Hi there….I neglected to mention in my previous post that I ran Ccleaner several times, but you probably already knew that:
OTL Folder:
OTL logfile created on: 6/13/2010 11:27:37 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 76.58 Gb Free Space | 41.11% Space Free | Partition Type: NTFS
Drive D: | 232.89 Gb Total Space | 104.70 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 71.65 Gb Free Space | 15.38% Space Free | Partition Type: NTFS
Drive G: | 1.86 Gb Total Space | 1.69 Gb Free Space | 90.55% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GARY-PC
Current User Name: Gary
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Users\Gary\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
========== Modules (SafeList) ==========
MOD - C:\Users\Gary\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:
64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:
64bit: - (Samsung UPD Service) – C:\Windows\SysNative\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (afcdpsrv) – C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()
========== Driver Services (SafeList) ==========
DRV:
64bit: - (afcdp) – C:\Windows\SysNative\DRIVERS\afcdp.sys (Acronis)
DRV:
64bit: - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\Windows\SysNative\DRIVERS\tdrpm258.sys (Acronis)
DRV:
64bit: - (timounter) – C:\Windows\SysNative\DRIVERS\timntr.sys (Acronis)
DRV:
64bit: - (snapman) – C:\Windows\SysNative\DRIVERS\snapman.sys (Acronis)
DRV:
64bit: - (Point64) – C:\Windows\SysNative\DRIVERS\point64k.sys (Microsoft Corporation)
DRV:
64bit: - (LMouFilt) – C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (LHidFilt) – C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:
64bit: - (SSPORT) – C:\Windows\SysNative\Drivers\SSPORT.sys (Samsung Electronics)
DRV:
64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:
64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:
64bit: - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:
64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:
64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:
64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:
64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:
64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:
64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:
64bit: - (tifsfilter) – C:\Windows\SysNative\DRIVERS\tifsfilt.sys (Acronis)
DRV:
64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:
64bit: - (SaiMini) – C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:
64bit: - (SaiK0728) – C:\Windows\SysNative\DRIVERS\SaiK0728.sys (Saitek)
DRV:
64bit: - (Alpham1) – C:\Windows\SysNative\DRIVERS\Alpham164.sys (Ideazon Corporation)
DRV:
64bit: - (UsbFltr) – C:\Windows\SysNative\Drivers\UsbFltr.sys (Waytech Development, Inc.)
DRV:
64bit: - (Alpham2) – C:\Windows\SysNative\DRIVERS\Alpham264.sys (Ideazon Corporation)
DRV:
64bit: - (DgiVecp) – C:\Windows\SysNative\Drivers\DgiVecp.sys (Samsung Electronics)
DRV:
64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:
64bit: - (athr) – C:\Windows\SysNative\DRIVERS\athrx.sys (Atheros Communications, Inc.)
DRV:
64bit: - (RTL85n64) – C:\Windows\SysNative\DRIVERS\RTL85n64.sys (Realtek)
DRV:
64bit: - (FET5A64) – C:\Windows\SysNative\DRIVERS\fet5a64.sys (VIA Technologies, Inc. )
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:62747
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.usedbfororder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:2.0.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.9
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: [removed]:2.0.6
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: [removed]:0.3.2
FF - prefs.js..extensions.enabledItems: [removed]:3.6.14
FF - prefs.js..extensions.enabledItems: {2a43f346-13de-4aad-adeb-00b61e5bcde3}:0.2
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.61
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..extensions.enabledItems: [removed]:1.9
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91
FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.91
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/08 18:54:47 | 000,000,000 | —D | M]
[2009/08/16 02:55:14 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions
[2009/08/16 02:55:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/06/09 22:18:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions
[2010/03/29 01:27:01 | 000,000,000 | —D | M] (Screengrab) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/05/07 22:01:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/05/28 19:10:34 | 000,000,000 | —D | M] (Vista-aero) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2010/04/27 20:20:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/02 00:14:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2010/06/06 02:36:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{2a43f346-13de-4aad-adeb-00b61e5bcde3}
[2010/01/21 12:43:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/04/03 00:03:45 | 000,000,000 | —D | M] (Surf Canyon - Search Engine Assistant) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2010/02/22 22:30:21 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010/05/12 12:15:04 | 000,000,000 | —D | M] (WOT) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/15 17:35:07 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/04/12 14:35:04 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/05/28 19:10:41 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/28 19:10:12 | 000,000,000 | —D | M] (myFireFox) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}
[2010/05/28 19:10:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}-trash
[2010/04/09 16:48:01 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/18 10:25:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/03/18 10:25:50 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/20 19:56:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/06 15:18:38 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2009/09/10 16:09:54 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\morningCoffee@shaneliesegang
[2010/02/22 22:30:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/05/22 19:19:19 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/16 15:16:17 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/05/28 19:10:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
[2010/05/28 19:10:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}\chrome\mozapps\extensions
[2010/06/03 14:54:23 | 000,002,282 | —- | M] () – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\searchplugins\surf-canyon.xml
[2010/03/22 06:41:40 | 000,007,328 | —- | M] () – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\searchplugins\thottbot-wow.xml
[2010/06/10 18:48:06 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/01/13 18:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:
64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:
64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll (Google Inc.)
O2:
64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:
64bit: - HKLM..\Run: [AsioReg] File not found
O4:
64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\ctasio.dll (Creative Technology Ltd)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:
64bit: - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:
64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1}
http://www.parallelgraphics.com/l2/bin/cortvrml.cab (ParallelGraphics Cortona Control)
O16 - DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA}
http://www.srtest.com/srl_bin/sysreqlab_test.cab (System Requirements Lab Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:
64bit: Ias - C:\Windows\SysNative\ias [2008/11/01 19:21:00 | 000,000,000 | —D | M]
NetSvcs:
64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:
64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/11/01 19:21:27 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010/06/13 11:24:18 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2010/06/13 11:23:44 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\further instructions folder
[2010/06/12 19:03:16 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Gary\Desktop\HiJackThis.exe
[2010/06/12 19:02:42 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\new virus removal
[2010/06/11 03:57:49 | 000,000,000 | —D | C] – C:\Users\Gary\.SunDownloadManager
[2010/06/10 22:38:33 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\virus removal
[2010/06/03 16:50:30 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\paul2
[2010/06/03 16:43:20 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\paul
[2010/06/03 09:42:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/03 09:42:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/31 12:18:03 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\bieberhead
[2010/05/30 23:30:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010/05/30 23:29:51 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/05/29 01:11:29 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/05/17 20:31:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliPoint
[2010/05/07 13:03:04 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Windows SideBar
[2010/05/07 00:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Apple Computer
[2010/05/04 01:09:08 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\NCH Software
[2010/05/04 01:08:08 | 000,000,000 | —D | C] – C:\ProgramData\NCH Swift Sound
[2010/05/04 01:07:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Swift Sound
[2010/05/04 01:07:56 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\NCH Swift Sound
[2010/04/29 23:36:10 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010/04/28 01:57:56 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2010/04/21 18:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\Documents\My Games
[2010/04/21 18:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Local\My Games
[2010/04/21 10:22:38 | 000,000,000 | —D | C] – C:\steam
[2010/04/15 13:12:49 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Acronis
[2010/04/15 13:11:04 | 000,000,000 | —D | C] – C:\ProgramData\Acronis
[2010/04/15 12:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Acronis
[2010/04/15 12:57:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acronis
[2010/04/03 22:55:32 | 000,064,616 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/04/03 22:55:32 | 000,056,424 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/04/03 10:07:23 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/22 06:14:28 | 000,000,000 | —D | C] – C:\Windows\Sun
[2008/10/07 23:42:42 | 000,060,928 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll
[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/06/13 11:29:59 | 000,000,432 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D705618D-2A18-4B1D-B733-4F084BB0159C}.job
[2010/06/13 11:27:59 | 000,000,436 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4F921297-886A-42B4-B743-9E6D5990E6A3}.job
[2010/06/13 11:27:39 | 003,407,872 | -HS- | M] () – C:\Users\Gary\ntuser.dat
[2010/06/13 11:24:12 | 000,694,964 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/13 11:24:12 | 000,598,350 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/13 11:24:12 | 000,101,988 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/13 11:24:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/13 11:23:06 | 000,070,389 | —- | M] () – C:\ProgramData\nvModes.001
[2010/06/13 11:21:59 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1002UA.job
[2010/06/13 11:15:00 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2010/06/13 11:11:59 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1001UA.job
[2010/06/13 09:53:15 | 000,000,432 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{9C87E4B8-515C-4766-9808-5C3389C31BB5}.job
[2010/06/13 09:51:39 | 000,070,389 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/06/13 09:51:29 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/13 09:51:09 | 000,004,176 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 09:51:09 | 000,004,176 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 09:51:04 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/13 09:51:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/12 22:01:49 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:49 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXState-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:49 | 000,000,788 | —- | M] () – C:\Windows\SysNative\DVCState-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:35 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/06/12 22:01:35 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TM.blf
[2010/06/12 22:01:33 | 002,801,612 | -H– | M] () – C:\Users\Gary\AppData\Local\IconCache.db
[2010/06/12 19:29:53 | 000,212,480 | —- | M] () – C:\Users\Gary\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 19:12:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1001Core.job
[2010/06/12 03:22:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1002Core.job
[2010/06/11 18:14:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Gary\Desktop\HiJackThis.exe
[2010/06/11 18:12:50 | 000,359,929 | —- | M] () – C:\Users\Gary\Desktop\dds.scr
[2010/06/11 14:38:17 | 000,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2010/06/11 14:38:17 | 000,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2010/06/11 03:44:56 | 000,002,188 | —- | M] () – C:\Users\Gary\AppData\Local\d3d9caps64.dat
[2010/06/11 03:43:31 | 000,001,356 | —- | M] () – C:\Users\Gary\AppData\Local\d3d9caps.dat
[2010/06/09 21:51:26 | 000,630,742 | —- | M] () – C:\Users\Gary\Desktop\oap-landsea-oceans-100608-02.jpg
[2010/06/09 00:11:10 | 000,080,229 | —- | M] () – C:\Users\Gary\Desktop\12275396.pdf
[2010/06/08 23:39:41 | 000,053,069 | —- | M] () – C:\Users\Gary\Desktop\DL_SubUnsub_BRR.pdf
[2010/06/08 23:16:36 | 000,207,618 | —- | M] () – C:\Users\Gary\Desktop\attachments_2010_06_08.zip
[2010/06/08 21:57:21 | 000,094,390 | —- | M] () – C:\Users\Gary\Desktop\0ec82692adff72fc0c7d82f84d243781.jpg
[2010/06/08 19:05:22 | 000,318,944 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/08 18:57:01 | 000,000,240 | —- | M] () – C:\Windows\win.ini
[2010/06/07 22:02:04 | 000,025,913 | —- | M] () – C:\Users\Gary\Desktop\tumblr_l3meggd9Fm1qay8mao1_400.jpg
[2010/06/07 21:15:42 | 000,058,476 | —- | M] () – C:\Users\Gary\Desktop\TDLPn.jpg
[2010/06/07 17:29:17 | 478,531,721 | —- | M] () – C:\Users\Gary\Desktop\Brocket.wmv
[2010/06/07 17:28:09 | 174,953,531 | —- | M] () – C:\Users\Gary\Desktop\MassiveStd Johnny and Tim.flv
[2010/06/07 15:09:06 | 000,082,432 | —- | M] () – C:\Users\Gary\Desktop\securedownload (1).jpg
[2010/06/07 15:08:58 | 000,070,957 | —- | M] () – C:\Users\Gary\Desktop\securedownload.jpg
[2010/06/05 19:25:48 | 000,385,315 | —- | M] () – C:\Users\Gary\Desktop\Book On The Taboo Against Knowing Who You Are.pdf
[2010/06/05 15:48:28 | 001,392,526 | —- | M] () – C:\Users\Gary\Desktop\philosophy of humanism.pdf
[2010/06/04 13:24:29 | 000,121,789 | —- | M] () – C:\Users\Gary\Desktop\FWSAPP1011.pdf
[2010/06/03 09:42:57 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 00:15:45 | 000,164,689 | —- | M] () – C:\Users\Gary\Desktop\Class-Search-4-09.pdf
[2010/06/02 00:13:57 | 000,351,754 | —- | M] () – C:\Users\Gary\Desktop\Registration-Process-4-09.pdf
[2010/06/01 13:22:27 | 000,002,369 | —- | M] () – C:\Users\Gary\Desktop\WinWay Resume Deluxe.lnk
[2010/05/30 23:29:52 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/30 18:57:48 | 000,046,415 | —- | M] () – C:\Users\Gary\Desktop\tWkCL.jpg
[2010/05/30 18:36:44 | 000,023,997 | —- | M] () – C:\Users\Gary\Desktop\q4XvN.jpg
[2010/05/29 13:35:07 | 000,001,724 | —- | M] () – C:\Users\Gary\Desktop\CCleaner.lnk
[2010/05/29 10:22:37 | 000,008,687 | —- | M] () – C:\Users\Gary\Desktop\fall-2010.pdf
[2010/05/29 10:22:15 | 000,038,766 | —- | M] () – C:\Users\Gary\Desktop\summer 2010 rev 07-24-09.pdf
[2010/05/29 01:11:31 | 000,000,752 | —- | M] () – C:\Users\Gary\Desktop\Ventrilo.lnk
[2010/05/29 01:11:31 | 000,000,210 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/05/27 19:34:38 | 000,023,063 | —- | M] () – C:\Users\Gary\Desktop\esar[1].pdf
[2010/05/23 18:06:40 | 000,000,388 | —- | M] () – C:\Users\Gary\Desktop\desktop for c - Shortcut.lnk
[2010/05/18 09:44:37 | 000,079,600 | —- | M] () – C:\Users\Gary\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/17 20:35:21 | 000,002,030 | —- | M] () – C:\Users\Public\Desktop\Microsoft Mouse.lnk
[2010/05/17 20:02:41 | 000,000,270 | —- | M] () – C:\Users\Gary\Desktop\Mouse - Shortcut.lnk
[2010/05/16 15:19:48 | 000,018,960 | —- | M] (Logitech, Inc.) – C:\Windows\SysNative\drivers\LNonPnP.sys
[2010/05/14 16:32:54 | 000,000,219 | —- | M] () – C:\Users\Gary\Desktop\Portal.url
[2010/05/11 22:05:50 | 000,000,382 | —- | M] () – C:\Users\Gary\Desktop\adult toons - Shortcut.lnk
[2010/05/07 00:42:12 | 000,002,024 | —- | M] () – C:\Users\Gary\Desktop\Tuner2 - your ears will know.lnk
[2010/05/07 00:42:12 | 000,001,018 | —- | M] () – C:\Users\Gary\Desktop\AAC-aacPlus Plugin Read Me.lnk
[2010/05/04 10:57:37 | 000,001,878 | —- | M] () – C:\Users\Gary\Desktop\Mahjong.lnk
[2010/05/04 10:57:28 | 000,001,910 | —- | M] () – C:\Users\Gary\Desktop\Solitaire.lnk
[2010/05/04 01:08:07 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/05/02 23:47:08 | 000,000,944 | —- | M] () – C:\Users\Public\Desktop\GOM Player.lnk
[2010/05/02 18:51:02 | 012,447,954 | —- | M] () – C:\Users\Gary\Desktop\Tempest_in_Tristram.mp3
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/22 15:42:34 | 000,032,256 | —- | M] () – C:\Users\Gary\Desktop\Gary Till.doc
[2010/04/22 04:35:58 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2010/04/15 12:58:13 | 000,002,120 | —- | M] () – C:\Users\Public\Desktop\Acronis One-Click Backup.lnk
[2010/04/15 12:58:13 | 000,001,046 | —- | M] () – C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
[2010/04/15 12:55:21 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/14 23:10:33 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/04/03 22:55:32 | 000,064,616 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/04/03 22:55:32 | 000,056,424 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/04/03 22:55:32 | 000,009,832 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2010/04/03 18:41:38 | 000,276,196 | —- | M] () – C:\Windows\SysNative\NvApps.xml
[2010/04/03 18:41:38 | 000,066,714 | —- | M] () – C:\Windows\SysNative\NvwsApps.xml
[2010/04/03 10:07:31 | 000,001,756 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | M] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/31 01:29:15 | 000,003,519 | —- | M] () – C:\Windows\InstText.ini
[2010/03/28 01:29:08 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/27 07:51:13 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 07:51:13 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TM.blf
[2010/03/23 06:36:15 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/03/22 10:13:07 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/21 22:59:17 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{da4e1f6f-2bcb-11df-8b47-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/21 22:59:17 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{da4e1f6f-2bcb-11df-8b47-0016e65a2068}.TM.blf
[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/12 19:03:06 | 000,359,929 | —- | C] () – C:\Users\Gary\Desktop\dds.scr
[2010/06/11 14:34:18 | 000,001,905 | —- | C] () – C:\Windows\diagwrn.xml
[2010/06/11 14:34:18 | 000,001,905 | —- | C] () – C:\Windows\diagerr.xml
[2010/06/09 21:51:25 | 000,630,742 | —- | C] () – C:\Users\Gary\Desktop\oap-landsea-oceans-100608-02.jpg
[2010/06/09 00:11:10 | 000,080,229 | —- | C] () – C:\Users\Gary\Desktop\12275396.pdf
[2010/06/08 23:39:41 | 000,053,069 | —- | C] () – C:\Users\Gary\Desktop\DL_SubUnsub_BRR.pdf
[2010/06/08 23:16:34 | 000,207,618 | —- | C] () – C:\Users\Gary\Desktop\attachments_2010_06_08.zip
[2010/06/08 21:57:20 | 000,094,390 | —- | C] () – C:\Users\Gary\Desktop\0ec82692adff72fc0c7d82f84d243781.jpg
[2010/06/07 22:02:03 | 000,025,913 | —- | C] () – C:\Users\Gary\Desktop\tumblr_l3meggd9Fm1qay8mao1_400.jpg
[2010/06/07 21:15:42 | 000,058,476 | —- | C] () – C:\Users\Gary\Desktop\TDLPn.jpg
[2010/06/07 16:14:17 | 174,953,531 | —- | C] () – C:\Users\Gary\Desktop\MassiveStd Johnny and Tim.flv
[2010/06/07 15:28:06 | 478,531,721 | —- | C] () – C:\Users\Gary\Desktop\Brocket.wmv
[2010/06/07 15:09:06 | 000,082,432 | —- | C] () – C:\Users\Gary\Desktop\securedownload (1).jpg
[2010/06/07 15:08:58 | 000,070,957 | —- | C] () – C:\Users\Gary\Desktop\securedownload.jpg
[2010/06/05 19:25:48 | 000,385,315 | —- | C] () – C:\Users\Gary\Desktop\Book On The Taboo Against Knowing Who You Are.pdf
[2010/06/05 15:48:28 | 001,392,526 | —- | C] () – C:\Users\Gary\Desktop\philosophy of humanism.pdf
[2010/06/04 13:24:28 | 000,121,789 | —- | C] () – C:\Users\Gary\Desktop\FWSAPP1011.pdf
[2010/06/03 09:42:57 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 00:15:45 | 000,164,689 | —- | C] () – C:\Users\Gary\Desktop\Class-Search-4-09.pdf
[2010/06/02 00:13:57 | 000,351,754 | —- | C] () – C:\Users\Gary\Desktop\Registration-Process-4-09.pdf
[2010/05/30 23:29:52 | 000,000,942 | —- | C] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/30 18:57:47 | 000,046,415 | —- | C] () – C:\Users\Gary\Desktop\tWkCL.jpg
[2010/05/30 18:36:42 | 000,023,997 | —- | C] () – C:\Users\Gary\Desktop\q4XvN.jpg
[2010/05/29 10:22:37 | 000,008,687 | —- | C] () – C:\Users\Gary\Desktop\fall-2010.pdf
[2010/05/29 10:22:15 | 000,038,766 | —- | C] () – C:\Users\Gary\Desktop\summer 2010 rev 07-24-09.pdf
[2010/05/29 05:57:52 | 000,001,356 | —- | C] () – C:\Users\Gary\AppData\Local\d3d9caps.dat
[2010/05/29 01:11:30 | 000,000,752 | —- | C] () – C:\Users\Gary\Desktop\Ventrilo.lnk
[2010/05/29 01:11:26 | 000,000,210 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/05/27 19:34:38 | 000,023,063 | —- | C] () – C:\Users\Gary\Desktop\esar[1].pdf
[2010/05/23 18:06:40 | 000,000,388 | —- | C] () – C:\Users\Gary\Desktop\desktop for c - Shortcut.lnk
[2010/05/17 20:35:21 | 000,002,030 | —- | C] () – C:\Users\Public\Desktop\Microsoft Mouse.lnk
[2010/05/17 20:02:41 | 000,000,270 | —- | C] () – C:\Users\Gary\Desktop\Mouse - Shortcut.lnk
[2010/05/14 16:32:54 | 000,000,219 | —- | C] () – C:\Users\Gary\Desktop\Portal.url
[2010/05/11 22:05:50 | 000,000,382 | —- | C] () – C:\Users\Gary\Desktop\adult toons - Shortcut.lnk
[2010/05/04 10:57:37 | 000,001,878 | —- | C] () – C:\Users\Gary\Desktop\Mahjong.lnk
[2010/05/04 10:57:28 | 000,001,910 | —- | C] () – C:\Users\Gary\Desktop\Solitaire.lnk
[2010/05/04 01:08:07 | 000,000,972 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/05/02 18:47:07 | 012,447,954 | —- | C] () – C:\Users\Gary\Desktop\Tempest_in_Tristram.mp3
[2010/04/22 15:42:34 | 000,032,256 | —- | C] () – C:\Users\Gary\Desktop\Gary Till.doc
[2010/04/21 10:26:22 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2010/04/15 12:58:13 | 000,002,120 | —- | C] () – C:\Users\Public\Desktop\Acronis One-Click Backup.lnk
[2010/04/15 12:58:13 | 000,001,046 | —- | C] () – C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
[2010/04/03 22:55:32 | 000,009,832 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2010/04/03 18:41:38 | 000,276,196 | —- | C] () – C:\Windows\SysNative\NvApps.xml
[2010/04/03 18:41:38 | 000,066,714 | —- | C] () – C:\Windows\SysNative\NvwsApps.xml
[2010/04/03 10:07:31 | 000,001,756 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/27 23:07:56 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/27 23:07:56 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 23:07:56 | 000,065,536 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TM.blf
[2010/03/22 06:22:55 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/22 06:22:55 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/22 06:22:55 | 000,065,536 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TM.blf
[2010/03/12 01:10:16 | 000,708,868 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/02/12 08:02:00 | 000,003,519 | —- | C] () – C:\Windows\InstText.ini
[2010/02/11 17:32:24 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/21 22:20:16 | 000,000,496 | —- | C] () – C:\Windows\SysWow64\wlan.ini
[2009/12/21 20:05:48 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\GTW32N50.dll
[2009/06/09 00:22:36 | 000,144,896 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/06/09 00:22:36 | 000,071,168 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/06/02 10:22:56 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/06/02 10:21:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/11/01 16:30:18 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/10/08 00:08:38 | 000,020,936 | —- | C] () – C:\Windows\SysWow64\instwdm.ini
[2008/10/07 23:41:40 | 000,002,560 | —- | C] () – C:\Windows\SysWow64\CtxfiRes.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/08/19 18:39:18 | 000,000,321 | —- | C] () – C:\Windows\SysWow64\kill.ini
[2008/07/11 16:22:30 | 000,000,054 | —- | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\SysWow64\OUTLPERF.INI
========== LOP Check ==========
[2010/04/16 09:34:29 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Acronis
[2009/11/13 16:05:46 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Amazon
[2009/07/13 02:26:15 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Braid
[2009/10/16 11:49:51 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/12/19 04:21:10 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Ideazon
[2009/08/29 23:18:40 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Leadertech
[2010/05/04 01:07:56 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\NCH Swift Sound
[2009/05/13 12:46:12 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\The Creative Assembly
[2009/08/16 02:55:14 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Thunderbird
[2010/05/07 13:03:04 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Windows SideBar
[2010/01/01 13:54:05 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\WinWay
[2010/02/21 02:12:39 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\yess
[2010/06/12 22:01:39 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/13 11:27:59 | 000,000,436 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{4F921297-886A-42B4-B743-9E6D5990E6A3}.job
[2010/06/13 09:53:15 | 000,000,432 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{9C87E4B8-515C-4766-9808-5C3389C31BB5}.job
[2010/06/13 11:29:59 | 000,000,432 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D705618D-2A18-4B1D-B733-4F084BB0159C}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/19 04:09:09 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/19 04:09:09 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/09/17 04:09:57 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=05001E1FACCE49DB895B8526B05C7302 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_37cb142cf6008bc1\atapi.sys
[2008/01/19 04:07:46 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008/09/17 04:09:57 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=BB55C79E0595D8CFBE4A80A3C9EB77EA – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\atapi.sys
[2009/04/11 03:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 07:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008/01/19 04:11:31 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2008/01/19 04:03:01 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006/11/02 05:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 03:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/19 03:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006/11/02 07:18:47 | 000,684,032 | —- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008/01/19 04:08:50 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/19 03:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006/11/02 07:19:09 | 000,239,616 | —- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008/01/19 04:03:55 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006/11/02 05:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 03:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
< End of Report >
Extras folder:
OTL Extras logfile created on: 6/13/2010 11:27:37 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 76.58 Gb Free Space | 41.11% Space Free | Partition Type: NTFS
Drive D: | 232.89 Gb Total Space | 104.70 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 71.65 Gb Free Space | 15.38% Space Free | Partition Type: NTFS
Drive G: | 1.86 Gb Total Space | 1.69 Gb Free Space | 90.55% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GARY-PC
Current User Name: Gary
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with FastStone] – "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with FastStone] – "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 86 63 CB B5 79 3C C9 01 [binary data]
"VistaSp2" = 29 89 C8 08 91 E3 C9 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AF0F4E2-A8EC-4683-BD7C-F27A7AB817B0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0C30746F-169D-4B67-AAC1-D67DEF315C49}" = rport=10243 | protocol=6 | dir=out | app=system |
"{19D77A63-51E5-4F47-A40E-7365E6249FCC}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1B1D802F-7E56-4DB4-886F-42F77B3830DC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2162921C-81FF-49FF-9D5E-5639C5F4CE81}" = lport=137 | protocol=17 | dir=in | app=system |
"{27179819-2137-43D7-90C9-13322E78F48F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{27593AB3-F3C1-45E8-A52F-E48073D6B5F6}" = lport=139 | protocol=6 | dir=in | app=system |
"{39FAA7C2-3783-48E4-BBB6-4BAFDFE4229E}" = rport=137 | protocol=17 | dir=out | app=system |
"{3FBE4DC1-0A44-4563-A0D0-8E8E10454D9D}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{44B5A9B6-93F5-4A26-BFFD-7C28F1E20274}" = rport=445 | protocol=6 | dir=out | app=system |
"{4C465E55-FD53-47BE-9CFB-7B28B84FD572}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6CC010D6-7D66-48D8-830A-D2EB31331B1B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7142FA0D-7249-4EC1-B365-7A38E845ED05}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7262555C-5D75-4129-82B1-27CCB0904502}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A40EC0D9-C77D-40F3-9422-458D7F53603D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{B70D60D9-9CDC-445F-9EE0-6FFF2793ECBB}" = lport=445 | protocol=6 | dir=in | app=system |
"{D7AE2A3E-3E84-4412-9665-5483F66FEEE6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E7D114D5-6A48-41C7-A804-3074D4902F0C}" = rport=138 | protocol=17 | dir=out | app=system |
"{EDEE8D63-80E6-4B7E-A631-769476616B5B}" = rport=139 | protocol=6 | dir=out | app=system |
"{EEACD182-196D-4A86-AEB6-2A8150ADDC78}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F2336454-9EE9-4E71-AFAB-18CBEF17932D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F71E97FF-F58E-408E-8333-3959350AD9BF}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010059A8-1BBC-4481-9BF0-097906AE8535}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{05CB3FB8-26A6-4FBD-A186-B7CE7E39D5FC}" = protocol=17 | dir=in | app=c:\program files\softscript\ssivoxplayer\ssivoxplayer.exe |
"{0CB40D16-4698-4910-BC56-9E48A552646D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{11DA3D27-46A8-4B2B-884D-239AA1600AE1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{14E388F4-B25C-448C-8535-DD7A7E005A00}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc.exe |
"{152B843E-7AEC-4853-8C91-0096A7DD8062}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{15EE0C52-48C1-40EF-8807-FB773E1E1DA9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1C479EFB-DABC-4C8C-896B-2A2BF8B5F862}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war demo\empire.exe |
"{1FCAFAB1-7945-42B9-A8C4-2114DD17F65D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1FF5462D-3901-4975-91F0-CF631602EA8D}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{2824FCFF-4321-4FFE-B092-66A482EF1E60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{2E061F15-FC71-48C9-B062-04B60FC2B40F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{304BFF29-786C-4BA3-8ECB-DE6B1FA5C4DB}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc.exe |
"{372C394B-4164-4BD8-9090-FD944CC70AF5}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{376938EF-93DD-4485-95C2-D973712BA545}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3814265C-BBFF-49A9-943E-A9B6A214AB9D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3FAE04D3-57C0-416B-A468-AE9DF2EFE07C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{401C830C-E908-4339-95AA-F308BA03D370}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{41B50745-FC21-4EC7-97AF-F6C69C701076}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{42DEF683-54F0-419C-8309-13DC7A18A24C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{45DC0035-BBA2-4502-9252-6E727D7D6D69}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{4A65A611-879E-467D-B71A-C1989F0779B5}" = protocol=17 | dir=in | app=c:\program files (x86)\softscript\sftrclient\sftrclient.exe |
"{56B3C475-D3C3-48BB-BCB2-DDF21D6633BB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{571B517F-0943-4D42-B81B-E6BE3F8248D3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5B3CE2AD-85F3-45FC-9C61-DBE8BA1565B6}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6FE48371-4108-4899-B2D9-E81902BA2481}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{708F0CF8-0DF6-485C-B93F-D2D03557779D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7719E841-0F04-482B-8699-51ECDA5DBCCB}" = protocol=6 | dir=in | app=c:\program files\softscript\ssivoxplayer\ssivoxplayer.exe |
"{7FF7A18F-306B-40BD-B867-F7BA6FB719AC}" = protocol=6 | dir=out | app=system |
"{85FF9D46-55CF-4BB1-9051-D8C9CAECBC59}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war demo\empire.exe |
"{88830778-662D-48C8-9FEB-9287AAA16665}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{8DCF1E75-7EE9-44F7-AE75-5C9F36351E2D}" = protocol=6 | dir=in | app=c:\program files (x86)\softscript\sftrclient\sftrclient.exe |
"{90A826C5-1A26-4037-A361-F4B86472FEB1}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{92F2CE6F-F87F-4416-841D-01E3BAC22799}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{95589064-0229-421D-AD41-4B3B7CC8CAFF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{975BF5AF-4655-4891-AB25-F455D6714DFE}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{99F04F04-DE5C-4A50-90AE-0076E28A44EE}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{9A62D37A-D2E7-4D81-BEA6-830CEFBEBE9A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A3588213-55D3-4B79-9E5D-609C492BAA4F}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{A7EC658A-8B0B-4C54-B09A-B73813F2FC76}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"{B6C0F68D-85DA-4289-A75F-12BE45F85F93}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{B7D52360-345C-460E-A857-D7C3381477C3}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{BD5B17FD-4810-490C-B22A-92D376E68824}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C6836A8B-E587-4CE9-BE13-E711A9707096}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CB217C87-DF01-40BA-A345-9E6E8871F410}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CD89012F-F8AE-45C3-B685-4D8B61519740}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{D83904DB-BEEF-4938-86DA-DA2916E7C9C9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DEC81621-5A6B-4C40-A56B-A4EEC98603A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{E9285948-FF70-4B34-94FA-9D88B8606525}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{F43933BB-9A0E-4CA2-8A5F-B26203FE81B7}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{F5C17BFB-A96A-404F-9927-C5EE136740D5}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{F726EB6C-F8B2-43D7-9EB2-3E505F9916E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FA7A6F81-A806-473B-A8E0-DD501EA4CEE0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"TCP Query User{130C32A7-368B-4D64-8FF2-914768682D83}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe |
"TCP Query User{1662442B-B39D-4AC6-9396-8F89229C1BC5}C:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{24F1B28C-BD60-47C7-8050-0F63B581F90C}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe |
"TCP Query User{33459EF0-ADE0-4671-8F2B-7FF3617F4C4C}C:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{3B8113D9-0CB5-4DD5-A693-0F234421B283}D:\world of warcraft\repair.exe" = protocol=6 | dir=in | app=d:\world of warcraft\repair.exe |
"TCP Query User{6B2AA169-9F55-4045-988F-4F32FC125779}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{77251446-8963-4155-81CC-0A943703ED23}C:\program files (x86)\quicktime\quicktimeplayer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\quicktime\quicktimeplayer.exe |
"TCP Query User{7D1ADD4A-A746-4A9F-B552-E47DCFFE064A}D:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe |
"TCP Query User{7F954C0A-DB8E-493A-9B51-86705AF3179A}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe |
"TCP Query User{8C1E2163-A889-432A-8E30-58E28E5B300E}C:\program files (x86)\gretech\gomplayer\gom.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gretech\gomplayer\gom.exe |
"TCP Query User{992675CF-CF4D-44F0-90FA-402FF32A433A}C:\program files (x86)\gigabyte\@bios\gwflash.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gigabyte\@bios\gwflash.exe |
"TCP Query User{9B0094FD-A87C-44F4-AEA2-82303B6AFC60}C:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{AD42D239-151A-4D3B-BBF6-0AD7699CBA23}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{EA9BC793-128C-4451-BBA9-E0269A4C2ED3}D:\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"UDP Query User{3680E554-CF1C-4B5A-896C-EE71B30A2CD1}C:\program files (x86)\gigabyte\@bios\gwflash.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gigabyte\@bios\gwflash.exe |
"UDP Query User{3684E0B0-D55C-4855-BD7C-C8F11D49DC8E}C:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{4B58CBD4-56B8-4FFE-953F-CAB67D060A59}C:\program files (x86)\quicktime\quicktimeplayer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\quicktime\quicktimeplayer.exe |
"UDP Query User{58888D5F-6086-4277-8500-C4E67707FB9A}D:\world of warcraft\repair.exe" = protocol=17 | dir=in | app=d:\world of warcraft\repair.exe |
"UDP Query User{674592F5-DF3F-46B0-91E0-FCA1DE7FE4D2}D:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe |
"UDP Query User{6BBB18A3-4153-40A1-B7B1-D7BB7DF354CC}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe |
"UDP Query User{7E1F2FB1-81D3-4BA6-87F7-E9CCA773A8D1}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{8364F391-8CFF-44A2-993F-CFF103142A57}C:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{8C270C61-7774-4FB1-9BA8-0B143CCDB9BE}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe |
"UDP Query User{A8569EB8-3C63-476F-B6AD-2FF5A4D19816}D:\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"UDP Query User{B1A79019-C0BC-4FB6-BFAB-414D6F91522F}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{B9C5AF96-BB88-40CA-AFC5-0B531EC3C1CF}C:\program files (x86)\gretech\gomplayer\gom.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gretech\gomplayer\gom.exe |
"UDP Query User{DB56F0C1-35B3-4634-BF0A-0A24ABCB7E3B}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe |
"UDP Query User{DB58C517-8113-4E2A-8434-F966CEE7775B}C:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{5EBE0F1F-45DF-4298-AC6B-E8E54EAEC834}" = Microsoft IntelliPoint 7.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F7513E19-6224-485E-988D-9BF45BE64B53}" = Windows Live Family Safety
"Defraggler" = Defraggler
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.03
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
"{DFACE88E-BFD1-4E1F-AF5C-100C979A12B0}" = WinWay Resume Deluxe
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ALchemy" = Creative ALchemy
"AudioCS" = Creative Audio Control Panel
"CCleaner" = CCleaner
"Console Launcher" = Creative Console Launcher
"Cool Timer_is1" = Cool Timer 3.6
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"Creative Volume Panel" = Volume Panel
"FastStone Image Viewer" = FastStone Image Viewer 3.9
"GOM Player" = GOM Player
"Instant Text V Pro" = Instant Text V Pro
"Karen's Alarm Clock" = Karen's Alarm Clock
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.2
"OpenAL" = OpenAL
"Picasa 3" = Picasa 3
"ProcessScanner_is1" = Uniblue ProcessScanner
"RealPlayer 6.0" = RealPlayer
"Samsung ML-1710 Series" = Samsung ML-1710 Series
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Steam App 12900" = Audiosurf
"Steam App 18300" = Spectraball
"Steam App 400" = Portal
"Stedmans Spell Checker Setup_is1" = Stedmans Spell Checker Setup
"Switch" = Switch Sound File Converter
"SystemRequirementsLab" = System Requirements Lab
"VLC media player" = VLC media player 1.0.5
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wisdom-soft ScreenHunter 5.0 Free" = Wisdom-soft ScreenHunter 5.0 Free
"XiphQT" = Xiph QuickTime Components
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Octoshape Streaming Services" = Octoshape Streaming Services
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/10/2010 2:19:23 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 2:36:25 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 5:47:25 PM | Computer Name = Gary-PC | Source = EventSystem | ID = 4609
Description =
Error - 6/10/2010 5:48:28 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 5:48:28 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/11/2010 3:49:03 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/11/2010 3:49:03 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/12/2010 6:16:11 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/13/2010 9:51:53 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/13/2010 9:51:53 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
[ System Events ]
Error - 6/10/2010 6:03:33 PM | Computer Name = Gary-PC | Source = DCOM | ID = 10005
Description =
Error - 6/11/2010 2:19:51 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10005
Description =
Error - 6/11/2010 3:46:27 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10010
Description =
Error - 6/11/2010 3:47:54 AM | Computer Name = Gary-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0016E65A2068 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 6/11/2010 3:49:23 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 6/11/2010 3:52:37 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer Samsung ML-1710 Series with
shared resource name Samsung ML-1710 Series. Error 2114. The printer cannot be
used by others on the network.
Error - 6/11/2010 3:53:54 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 6/12/2010 3:08:02 PM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 6/13/2010 9:51:05 AM | Computer Name = Gary-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0016E65A2068 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 6/13/2010 9:52:28 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >