M] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/03/10 18:22:45 | 000,003,373 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.inf
[2010/03/10 18:22:45 | 000,001,752 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\ccHPx86.inf
[2010/03/10 18:22:45 | 000,001,562 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNetV.inf
[2010/03/10 18:22:45 | 000,001,561 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNet.inf
[2010/03/10 18:22:45 | 000,001,388 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.inf
[2010/03/10 18:22:45 | 000,001,382 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.inf
[2010/03/10 18:22:45 | 000,000,640 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.inf
[2010/03/10 18:22:39 | 000,009,412 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\symnetv.cat
[2010/03/10 18:22:39 | 000,009,402 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNet.cat
[2010/03/10 18:22:39 | 000,007,431 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.cat
[2010/03/10 18:22:39 | 000,007,429 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.cat
[2010/03/10 18:22:39 | 000,007,425 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.cat
[2010/03/10 18:22:39 | 000,007,400 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.CAT
[2010/03/10 18:22:39 | 000,007,383 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0308000.029\ccHPx86.cat
[2010/03/10 18:09:39 | 000,012,638 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Pj2f4roAv7
[2010/03/09 22:07:43 | 000,106,271 | —- | M] () – C:\Documents and Settings\Owner\Desktop\annoyingprompt.jpg
[2010/03/09 21:58:46 | 000,420,819 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Unauthorizedscan.jpg
[2010/03/09 21:57:59 | 000,244,550 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Prompt.jpg
[2010/03/05 20:53:13 | 000,001,626 | —- | M] () – C:\Documents and Settings\Owner\Desktop\City of Heroes.lnk
[2010/03/05 20:37:33 | 000,007,446 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Guild Wars Login.odt
[5 C:\Documents and Settings\Owner\*.tmp files -> C:\Documents and Settings\Owner\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/26 22:49:39 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Might and Magic® VI.lnk
[2010/03/26 22:43:28 | 000,001,675 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Might and Magic® VII.lnk
[2010/03/26 22:43:04 | 102,567,607 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Warcraft3_Demo.zip
[2010/03/17 19:42:18 | 000,014,776 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\6pnFj01o
[2010/03/17 19:42:18 | 000,014,776 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6pnFj01o
[2010/03/11 07:09:27 | 000,563,102 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\Cat.DB
[2010/03/10 18:59:15 | 000,001,562 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNetV.inf
[2010/03/10 18:59:14 | 000,009,412 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\symnetv.cat
[2010/03/10 18:59:14 | 000,009,402 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNet.cat
[2010/03/10 18:59:14 | 000,007,431 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.cat
[2010/03/10 18:59:14 | 000,007,429 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.cat
[2010/03/10 18:59:14 | 000,007,425 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.cat
[2010/03/10 18:59:14 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\ccHPx86.cat
[2010/03/10 18:59:14 | 000,003,373 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymEFA.inf
[2010/03/10 18:59:14 | 000,001,752 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\ccHPx86.inf
[2010/03/10 18:59:14 | 000,001,561 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\SymNet.inf
[2010/03/10 18:59:14 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtspx.inf
[2010/03/10 18:59:14 | 000,001,382 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\srtsp.inf
[2010/03/10 18:59:14 | 000,000,640 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.inf
[2010/03/10 18:59:13 | 000,007,400 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\BHDrvx86.CAT
[2010/03/10 18:58:37 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0308000.029\isolate.ini
[2010/03/10 18:23:10 | 000,007,456 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/03/10 18:23:10 | 000,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/03/10 18:23:05 | 000,001,906 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/03/09 22:07:42 | 000,106,271 | —- | C] () – C:\Documents and Settings\Owner\Desktop\annoyingprompt.jpg
[2010/03/09 21:58:45 | 000,420,819 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Unauthorizedscan.jpg
[2010/03/09 21:57:57 | 000,244,550 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Prompt.jpg
[2010/03/09 20:11:24 | 000,012,638 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\Pj2f4roAv7
[2010/03/05 20:53:13 | 000,001,626 | —- | C] () – C:\Documents and Settings\Owner\Desktop\City of Heroes.lnk
[2010/03/05 20:37:32 | 000,007,446 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Guild Wars Login.odt
[2010/01/08 15:58:50 | 000,002,352 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/11/01 22:14:23 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2009/10/14 07:49:50 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Sync Services
[2009/10/14 07:49:50 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Strings
[2009/10/14 07:49:50 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2009/10/14 07:49:50 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\SystemConfiguration
[2007/04/09 19:40:32 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2007/01/25 19:13:09 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/01/25 18:26:07 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/25 18:06:33 | 000,001,892 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/12/18 17:25:20 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/12/18 17:02:34 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/12/18 17:02:34 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/12/18 17:02:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/12/18 17:02:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/12/18 17:02:34 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/12/18 17:02:34 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/12/18 17:02:26 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\cddvdint.dll
[2006/12/18 16:39:14 | 000,017,536 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/12/18 16:39:11 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/12/18 09:40:12 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/12/18 09:40:12 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/12/18 09:40:11 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/12/18 09:40:11 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/11/24 17:02:55 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/11/24 17:02:45 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/11/24 17:01:42 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/11/24 16:54:16 | 000,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/11/24 16:17:14 | 000,394,240 | —- | C] () – C:\WINDOWS\System32\HMTCD.dll
[2003/03/31 10:00:00 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\CopyToSendTo.dll
[2001/07/07 03:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2000/04/12 15:24:10 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[1997/09/30 14:30:02 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL

========== LOP Check ==========

[2008/06/30 11:18:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/06/24 14:03:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Astar Games
[2010/01/07 16:50:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CaveDays
[2008/03/15 20:29:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eGames
[2009/12/14 19:40:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/02/12 19:13:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Enkord
[2009/10/14 07:49:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/12/31 21:47:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Escape From Paradise
[2010/01/05 19:12:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/27 20:29:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2009/02/17 20:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreshGames
[2009/11/23 20:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2007/12/31 17:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2008/06/24 22:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii Games
[2008/06/02 19:56:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GraphicsDesk
[2008/06/02 20:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hemera
[2007/12/02 10:46:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2009/02/18 22:44:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Legendo
[2008/04/15 22:11:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/02/28 21:09:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mushroom Age
[2009/10/14 07:50:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2007/11/27 22:55:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/07/11 21:08:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/11/18 21:59:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/06/30 11:01:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/02/14 11:33:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/02/12 18:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/22 02:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/10/14 07:49:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2010/02/03 20:16:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/06/30 11:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/02/14 11:43:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BeachPartyCraze
[2007/12/31 05:04:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EA
[2008/03/15 20:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eGames
[2009/02/28 16:01:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EleFun Games
[2010/03/17 20:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2008/01/05 18:01:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Gaijin Ent
[2009/03/04 18:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Gamelab
[2008/09/26 23:28:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/06/24 22:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Gogii Games
[2008/06/02 20:01:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Hemera
[2008/05/18 22:19:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Home Sweet Home
[2007/11/12 19:44:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ideazon
[2008/03/04 20:18:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2007/12/28 23:26:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\iWin
[2009/03/02 20:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Meridian93
[2007/12/29 00:55:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mind Control Software
[2008/06/30 20:54:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nexon
[2009/11/05 14:20:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2007/12/29 00:55:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayFirst
[2009/11/19 21:32:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2008/06/28 13:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Reflexive
[2008/10/13 23:33:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/02/13 20:24:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skip-Bo
[2008/11/29 12:27:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SPORE
[2008/06/27 16:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/30 19:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Super-Cow
[2009/06/22 02:20:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TomTom
[2007/11/26 21:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ViquaSoft
[2010/02/25 22:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WordWeb
[2009/04/30 20:27:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\YoudaGames
[2007/06/16 15:24:06 | 000,000,260 | —- | M] () – C:\WINDOWS\Tasks\Disk Cleanup.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ADE16379
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B99FE60
< End of report >


File named Extras:

OTL Extras logfile created on: 3/27/2010 6:35:44 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 500.00 Mb Available Physical Memory | 49.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 3072 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 372.60 Gb Total Space | 265.98 Gb Free Space | 71.38% Space Free | Partition Type: NTFS
Drive D: | 200.01 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADMIN-AEF638EE6
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\Owner\Local Settings\Application Data\ave.exe File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}" = TrayApp
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{19FDB8E4-59AD-4330-9667-E8DCAF018DD3}" = Unload
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# 1.1 Redistributable Package
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{1E1F1E70-14D8-4380-8652-BD1A895A7D65}" = Status
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}" = SolutionCenter
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}" = iTunes
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{61CF89F5-5175-4b3b-ABB8-C89821252D50}" = HP Photosmart Cameras 6.0
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{686BB230-DE5B-44F4-8DB0-4F9BEE7310F7}" = OpenOffice.org 2.0
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{729DF902-05F9-4C00-9E6D-411119824E5F}" = hpiCamDrvQFolder
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90885A82-9673-49EA-AB39-AF776639C67C}" = InterVideo WinDVD 7
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7BF5269-3E74-11D5-B00F-00104B398D77}" = QuarkXPress 5.0
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F5421F-DA70-4C77-BB97-8D77EC33ED5E}" = HP Photosmart and Deskjet 7.0.A
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}" = SPORE™ Creepy & Cute Parts Pack
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5A5C573-FB6D-48d8-9F7F-08FC4AD4B488}" = CameraUserGuides
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & White® 2
"{DA5BE26C-8295-4F7F-BBA8-475EF9231289}" = The Roleplaying assistant V7.13b
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DEBB2986-15B0-4D28-95FA-5C966A396589}" = HPProductAssistant
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E28C0E25-CCDC-40B7-8491-C1A2B1B5EB1E}" = 250,000 Designer Clip Art V2
"{E5A1DE9A-A21C-43A1-B06D-5146BAF62033}" = PanoStandAlone
"{E6FC4EEE-2EEA-49A7-B036-908B9BD4BB70}" = MapleStory
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EC2715CE-C182-483C-84CC-81D7D914CF14}" = WebReg
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F876A4EC-DD7A-4bf8-A169-E4FD6C60BA3F}" = CameraDrivers
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"10 Talismans_is1" = 10 Talismans
"7 Wonders_is1" = 7 Wonders
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AI RoboForm" = AI RoboForm (All Users)
"AIM_6" = AIM 6
"Aveyond_is1" = Aveyond
"Aztec Bricks_is1" = Aztec Bricks
"Babysitting Mania_is1" = Babysitting Mania
"Beach Party Craze_is1" = Beach Party Craze
"Bob the Builder Can-Do Carnival_is1" = Bob the Builder Can-Do Carnival
"Bookworm Deluxe_is1" = Bookworm Deluxe
"Build in Time_is1" = Build in Time
"Buildalot_is1" = Buildalot
"Burger Rush_is1" = Burger Rush
"Can You See What I See_is1" = Can You See What I See
"Cave Days_is1" = Cave Days
"Celebrity Toolbar" = Celebrity Toolbar
"Chocolatier 2_is1" = Chocolatier 2
"Chuzzle Deluxe_is1" = Chuzzle Deluxe
"Cindys Sundaes_is1" = Cindys Sundaes
"Cinema Tycoon Gold_is1" = Cinema Tycoon Gold
"COH" = City of Villains/City of Heroes (remove only)
