Hey Tom and thanks for aiding me in my learning journey with this
Here is the OTL log:
OTL logfile created on: 3/28/2010 9:45:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 4989 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 1.40 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USERCHRIS
Current User Name: GUgenH3iMer schmidt
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
PRC - [2010/03/26 13:52:46 | 000,136,176 | —- | M] (Google Inc.) – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
PRC - [2010/03/24 12:58:30 | 001,086,744 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/24 12:58:30 | 000,617,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/03/24 12:58:28 | 000,508,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/24 12:58:25 | 000,710,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/24 12:58:10 | 002,059,544 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/03/24 12:58:05 | 002,325,816 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgfws9.exe
PRC - [2010/03/24 12:57:42 | 000,836,888 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/03/24 12:57:39 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/24 12:57:28 | 000,596,488 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/03/24 12:57:25 | 005,888,008 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/03/22 13:51:30 | 000,530,928 | —- | M] (Google Inc.) – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/12/21 19:10:03 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/05/27 04:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2008/11/24 23:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 23:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/05 18:20:42 | 000,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/02/05 18:18:48 | 000,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2006/07/27 15:19:00 | 000,282,624 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
========== Modules (SafeList) ==========
MOD - [2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
MOD - [2008/02/05 18:20:30 | 000,109,080 | —- | M] (Logitech Inc.) – C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/03/24 12:58:05 | 002,325,816 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgfws9.exe – (avgfws9)
SRV - [2010/03/24 12:57:39 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/24 12:57:25 | 005,888,008 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2009/09/09 12:37:11 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/05/27 04:27:04 | 029,262,680 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/11/24 23:31:12 | 000,087,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)
SRV - [2008/11/24 23:31:08 | 000,239,968 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser)
SRV - [2008/11/24 23:31:08 | 000,045,408 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper)
SRV - [2008/02/05 18:22:36 | 000,141,848 | —- | M] (Logitech Inc.) [Auto | Stopped] – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher)
SRV - [2008/02/05 18:20:42 | 000,150,040 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/02/05 18:18:48 | 000,186,904 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Disabled | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/09/23 07:01:16 | 002,799,808 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – c:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe – (msvsmon80)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/24 12:56:51 | 000,000,000 | —D | M]
[2010/03/26 13:55:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/03/26 13:52:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/02/23 22:54:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/09/05 11:11:14 | 000,081,920 | —- | M] (MeadCo Corp.) – C:\Program Files\Mozilla Firefox\plugins\npmeadax.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/01/27 17:42:17 | 000,378,506 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 13048 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Save YouTube Video as MP3 - C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll (DVSTeam)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WinCtrl32: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\ssqpq) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell - "" = AutoRun
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b8cec85b-d3c9-11dd-ae2c-001372325061}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\AutoRunMorrowind.exe – File not found
O33 - MountPoints2\D\Shell\install\command - "" = D:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/28 17:48:54 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanServer - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (32935965299310592)
========== Files/Folders - Created Within 14 Days ==========
File not found – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
[2010/03/28 21:24:17 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
[2010/03/28 13:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\AVG9
[2010/03/26 13:52:53 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Temp
[2010/03/26 13:52:46 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\Google
[2010/03/25 10:59:39 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/03/24 12:59:03 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/24 12:59:00 | 000,029,512 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/24 12:58:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/03/24 12:57:49 | 000,025,096 | —- | C] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/03/24 12:57:47 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/03/24 12:57:44 | 000,242,696 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/24 12:57:42 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/24 12:53:44 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/03/23 16:43:24 | 000,094,208 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\DIIUnin.exe
[2010/03/23 16:36:41 | 000,000,000 | —D | C] – C:\Diablo II
[2010/03/21 23:48:06 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Storage
[2010/03/21 22:54:22 | 000,000,000 | —D | C] – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Camera Logs
[2010/03/20 23:16:07 | 000,524,288 | —- | C] (SerComm Corporation) – C:\WINDOWS\System32\Mpeg4Receiver.ax
[2010/03/20 23:15:53 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2010/03/17 23:21:29 | 000,118,784 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\DiabUnin.exe
[2010/03/17 23:21:26 | 000,000,000 | —D | C] – C:\Program Files\Diablo
[2010/03/17 23:16:01 | 000,000,000 | —D | C] – C:\Program Files\Sierra
[2010/03/15 20:18:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Linksys
[2010/03/15 16:38:33 | 000,709,248 | R— | C] (Ralink Technology, Corp.) – C:\WINDOWS\System32\drivers\rt2870.sys
[2010/03/15 16:38:33 | 000,221,184 | R— | C] (Ralink Technology, Inc.) – C:\WINDOWS\System32\RaCoInst.dll
[2010/03/15 16:31:15 | 000,000,000 | —D | C] – C:\Program Files\WebEx
[2010/03/15 16:26:55 | 000,939,368 | R— | C] (Macromedia, Inc.) – C:\WINDOWS\System32\myflash.ocx
[2010/03/15 16:18:31 | 000,000,000 | —D | C] – C:\Program Files\Linksys
[2007/10/28 11:10:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/09/21 19:12:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2007/09/21 19:12:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Google
[2007/09/21 19:12:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
[2007/08/21 20:32:21 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2007/07/10 19:02:57 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/08/10 14:08:14 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
File not found – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\[Torrentsworld.net] - Iria Zeiram - The Animation (Complete+ENG).torrent
[2010/03/28 21:24:18 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\OTL.exe
[2010/03/28 20:57:00 | 000,001,034 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003UA.job
[2010/03/28 17:33:08 | 058,189,431 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/28 13:57:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003Core.job
[2010/03/26 13:53:30 | 000,002,386 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\Google Chrome.lnk
[2010/03/26 01:52:39 | 000,031,232 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/26 01:25:52 | 002,287,616 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ravel Theme (music).mp3
[2010/03/26 01:25:18 | 002,273,280 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ignus Theme (music).mp3
[2010/03/26 01:24:47 | 004,247,552 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Smoldering Corpse Bar (music).mp3
[2010/03/26 00:45:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/03/26 00:44:08 | 000,000,104 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/03/26 00:43:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/03/26 00:43:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/03/26 00:42:07 | 018,350,080 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\ntuser.dat
[2010/03/26 00:42:07 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\ntuser.ini
[2010/03/26 00:41:56 | 000,549,496 | -H– | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\IconCache.db
[2010/03/26 00:34:57 | 000,026,794 | —- | M] () – C:\WINDOWS\DIIUnin.dat
[2010/03/26 00:34:02 | 000,021,840 | —- | M] () – C:\WINDOWS\System32\SIntfNT.dll
[2010/03/26 00:34:02 | 000,017,212 | —- | M] () – C:\WINDOWS\System32\SIntf32.dll
[2010/03/26 00:34:02 | 000,012,067 | —- | M] () – C:\WINDOWS\System32\SIntf16.dll
[2010/03/25 22:58:15 | 000,011,093 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\SkinnerArticle.docx
[2010/03/24 23:47:29 | 000,055,960 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\SNC00147.jpg
[2010/03/24 12:59:04 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/03/24 12:59:01 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/03/24 12:59:00 | 000,572,937 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/03/24 12:59:00 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/24 12:57:49 | 000,025,096 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2010/03/24 12:57:47 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2010/03/24 12:57:46 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/03/24 12:57:42 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/03/24 12:56:52 | 000,030,104 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgfwdx.sys
[2010/03/23 16:43:24 | 000,094,208 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\DIIUnin.exe
[2010/03/23 16:43:24 | 000,002,829 | —- | M] () – C:\WINDOWS\DIIUnin.pif
[2010/03/22 13:32:00 | 005,245,209 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\befvp41_v2-ug-Rev_NC.pdf
[2010/03/18 15:59:35 | 004,495,360 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\The Peanuts Theme.mp3
[2010/03/17 23:32:17 | 000,000,008 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/03/17 23:27:31 | 000,006,135 | —- | M] () – C:\WINDOWS\DiabUnin.dat
[2010/03/17 23:21:29 | 000,118,784 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\DiabUnin.exe
[2010/03/17 23:21:29 | 000,002,829 | —- | M] () – C:\WINDOWS\DiabUnin.pif
[2010/03/15 16:39:49 | 000,579,754 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/15 16:39:49 | 000,482,936 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/15 16:39:49 | 000,086,322 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/03/15 14:55:06 | 000,065,517 | —- | M] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\img031.jpg
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/28 15:34:12 | 667,541,504 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\The Wire - 212 - Port in a Storm [FuckGov].avi
[2010/03/26 13:53:30 | 000,002,386 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\Google Chrome.lnk
[2010/03/26 13:52:52 | 000,001,034 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003UA.job
[2010/03/26 13:52:51 | 000,000,982 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-688789844-839522115-1003Core.job
[2010/03/26 01:25:48 | 002,287,616 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ravel Theme (music).mp3
[2010/03/26 01:25:14 | 002,273,280 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Ignus Theme (music).mp3
[2010/03/26 01:24:40 | 004,247,552 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\Planescape- Torment - Smoldering Corpse Bar (music).mp3
[2010/03/25 21:48:21 | 000,011,093 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\SkinnerArticle.docx
[2010/03/24 23:46:44 | 000,055,960 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\SNC00147.jpg
[2010/03/24 12:59:00 | 000,572,937 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/03/24 12:59:00 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/03/24 12:58:52 | 058,189,431 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/23 16:43:27 | 000,026,794 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/03/23 16:43:24 | 000,002,829 | —- | C] () – C:\WINDOWS\DIIUnin.pif
[2010/03/22 13:31:55 | 005,245,209 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\befvp41_v2-ug-Rev_NC.pdf
[2010/03/20 23:16:07 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\CiscoPlayer.ocx
[2010/03/20 23:16:04 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DSKernel.dll
[2010/03/20 23:15:53 | 000,794,624 | R— | C] () – C:\WINDOWS\System32\ffdshowX.ax
[2010/03/20 23:15:53 | 000,557,056 | R— | C] () – C:\WINDOWS\System32\libavcodecX.dll
[2010/03/20 23:15:53 | 000,099,328 | R— | C] () – C:\WINDOWS\System32\realaacX.dll
[2010/03/18 15:59:29 | 004,495,360 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\The Peanuts Theme.mp3
[2010/03/17 23:21:29 | 000,002,829 | —- | C] () – C:\WINDOWS\DiabUnin.pif
[2010/03/17 23:21:25 | 000,006,135 | —- | C] () – C:\WINDOWS\DiabUnin.dat
[2010/03/15 16:38:33 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2010/03/15 16:26:52 | 000,000,005 | —- | C] () – C:\Program Files\eula.txt
[2010/03/15 16:26:25 | 000,000,014 | —- | C] () – C:\Program Files\version.txt
[2010/03/15 14:55:14 | 000,065,517 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\My Documents\img031.jpg
[2010/03/11 13:45:49 | 000,000,632 | —- | C] () – C:\WINDOWS\CoD.INI
[2009/11/07 14:27:16 | 000,000,760 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\setup_ldm.iss
[2009/09/11 17:26:50 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/09/09 16:33:53 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/09/03 05:12:54 | 000,000,882 | —- | C] () – C:\WINDOWS\DC.ini
[2009/08/28 15:12:09 | 000,000,306 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/10 01:02:49 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/05/31 01:41:07 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/05/28 04:39:16 | 000,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/28 04:39:12 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/01 00:31:06 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/01/06 10:02:31 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\Hook.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/28 14:22:39 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/28 10:56:35 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/07/28 09:51:34 | 000,028,307 | —- | C] () – C:\WINDOWS\System32\kcopt.dll
[2008/07/28 09:51:34 | 000,004,546 | —- | C] () – C:\WINDOWS\System32\ksvcl.dll
[2008/06/24 11:26:51 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/06/24 11:26:51 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/06/24 11:26:51 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/22 16:34:08 | 000,000,260 | —- | C] () – C:\WINDOWS\cookies.ini
[2008/04/16 10:13:49 | 000,768,035 | -HS- | C] () – C:\WINDOWS\System32\xgcgqubr.ini
[2008/04/14 18:16:03 | 000,000,147 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/14 10:13:02 | 000,709,083 | -HS- | C] () – C:\WINDOWS\System32\chfgcovb.ini
[2008/04/13 10:05:44 | 000,708,447 | -HS- | C] () – C:\WINDOWS\System32\xtxkrrlt.ini
[2008/04/12 10:11:35 | 001,072,575 | -HS- | C] () – C:\WINDOWS\System32\gvsxbpcj.ini
[2008/04/11 10:14:35 | 001,095,585 | -HS- | C] () – C:\WINDOWS\System32\cccmcjdk.ini
[2008/04/10 10:08:35 | 001,256,745 | -HS- | C] () – C:\WINDOWS\System32\nuaknhvh.ini
[2008/04/08 10:06:45 | 001,270,011 | -HS- | C] () – C:\WINDOWS\System32\bfeefvtb.ini
[2008/03/17 11:01:20 | 001,027,160 | -HS- | C] () – C:\WINDOWS\System32\ukmtunwb.ini
[2008/03/17 09:58:20 | 001,017,318 | -HS- | C] () – C:\WINDOWS\System32\qckdiema.ini
[2008/03/17 08:58:20 | 001,017,258 | -HS- | C] () – C:\WINDOWS\System32\pwjkbpns.ini
[2008/03/17 07:55:21 | 001,017,198 | -HS- | C] () – C:\WINDOWS\System32\eroydpse.ini
[2008/03/17 06:55:20 | 001,017,255 | -HS- | C] () – C:\WINDOWS\System32\dyyeawtb.ini
[2008/03/17 05:55:20 | 001,017,195 | -HS- | C] () – C:\WINDOWS\System32\pqbsstqa.ini
[2008/03/17 04:55:20 | 001,013,778 | -HS- | C] () – C:\WINDOWS\System32\kwaiheye.ini
[2008/03/17 03:58:20 | 001,013,718 | -HS- | C] () – C:\WINDOWS\System32\hiuvgska.ini
[2008/03/17 02:55:20 | 001,005,222 | -HS- | C] () – C:\WINDOWS\System32\wwtoxnsp.ini
[2008/03/17 01:55:20 | 001,005,159 | -HS- | C] () – C:\WINDOWS\System32\smuiiwvw.ini
[2008/03/17 00:55:20 | 001,040,873 | -HS- | C] () – C:\WINDOWS\System32\xksybfem.ini
[2008/03/16 23:55:20 | 001,038,380 | -HS- | C] () – C:\WINDOWS\System32\qawpinfl.ini
[2008/03/16 22:55:20 | 001,038,320 | -HS- | C] () – C:\WINDOWS\System32\eivstxip.ini
[2008/03/16 21:52:20 | 001,038,260 | -HS- | C] () – C:\WINDOWS\System32\pjkxhjag.ini
[2008/03/16 20:52:20 | 001,038,200 | -HS- | C] () – C:\WINDOWS\System32\cgfiawdk.ini
[2008/03/16 19:52:21 | 001,038,140 | -HS- | C] () – C:\WINDOWS\System32\letqglbt.ini
[2008/03/16 18:49:20 | 001,038,080 | -HS- | C] () – C:\WINDOWS\System32\snabrpwq.ini
[2008/03/16 17:49:20 | 001,038,020 | -HS- | C] () – C:\WINDOWS\System32\adxhuevj.ini
[2008/03/16 16:49:20 | 001,037,960 | -HS- | C] () – C:\WINDOWS\System32\pewvvmev.ini
[2008/03/16 15:49:20 | 001,037,900 | -HS- | C] () – C:\WINDOWS\System32\qqaaoeog.ini
[2008/03/16 14:49:20 | 001,037,840 | -HS- | C] () – C:\WINDOWS\System32\yxsnkney.ini
[2008/03/16 13:46:20 | 001,037,780 | -HS- | C] () – C:\WINDOWS\System32\qoemgsit.ini
[2008/03/16 12:49:20 | 001,037,720 | -HS- | C] () – C:\WINDOWS\System32\iudrmnmo.ini
[2008/03/16 11:49:20 | 001,037,660 | -HS- | C] () – C:\WINDOWS\System32\gtjdlxlj.ini
[2008/03/16 10:49:21 | 001,037,600 | -HS- | C] () – C:\WINDOWS\System32\rwdeddfb.ini
[2008/03/16 09:46:20 | 001,037,540 | -HS- | C] () – C:\WINDOWS\System32\hragwxgi.ini
[2008/03/16 08:46:20 | 001,037,480 | -HS- | C] () – C:\WINDOWS\System32\sovoboov.ini
[2008/03/16 07:43:20 | 001,037,420 | -HS- | C] () – C:\WINDOWS\System32\xutgmrct.ini
[2008/03/16 06:43:20 | 001,037,360 | -HS- | C] () – C:\WINDOWS\System32\urgqomgy.ini
[2008/03/16 05:43:19 | 001,037,300 | -HS- | C] () – C:\WINDOWS\System32\ddkabamu.ini
[2008/03/16 04:43:20 | 001,037,240 | -HS- | C] () – C:\WINDOWS\System32\lthiwovj.ini
[2008/03/16 03:40:20 | 001,037,180 | -HS- | C] () – C:\WINDOWS\System32\maaoimmn.ini
[2008/03/16 02:40:19 | 001,037,120 | -HS- | C] () – C:\WINDOWS\System32\belmigbk.ini
[2008/03/16 01:40:20 | 001,037,060 | -HS- | C] () – C:\WINDOWS\System32\pxvxolrp.ini
[2008/03/16 00:40:20 | 001,037,000 | -HS- | C] () – C:\WINDOWS\System32\ocydaenk.ini
[2008/03/15 23:43:20 | 001,036,940 | -HS- | C] () – C:\WINDOWS\System32\lwyaydtn.ini
[2008/03/15 22:40:20 | 001,036,880 | -HS- | C] () – C:\WINDOWS\System32\eotyxsts.ini
[2008/03/15 21:37:20 | 001,036,820 | -HS- | C] () – C:\WINDOWS\System32\xcllcrdd.ini
[2008/03/15 20:40:20 | 001,036,760 | -HS- | C] () – C:\WINDOWS\System32\xobyxvpe.ini
[2008/03/15 19:37:20 | 001,036,700 | -HS- | C] () – C:\WINDOWS\System32\qluiwtuo.ini
[2008/03/15 18:40:19 | 001,036,640 | -HS- | C] () – C:\WINDOWS\System32\lrvnanwe.ini
[2008/03/15 17:37:19 | 001,036,580 | -HS- | C] () – C:\WINDOWS\System32\sschmtgw.ini
[2008/03/15 16:37:37 | 001,036,520 | -HS- | C] () – C:\WINDOWS\System32\chmrpvrv.ini
[2008/03/15 15:34:38 | 001,036,460 | -HS- | C] () – C:\WINDOWS\System32\tljrpfyl.ini
[2008/03/15 14:34:38 | 001,036,400 | -HS- | C] () – C:\WINDOWS\System32\kemibabe.ini
[2008/03/15 13:34:38 | 001,036,340 | -HS- | C] () – C:\WINDOWS\System32\vxpslccr.ini
[2008/03/15 12:37:38 | 001,036,280 | -HS- | C] () – C:\WINDOWS\System32\chrwhnsx.ini
[2008/03/15 11:34:39 | 001,036,220 | -HS- | C] () – C:\WINDOWS\System32\edbnjlso.ini
[2008/03/15 10:34:38 | 001,036,160 | -HS- | C] () – C:\WINDOWS\System32\qalmtnie.ini
[2008/03/15 09:34:37 | 001,036,100 | -HS- | C] () – C:\WINDOWS\System32\avakbaoa.ini
[2008/03/15 08:31:37 | 001,036,040 | -HS- | C] () – C:\WINDOWS\System32\oushunec.ini
[2008/03/15 07:31:38 | 001,035,980 | -HS- | C] () – C:\WINDOWS\System32\fnfxkqgc.ini
[2008/03/15 06:31:37 | 001,035,920 | -HS- | C] () – C:\WINDOWS\System32\tnwdroco.ini
[2008/03/15 05:31:37 | 001,035,860 | -HS- | C] () – C:\WINDOWS\System32\elnnggxi.ini
[2008/03/15 04:28:37 | 001,035,800 | -HS- | C] () – C:\WINDOWS\System32\islpartr.ini
[2008/03/15 03:28:37 | 001,035,740 | -HS- | C] () – C:\WINDOWS\System32\oyiltrjk.ini
[2008/03/15 02:31:37 | 001,035,680 | -HS- | C] () – C:\WINDOWS\System32\ikoaclmg.ini
[2008/03/15 01:31:38 | 001,035,620 | -HS- | C] () – C:\WINDOWS\System32\jhosptag.ini
[2008/03/15 00:28:38 | 001,035,560 | -HS- | C] () – C:\WINDOWS\System32\dtkjpgpt.ini
[2008/03/14 23:25:37 | 001,035,500 | -HS- | C] () – C:\WINDOWS\System32\xixnshlc.ini
[2008/03/14 22:25:37 | 001,035,440 | -HS- | C] () – C:\WINDOWS\System32\mbbiilrs.ini
[2008/03/14 21:25:37 | 001,035,380 | -HS- | C] () – C:\WINDOWS\System32\nogagtgk.ini
[2008/03/14 20:28:37 | 001,089,944 | -HS- | C] () – C:\WINDOWS\System32\pgsvbqoi.ini
[2008/03/14 19:25:38 | 001,197,835 | -HS- | C] () – C:\WINDOWS\System32\wrmxucau.ini
[2008/03/14 14:54:01 | 000,001,639 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/03/13 20:41:32 | 001,119,020 | -HS- | C] () – C:\WINDOWS\System32\sqdofbwf.ini
[2008/03/12 20:46:45 | 001,082,155 | -HS- | C] () – C:\WINDOWS\System32\nysmfdqm.ini
[2008/03/11 20:43:45 | 001,084,170 | -HS- | C] () – C:\WINDOWS\System32\cjfoghkm.ini
[2008/03/10 20:46:52 | 001,129,962 | -HS- | C] () – C:\WINDOWS\System32\batyjgtl.ini
[2008/03/09 20:46:44 | 001,111,061 | -HS- | C] () – C:\WINDOWS\System32\nlfkpqvi.ini
[2008/03/08 20:43:44 | 001,111,001 | -HS- | C] () – C:\WINDOWS\System32\jpdhscpk.ini
[2008/02/13 18:33:58 | 001,239,857 | -HS- | C] () – C:\WINDOWS\System32\bghtmhsp.ini
[2008/02/12 18:39:56 | 001,235,101 | -HS- | C] () – C:\WINDOWS\System32\jejqmmxw.ini
[2008/02/12 18:36:38 | 001,203,415 | -HS- | C] () – C:\WINDOWS\System32\qcvmedvh.ini
[2008/02/11 18:39:27 | 001,214,606 | -HS- | C] () – C:\WINDOWS\System32\aueqhqde.ini
[2008/02/11 18:36:26 | 001,210,435 | -HS- | C] () – C:\WINDOWS\System32\hesebuij.ini
[2008/02/10 18:39:14 | 001,203,294 | -HS- | C] () – C:\WINDOWS\System32\oebljdft.ini
[2008/02/10 18:33:14 | 001,203,114 | -HS- | C] () – C:\WINDOWS\System32\ixeosydx.ini
[2008/02/10 16:35:15 | 001,203,054 | -HS- | C] () – C:\WINDOWS\System32\tnawmxao.ini
[2008/02/10 16:32:16 | 001,202,934 | -HS- | C] () – C:\WINDOWS\System32\hnfwllhh.ini
[2008/02/09 16:32:23 | 001,202,874 | -HS- | C] () – C:\WINDOWS\System32\ffbtxhfh.ini
[2008/02/09 16:29:23 | 001,202,814 | -HS- | C] () – C:\WINDOWS\System32\hmsrmdwk.ini
[2008/02/08 16:29:21 | 001,202,754 | -HS- | C] () – C:\WINDOWS\System32\acniniav.ini
[2008/02/08 16:26:20 | 001,202,574 | -HS- | C] () – C:\WINDOWS\System32\pasftbut.ini
[2008/02/07 16:30:46 | 001,204,645 | -HS- | C] () – C:\WINDOWS\System32\ixjvlgft.ini
[2008/02/07 16:27:46 | 001,204,058 | -HS- | C] () – C:\WINDOWS\System32\hrmhuojc.ini
[2008/02/06 16:24:47 | 001,207,461 | -HS- | C] () – C:\WINDOWS\System32\vcwvvfjp.ini
[2008/02/06 16:21:47 | 001,201,793 | -HS- | C] () – C:\WINDOWS\System32\uvipipfr.ini
[2008/02/05 18:20:08 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/02/05 16:29:31 | 001,194,375 | -HS- | C] () – C:\WINDOWS\System32\likijins.ini
[2008/02/05 16:26:32 | 001,194,255 | -HS- | C] () – C:\WINDOWS\System32\fouhugyl.ini
[2008/02/04 12:17:51 | 001,194,315 | -HS- | C] () – C:\WINDOWS\System32\xlwsmqtw.ini
[2008/02/04 12:12:06 | 001,192,538 | -HS- | C] () – C:\WINDOWS\System32\iepndqnr.ini
[2008/02/03 10:54:46 | 000,031,232 | —- | C] () – C:\Documents and Settings\GUgenH3iMer schmidt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/03 04:14:01 | 000,532,796 | -HS- | C] () – C:\WINDOWS\System32\qpqss.ini
[2008/02/03 01:59:06 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2008/02/03 01:59:06 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2002/03/21 15:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL
========== LOP Check ==========
[2008/12/19 18:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
[2009/05/28 00:33:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
[2009/12/01 18:35:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM
[2008/12/07 18:16:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM Toolbar
[2010/02/24 03:39:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software
[2010/03/24 12:55:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2008/04/04 15:04:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/03/15 20:18:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Linksys
[2009/09/11 16:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PreEmptive Solutions
[2009/12/21 19:06:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Screaming Bee
[2008/08/07 07:05:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/06/10 17:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
[2008/02/03 10:48:52 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\acccore
[2009/05/28 00:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\ACD Systems
[2010/03/28 13:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\AVG9
[2009/12/21 19:02:08 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Avnex
[2010/03/22 12:07:00 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Azureus
[2009/09/03 11:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Electronic Arts
[2009/08/28 15:11:24 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\GetRightToGo
[2009/09/09 16:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Leadertech
[2009/12/21 19:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Screaming Bee
[2008/07/28 09:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\TmpRecentIcons
[2008/02/20 21:53:34 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\Viewpoint
[2009/05/22 14:55:24 | 000,000,000 | —D | M] – C:\Documents and Settings\GUgenH3iMer schmidt\Application Data\WinPatrol
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 06:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/04 06:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/04 08:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/03 16:46:14 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\i386\atapi.sys
[2004/08/04 08:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 06:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
[2004/08/04 08:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
[2004/08/04 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATABUS.SYS >
[2006/08/05 10:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\dell\drivers\R133282\nvatabus.sys
[2006/08/05 08:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\drivers\storage\r133282\nvatabus.sys
[2006/08/05 08:00:40 | 000,105,344 | —- | M] (NVIDIA Corporation) MD5=75562456AA672BB5FE56D3C64C6D1C7D – C:\i386\nvatabus.sys
< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2004/08/04 08:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
< End of report >
And here is the Extras log
OTL Extras logfile created on: 3/28/2010 9:45:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 4989 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 1.40 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USERCHRIS
Current User Name: GUgenH3iMer schmidt
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee 9.0.Browse] – "C:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MI1933~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"6114:UDP" = 6114:UDP:*:Enabled:Chris' Laptop
"49901:TCP" = 49901:TCP:*:Enabled:Vuze
"49901:UDP" = 49901:UDP:*:Enabled:Vuze
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\EA Games\Ultima Online Mondain's Legacy\client.exe" = C:\Program Files\EA Games\Ultima Online Mondain's Legacy\client.exe:*:Enabled:Ultima Online Client – (Electronic Arts)
"C:\Program Files\AIM6\aim6 .exe" = C:\Program Files\AIM6\aim6 .exe:*:Enabled:AIM – File not found
"C:\Program Files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe" = C:\Program Files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe:*:Enabled:jk2mp – File not found
"C:\Program Files\Steam\steamapps\zankuro\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\counter-strike\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus – (Vuze Inc.)
"C:\Program Files\Steam\steamapps\zankuro\half-life\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\half-life\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\Call of Duty\CoDMP.exe" = C:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP – File not found
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – File not found
"C:\Warcraft III\Warcraft III.exe" = C:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – File not found
"C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\uo hacks\SphereAgent\SphereAgent.exe" = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\uo hacks\SphereAgent\SphereAgent.exe:*:Enabled:SphereAgent – File not found
"C:\Program Files\Diablo\Diablo.exe" = C:\Program Files\Diablo\Diablo.exe:*:Enabled:Diablo – (Blizzard Entertainment)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\AlephOne-20081226\M1A1\AlephOne.exe" = C:\Documents and Settings\GUgenH3iMer schmidt\Desktop\AlephOne-20081226\M1A1\AlephOne.exe:*:Enabled:Aleph One/SDL for Win32 – File not found
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Steam\steamapps\zankuro\counter-strike source\hl2.exe" = C:\Program Files\Steam\steamapps\zankuro\counter-strike source\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Steam\steamapps\zankuro\half-life 2 deathmatch\hl2.exe" = C:\Program Files\Steam\steamapps\zankuro\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\PFPortChecker\PFPortChecker.exe" = C:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"C:\Program Files\Steam\steamapps\zankuro\day of defeat\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\day of defeat\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Steam\steamapps\zankuro\opposing force\hl.exe" = C:\Program Files\Steam\steamapps\zankuro\opposing force\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\AIM6\aim6 .exe" = C:\Program Files\AIM6\aim6 .exe:*:Enabled:AIM – File not found
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\WINDOWS\system32\a.exe" = C:\WINDOWS\system32\a.exe:*:Disabled:a – File not found
"C:\Doom 3\DOOM3DED.exe" = C:\Doom 3\DOOM3DED.exe:*:Enabled:DOOM 3 – File not found
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BE321C4-6E17-4ECD-A6CB-3EF73791BE87}" = Decoder
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23210453-8608-4FF2-B84B-B90453618781}" = Police Quest Collection™
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1" = RegAlyzer
"{29D3773E-54F4-23C2-D523-236A4453B844}_is1" = FileAlyzer
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{346D717A-A506-47FC-8AB0-FBB470B42266}" = Wireless-N Home Surveillance Camera
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{437AB8E0-FB69-4222-B280-A64F3DE22591}" = Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0
"{6444D9D9-CD6C-4464-B970-55C606C944DC}" = Logitech QuickCam
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6C531060-84FB-4F96-8F33-29DF020632EB}" = Microsoft .NET Compact Framework 1.0 SP3 Developer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78B75C6D-E53C-424C-BF83-4B63BD4A6682}" = Microsoft Device Emulator version 1.0 - ENU
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISSTDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISSTDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISSTDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISSTDR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISSTDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0053-0000-0000-0000000FF1CE}" = Microsoft Office Visio Standard 2007
"{91120000-0053-0000-0000-0000000FF1CE}_VISSTDR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{91120000-0053-0000-0000-0000000FF1CE}_VISSTDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92022F8E-2E55-4A16-88EB-B4778B35E942}" = ACDSee for PENTAX 3.0
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}" = Broadcom 440x 10/100 Integrated Controller
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1" = RunAlyzer
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DF7B213D-2065-41ED-BB51-7A3EED31EA7B}" = Ultima Online: Mondain's Legacy
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F49FEF83-45CA-4CE8-8304-A7372BA07AA9}" = Motorola Phone Tools
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCD9CD52-7222-4672-94A0-A722BA702FD0}" = Dell Resource CD
"AC3Filter_is1" = AC3Filter 1.60b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"AIM_7" = AIM 7
"AnalogX HyperTrace" = AnalogX HyperTrace
"AVG9Uninstall" = AVG 9.0
"BootLog XP_is1" = BootLog XP
"CamStudio" = CamStudio
"CodeStuff Starter" = CodeStuff Starter
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Diablo" = Diablo
"Diablo II" = Diablo II
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DOOM Collector's Edition" = DOOM Collector's Edition
"Fallout" = Fallout
"Fallout2" = Fallout2
"Free YouTube to Mp3 Converter_is1" = Free YouTube to Mp3 Converter version 3.2
"hp deskjet 940c series" = hp deskjet 940c series (Remove only)
"ie8" = Windows Internet Explorer 8
"lvdrivers_11.70" = Logitech QuickCam Driver Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Professional Edition - ENU" = Microsoft Visual Studio 2005 Professional Edition - ENU
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Natural Selection_is1" = Natural Selection 3.2
"NVIDIA Drivers" = NVIDIA Drivers
"PFPortChecker" = PFPortChecker 1.0.28
"PowerStrip 3 (remove only)" = PowerStrip 3 (remove only)
"RealPlayer 12.0" = RealPlayer
"Rise of The Triad_is1" = Rise of The Triad
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 10" = Counter-Strike
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 70" = Half-Life
"ULTIMATER" = Microsoft Office Ultimate 2007
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"VISSTDR" = Microsoft Office Visio Standard 2007 Trial
"VLC media player" = VLC media player 0.9.6
"Vuze" = Vuze
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.1 final uninstall
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Diablo" = Diablo
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/11/2010 2:03:28 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application Morrowind.exe, version 1.3.0.1029, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/14/2010 1:31:42 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).
Error - 3/14/2010 1:31:42 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 3/14/2010 3:13:10 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 3/14/2010 3:13:11 AM | Computer Name = USERCHRIS | Source = Ci | ID = 4127
Description = Content index on c:\documents and settings\all users.windows\application
data\microsoft\visio\catalog.wci could not be initialized. Error 3221225529.
Error - 3/17/2010 11:23:56 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application Diablo.exe, version 2000.2.2.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/17/2010 11:40:52 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application autorun.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/17/2010 11:40:52 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application autorun.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 3/24/2010 1:01:21 AM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application msiexec.exe, version 4.5.6001.22159, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/28/2010 9:45:35 PM | Computer Name = USERCHRIS | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.1.37.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 3/27/2010 5:44:50 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/27/2010 8:50:10 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/27/2010 6:00:20 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 12:09:46 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 3:12:24 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 6:17:39 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 9:25:41 AM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 12:29:28 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 3:32:02 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
Error - 3/28/2010 6:37:30 PM | Computer Name = USERCHRIS | Source = ipnathlp | ID = 31008
Description = The DNS proxy agent was unable to read the local list of name-resolution
servers
from the registry. The data is the error code.
< End of report >