"Cooking Academy_is1" = Cooking Academy
"County Fair_is1" = County Fair
"Create A Mall_is1" = Create A Mall
"CTDVDAudio Plugin" = Creative DVD Audio Plugin for Audigy Series
"Dr Daisy Pet Vet_is1" = Dr Daisy Pet Vet
"Escape From Paradise_is1" = Escape From Paradise
"EssenceRO" = EssenceRO
"Fab Fashion_is1" = Fab Fashion
"Farm Frenzy Pizza Party_is1" = Farm Frenzy Pizza Party
"Farm Frenzy_is1" = Farm Frenzy
"Farm Mania_is1" = Farm Mania
"Fizzball_is1" = Fizzball
"Flower Stand Tycoon_is1" = Flower Stand Tycoon
"Gardenscapes_is1" = Gardenscapes
"Google Chrome" = Google Chrome
"Grimms Hatchery_is1" = Grimms Hatchery
"Guild Wars" = Guild Wars
"Hidden Relics_is1" = Hidden Relics
"HijackThis" = HijackThis 2.0.2
"Home Sweet Home_is1" = Home Sweet Home
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center and Imaging Support Tools 6.0
"ie8" = Windows Internet Explorer 8
"Jewel Match Winter Wonderland_is1" = Jewel Match Winter Wonderland
"Jewel Quest Solitaire II_is1" = Jewel Quest Solitaire II
"kSolo" = kSolo Recorder
"Kudos_is1" = Kudos
"Laura Jones And The Gates Of Good And Evil_is1" = Laura Jones And The Gates Of Good And Evil
"Lemonade Tycoon 2_is1" = Lemonade Tycoon 2
"Luxor 3_is1" = Luxor 3
"Magic Farm_is1" = Magic Farm
"Mahjongg Artifacts Chapter 2_is1" = Mahjongg Artifacts Chapter 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Master of Defense_is1" = Master of Defense
"McAfee Security Scan" = McAfee Security Scan
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable" = Microsoft Visual J# 2.0 Redistributable Package
"Might and Magic® VI" = Might and Magic® VI
"Might and Magic® VII" = Might and Magic® VII
"Miss Management_is1" = Miss Management
"Monarch - The Butterfly King_is1" = Monarch - The Butterfly King
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MSNINST" = MSN
"Mushroom Age_is1" = Mushroom Age
"My Tribe_is1" = My Tribe
"Mythic Pearls_is1" = Mythic Pearls
"N360" = Norton 360
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA Drivers" = NVIDIA Drivers
"Oasis_is1" = Oasis
"Out Of Your Mind_is1" = Out Of Your Mind
"Party Down_is1" = Party Down
"Peggle Deluxe_is1" = Peggle Deluxe
"Peggle World of Warcraft Edition" = Peggle World of Warcraft Edition
"Phlinx To Go_is1" = Phlinx To Go
"Plant Tycoon_is1" = Plant Tycoon
"Poppit To Go_is1" = Poppit To Go
"PROR" = Microsoft Office Professional 2007
"Purrfect Pet Shop_is1" = Purrfect Pet Shop
"Puzzle Hero_is1" = Puzzle Hero
"Ranch Rush_is1" = Ranch Rush
"Sallys Spa_is1" = Sallys Spa
"Shop for HP Supplies" = Shop for HP Supplies
"SKIPBO Castaway Caper_is1" = SKIPBO Castaway Caper
"Spooky Spirits_is1" = Spooky Spirits
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster v3.4
"Supercow_is1" = Supercow
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"The Clumsys_is1" = The Clumsys
"The Game Of LIFE PTS_is1" = The Game Of LIFE PTS
"The Poppit Show_is1" = The Poppit Show
"The Treasures Of Montezuma_is1" = The Treasures Of Montezuma
"The Wizards Pen TM_is1" = The Wizards Pen TM
"Totem Tribe_is1" = Totem Tribe
"Venture Arctic_is1" = Venture Arctic
"Virtual Villagers 2_is1" = Virtual Villagers 2
"Virtual Villagers_is1" = Virtual Villagers
"Westward II Heroes Of The Frontier_is1" = Westward II Heroes Of The Frontier
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Word Web Deluxe_is1" = Word Web Deluxe
"WordWeb" = WordWeb
"World of Warcraft" = World of Warcraft
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"Yard Sale Junkie_is1" = Yard Sale Junkie
"YInstHelper" = Yahoo! Install Manager
"Youda Farmer_is1" = Youda Farmer

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/25/2010 10:37:03 AM | Computer Name = ADMIN-AEF638EE6 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\NDP1.1sp1-KB953297-X86\NDP1.1sp1-KB953297-X86-msi.0.log.

Error - 3/25/2010 10:37:04 AM | Computer Name = ADMIN-AEF638EE6 | Source = NativeWrapper | ID = 5000
Description =

Error - 3/26/2010 12:28:36 PM | Computer Name = ADMIN-AEF638EE6 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 3/26/2010 12:28:36 PM | Computer Name = ADMIN-AEF638EE6 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/26/2010 12:29:41 PM | Computer Name = ADMIN-AEF638EE6 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\NDP1.1sp1-KB953297-X86\NDP1.1sp1-KB953297-X86-msi.0.log.

Error - 3/26/2010 12:29:42 PM | Computer Name = ADMIN-AEF638EE6 | Source = NativeWrapper | ID = 5000
Description =

Error - 3/26/2010 11:53:41 PM | Computer Name = ADMIN-AEF638EE6 | Source = Application Error | ID = 1000
Description = Faulting application mm7.exe, version 1.0.0.1, faulting module mm7.exe,
version 1.0.0.1, fault address 0x000a3af6.

Error - 3/27/2010 12:09:07 AM | Computer Name = ADMIN-AEF638EE6 | Source = Application Error | ID = 1000
Description = Faulting application mm6.exe, version 1.0.0.1, faulting module mm6.exe,
version 1.0.0.1, fault address 0x0001003f.

Error - 3/27/2010 12:31:15 AM | Computer Name = ADMIN-AEF638EE6 | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\NDP1.1sp1-KB953297-X86\NDP1.1sp1-KB953297-X86-msi.0.log.

Error - 3/27/2010 12:31:15 AM | Computer Name = ADMIN-AEF638EE6 | Source = NativeWrapper | ID = 5000
Description =

[ System Events ]
Error - 3/22/2010 6:56:00 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 3/22/2010 10:47:47 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/23/2010 8:12:13 AM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/23/2010 10:46:13 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/24/2010 6:56:01 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 3/24/2010 8:54:35 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/25/2010 10:37:04 AM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/26/2010 12:29:43 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).

Error - 3/26/2010 9:43:51 PM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 3/27/2010 12:31:16 AM | Computer Name = ADMIN-AEF638EE6 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1 Security Update
for Windows 2000, Windows XP, Windows Vista, Windows Server 2008, Windows 7, and
Windows Server 2008 R2 (KB953297).


< End of report >
Hi harliequin,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\ave.exe" /START "%1" %* File not found

:Files
C:\Documents and Settings\Owner\Local Settings\Application Data\6pnFj01o
C:\Documents and Settings\All Users\Application Data\6pnFj01o

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log

How is the computer now?

Thanks
Have I mentioned how much I love you? :D It's working fine now from what I can see. THANK YOU SO MUCH for your help! <3 Here are the logs. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully. HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully! ========== FILES ========== C:\Documents and Settings\Owner\Local Settings\Application Data\6pnFj01o moved successfully. C:\Documents and Settings\All Users\Application Data\6pnFj01o moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner ->Temp folder emptied: 353658 bytes ->Temporary Internet Files folder emptied: 62578363 bytes ->Java cache emptied: 1716582 bytes ->FireFox cache emptied: 44139812 bytes ->Google Chrome cache emptied: 6322857 bytes ->Flash cache emptied: 339845 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 4708199 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 21253841 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 61819984 bytes Total Files Cleaned = 194.00 mb OTL by OldTimer - Version 3.1.37.3 log created on 03282010_112141 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\System32\config\systemprofile\Local Settings\Temp\JETC37E.tmp not found! File\Folder C:\WINDOWS\System32\config\systemprofile\Local Settings\Temp\Perflib_Perfdata_654.dat not found! Registry entries deleted on Reboot… Malwarebytes' Anti-Malware 1.44 Database version: 3923 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/28/2010 12:08:27 PM mbam-log-2010-03-28 (12-08-27).txt Scan type: Quick Scan Objects scanned: 134001 Time elapsed: 33 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Owner\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Owner\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Owner\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi harliequin,

We'll update your java and do one more scan to check our work.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 18
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u18-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall


J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 6
Java™ 6 Update 7


Do not uninstall Java TM 6 Update 18 if found! :yeah:

Reboot your computer.



  • Double-click on the saved file ( jre-6u18-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.


Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK


One more scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

When Kaspersky is finished, please obtain a new OTL scan log. Uncheck Lop and purity this time. There will only be an OTL.txt log produced.

Please post back with
  • Kaspersky log
  • OTL.txt

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI