OTL Extras logfile created on: 6/20/2010 5:12:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Stuart Southerland\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 713.44 Gb Free Space | 76.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298.08 Gb Total Space | 264.52 Gb Free Space | 88.74% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: STUART-OF1P8HQI
Current User Name: Stuart Southerland
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager – (Electronic Arts)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\steamapps\common\painkiller black edition\Bin\Painkiller.exe" = C:\Program Files\Steam\steamapps\common\painkiller black edition\Bin\Painkiller.exe:*:Enabled:Painkiller: Black Edition – (People Can Fly)
"C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\witcher.exe" = C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\witcher.exe:*:Enabled:The Witcher: Enhanced Edition – (CD Projekt Red)
"C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\djinni!.exe" = C:\Program Files\Steam\steamapps\common\the witcher enhanced edition\System\djinni!.exe:*:Enabled:The Witcher: Enhanced Edition – (CD Projekt Red)
"C:\Program Files\Steam\steamapps\common\stalker shadow of chernobyl\bin\XR_3DA.exe" = C:\Program Files\Steam\steamapps\common\stalker shadow of chernobyl\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R.: Shadow of Chernobyl – ()
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe" = C:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe:*:Enabled:Company of Heroes – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\company of heroes\help.htm" = C:\Program Files\Steam\steamapps\common\company of heroes\help.htm:*:Enabled:Company of Heroes – ()
"C:\Program Files\Steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe" = C:\Program Files\Steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe:*:Enabled:Relic Patch Download Manager – (THQ Canada Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\THQ\Dawn Of War\W40k.exe" = C:\Program Files\THQ\Dawn Of War\W40k.exe:*:Enabled:W40k – (THQ Canada Inc.)
"C:\Program Files\Steam\steamapps\common\the secret of monkey island special edition\MISE.exe" = C:\Program Files\Steam\steamapps\common\the secret of monkey island special edition\MISE.exe:*:Enabled:The Secret of Monkey Island: Special Edition – ()
"C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe" = C:\Program Files\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game – (BioWare)
"C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe" = C:\Program Files\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher – (BioWare)
"C:\Program Files\2K Games\BioShock 2\SP\Builds\Binaries\Bioshock2.exe" = C:\Program Files\2K Games\BioShock 2\SP\Builds\Binaries\Bioshock2.exe:*:Enabled:BioShock 2 – (Take-Two Interactive Software)
"C:\Program Files\2K Games\BioShock 2\MP\Builds\Binaries\Bioshock2.exe" = C:\Program Files\2K Games\BioShock 2\MP\Builds\Binaries\Bioshock2.exe:*:Enabled:BioShock 2 Multiplayer – (2K Games)
"C:\Program Files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe" = C:\Program Files\Steam\steamapps\common\mass effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect – (BioWare)
"D:\Setup.exe" = D:\Setup.exe:*:Enabled:Setup – File not found
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe" = C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe:*:Enabled:Serious Sam HD: The First Encounter Demo – (Croteam)
"C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD.exe" = C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD.exe:*:Enabled:Serious Sam HD: The First Encounter – (Croteam)
"C:\Program Files\Steam\steamapps\common\torchlight\Torchlight.exe" = C:\Program Files\Steam\steamapps\common\torchlight\Torchlight.exe:*:Enabled:Torchlight Demo – (Runic Games, Inc.)
"C:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe" = C:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe:*:Enabled:Warhammer® 40,000â„¢: Dawn of War® II – (THQ Canada Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{0B25271C-C90B-056F-B4B1-84DFCC905497}" = ATI Catalyst Install Manager
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP600" = Canon MP600
"{141C141A-0DB8-E6E5-59AA-27576C20B75D}" = CCC Help English
"{1648DB98-AE62-6E92-F418-8A9ECCA078A9}" = Catalyst Control Center Graphics Previews Common
"{17200570-C3A0-DAAB-8232-491FEC0C1DF4}" = Catalyst Control Center Graphics Full Existing
"{17E83691-BC8E-BA2A-DE9B-AE845E1C2457}" = Catalyst Control Center Graphics Light
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Ethernet Utility
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3BD76F20-EAA2-012B-AE7F-000000000000}" = TurboTax 2009 wokiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3D74A25E-F4A1-DD65-3327-FEE3C85A2565}" = Catalyst Control Center HydraVision Full
"{3F64C088-9A45-41B3-8B99-71AFAB720A56}" = Sherlock Holmes versus Jack the Ripper
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2
"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1
"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018302}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018303}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000018304}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000028301}" = BioShock 2
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{605BE2E8-D0D4-C157-68FD-40A318258E54}" = ccc-core-preinstall
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{71E8DEC6-8785-B293-FA6D-7A37A3D3E773}" = ccc-core-static
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83F12F73-D52E-40C0-93B1-463C311C4E17}" = Warhammer 40,000: Dawn Of War - Gold Edition
"{85243696-5e58-4357-9cf8-3498c609941d}" = NeroLiveGadget Help
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{88713CAC-8759-6FE4-D577-A823E5865CB9}" = ccc-utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91B323B5-A79C-4D23-BD6D-046C565F9BCF}" = MadOnion.com/3DMark2001 SE
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A93FE10A-42C3-B498-2856-2BBE22481A7A}" = Catalyst Control Center Graphics Full New
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{B2BAD2AF-A391-4306-96A3-BA1139630D84}" = Catalyst Control Center InstallProxy
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F029DBBC-FBBD-20CD-7038-6A703578EC79}" = Catalyst Control Center Core Implementation
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows XP Signed Files
"{fc803937-97f8-4004-8ad1-7c6063e2712d}" = Nero 9 Trial
"{FF39FC01-819B-42E4-AE49-1968AF12DDD4}" = Dawn of War - Dark Crusade
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Abuse" = Abuse
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 5.0 Limited Edition" = Adobe Photoshop 5.0 Limited Edition
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"AudioCS" = Creative Audio Console
"BitTorrent" = BitTorrent
"CanonMyPrinter" = Canon My Printer
"Convert_is1" = Convert 1.0 beta
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.53
"Creative Jukebox Driver" = Creative Jukebox Driver
"Creative NOMAD II Driver" = Creative NOMAD II Driver
"Creative PlayCenter 2.0" = Creative PlayCenter 2
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Darkness Within: In Pursuit of Loath Nolder_is1" = Darkness Within: In Pursuit of Loath Nolder 1.00
"EADM" = EA Download Manager
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"ffdshow_is1" = ffdshow [rev 589] [2006-11-26]
"Gabriel Knight 2 - The Beast Within_is1" = Gabriel Knight 2 - The Beast Within
"Gabriel Knight 3 - Blood of the Sacred, Blood of~B6A61117_is1" = Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned
"GameSpy Arcade" = GameSpy Arcade
"Giants – Citizen Kabuto_is1" = Giants – Citizen Kabuto
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator 3.0" = Canon MP Navigator 3.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenAL" = OpenAL
"Picasa 3" = Picasa 3
"RealPlayer 12.0" = RealPlayer
"ScummVM_is1" = ScummVM 1.0.0
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 17460" = Mass Effect
"Steam App 20900" = The Witcher: Enhanced Edition
"Steam App 220" = Half-Life 2
"Steam App 280" = Half-Life: Source
"Steam App 32360" = The Secret of Monkey Island: Special Edition
"Steam App 360" = Half-Life Deathmatch: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 39530" = Painkiller: Black Edition
"Steam App 41020" = Serious Sam HD: The First Encounter Demo
"Steam App 41510" = Torchlight Demo
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 4500" = S.T.A.L.K.E.R.: Shadow of Chernobyl
"Steam App 4560" = Company of Heroes
"The Penal Zone" = Sam and Max - The Devil's Playhouse - The Penal Zone
"The Tomb of Sammun-Mak" = Sam and Max - The Devil's Playhouse - The Tomb of Sammun-Mak
"TotalRecorder" = Total Recorder 8.0
"TurboTax 2009" = TurboTax 2009
"Under a Killing Moon_is1" = Under a Killing Moon
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Application Detect
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/21/2010 10:22:58 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 10:41:54 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 11:39:47 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 11:52:41 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 11:58:43 AM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 12:29:39 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 12:35:44 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
Error - 2/21/2010 1:21:08 PM | Computer Name = STUART-OF1P8HQI | Source = MsiInstaller | ID = 11316
Description = Product: Microsoft Games for Windows - LIVE Redistributable – Error
1316. A network error occurred while attempting to read from the file: c:\17a73b708cb6ce6b89e692096d80746a\pkg\XLiveUpdate.msi
Error - 2/21/2010 7:43:49 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x0038777f.
Error - 2/21/2010 8:45:42 PM | Computer Name = STUART-OF1P8HQI | Source = Application Error | ID = 1000
Description = Faulting application bioshock2.exe, version 1.0.0.1, faulting module
bioshock2.exe, version 1.0.0.1, fault address 0x003e9dff.
[ System Events ]
Error - 6/19/2010 7:33:30 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 6/19/2010 8:24:32 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 6/19/2010 8:24:32 AM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 6/19/2010 4:44:15 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 6/19/2010 4:44:15 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 6/20/2010 8:08:36 AM | Computer Name = STUART-OF1P8HQI | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the machine that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 6/20/2010 4:09:54 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 6/20/2010 4:09:54 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 6/20/2010 6:08:13 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 6/20/2010 6:08:13 PM | Computer Name = STUART-OF1P8HQI | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
< End of report >
OTL logfile created on: 6/20/2010 5:12:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Stuart Southerland\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 713.44 Gb Free Space | 76.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298.08 Gb Total Space | 264.52 Gb Free Space | 88.74% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: STUART-OF1P8HQI
Current User Name: Stuart Southerland
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Stuart Southerland\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (LPDSVC) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (TotRec8) – C:\WINDOWS\system32\drivers\TotRec8.sys (High Criteria inc.)
DRV - (TotRec7) – C:\WINDOWS\system32\drivers\TotRec7.sys (High Criteria inc.)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (cpuz132) – C:\WINDOWS\system32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/17 07:11:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/17 18:29:19 | 000,000,000 | —D | M]
[2010/06/17 07:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Extensions
[2010/06/19 21:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions
[2010/06/18 22:07:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Stuart Southerland\Application Data\Mozilla\Firefox\Profiles\kxaxo6e7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/19 21:30:07 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/01/13 17:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2010/06/17 20:20:07 | 000,000,686 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [BHR] C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe File not found
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1262617144187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1262617741375 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Zapotec.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Zapotec.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/04 09:53:27 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\CDStart.exe – File not found
O33 - MountPoints2\D\Shell\Install\Command - "" = D:\Setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/04 03:41:23 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)
========== Files/Folders - Created Within 30 Days ==========
[2010/06/19 20:53:38 | 000,000,000 | —D | C] – C:\Program Files\ffdshow
[2010/06/19 20:53:16 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windows media
[2010/06/19 20:53:07 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Components
[2010/06/19 20:52:50 | 000,000,000 | —D | C] – C:\Program Files\Convert
[2010/06/19 20:52:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Desktop\H.264 to WMV-AVI Convert
[2010/06/19 03:29:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/06/18 22:03:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\Symantec
[2010/06/17 20:19:23 | 000,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 20:17:37 | 000,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2010/06/17 20:05:03 | 000,000,000 | —D | C] – C:\SDFix
[2010/06/17 18:56:23 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2010/06/17 18:41:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/06/17 18:16:08 | 000,244,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSFLXGRD.OCX
[2010/06/17 18:16:08 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/06/17 18:16:08 | 000,140,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\COMDLG32.OCX
[2010/06/17 18:16:08 | 000,132,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSINET.OCX
[2010/06/17 18:04:49 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Application Data\MSN6
[2010/06/17 07:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSN6
[2010/06/11 21:27:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/06/06 17:46:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 17:45:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/06 17:12:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\Local Settings\Application Data\diwpdegos
[2010/06/01 20:57:20 | 000,000,000 | —D | C] – C:\Program Files\Darkness Within
[2010/05/31 06:44:29 | 000,000,000 | —D | C] – C:\Program Files\DotEmu
[2010/05/31 06:43:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Stuart Southerland\My Documents\PDF documents
[2010/05/22 08:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/06/23 12:49:14 | 000,010,752 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/06/20 17:07:48 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/20 17:07:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/20 06:22:42 | 000,002,473 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/19 20:54:59 | 000,000,788 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:54:38 | 004,718,592 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\NTUSER.DAT
[2010/06/19 20:52:51 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:43:36 | 000,000,161 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Application Data\default.rss
[2010/06/19 20:43:31 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/19 20:30:11 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/19 15:43:06 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:43:06 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000004-20021102}.rfx
[2010/06/19 15:42:59 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Stuart Southerland\ntuser.ini
[2010/06/19 15:42:52 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.CDF
[2010/06/19 15:42:52 | 004,931,715 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000001-00001102-00000004-20021102}.BAK
[2010/06/19 03:29:14 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/18 22:02:21 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/17 20:42:05 | 000,000,848 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/17 20:29:51 | 000,000,611 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/17 20:29:51 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/17 20:29:51 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/06/17 20:20:07 | 000,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/06/17 20:19:23 | 000,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2010/06/17 18:41:28 | 000,015,944 | —- | M] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 07:11:54 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 15:14:06 | 000,001,740 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/14 21:07:50 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/06/10 08:39:38 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/06/03 21:59:38 | 000,002,393 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2010/06/03 18:39:24 | 000,019,968 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | M] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/05/31 09:44:18 | 000,000,588 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/05/31 06:44:31 | 000,001,599 | —- | M] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk
[2010/05/22 08:18:44 | 002,646,860 | -H– | M] () – C:\Documents and Settings\Stuart Southerland\Local Settings\Application Data\IconCache.db
[2010/05/22 07:31:56 | 000,001,234 | —- | M] () – C:\Documents and Settings\All Users\Desktop\The Tomb of Sammun-Mak.lnk
[2010/05/21 22:01:20 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/19 20:54:59 | 000,000,788 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Windows Media Player.lnk
[2010/06/19 20:53:39 | 000,005,120 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/06/19 20:53:39 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/06/19 20:52:51 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\H264VDEC.dll
[2010/06/19 20:52:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\Mpeg4SrcFlt.ax
[2010/06/19 20:52:51 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Mpeg4null.ax
[2010/06/19 20:52:51 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Mp3Decdll.dll
[2010/06/19 20:52:51 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\HIKM4DEC.dll
[2010/06/19 20:52:51 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecA.ax
[2010/06/19 20:52:51 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\Mpeg4DecV.ax
[2010/06/19 20:52:51 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\Mpeg4Splitter.ax
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\G722ADEC.dll
[2010/06/19 20:52:51 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\BSPVDEC.dll
[2010/06/19 20:52:51 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Convert.lnk
[2010/06/19 20:52:22 | 013,992,463 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\H.264 to WMV-AVI Convert.zip
[2010/06/19 03:29:14 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/17 18:41:28 | 000,015,944 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/17 18:04:49 | 000,002,473 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\HiJackThis.lnk
[2010/06/17 07:11:54 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/16 12:34:02 | 000,001,740 | -H– | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Default.rdp
[2010/06/03 18:37:40 | 000,019,968 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\Record of homeowner's.doc
[2010/06/02 21:12:27 | 000,021,504 | —- | C] () – C:\Documents and Settings\Stuart Southerland\My Documents\BC Clark Jewelers.doc
[2010/06/01 21:02:13 | 000,000,761 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Darkness Within.lnk
[2010/05/31 06:44:31 | 000,001,599 | —- | C] () – C:\Documents and Settings\Stuart Southerland\Desktop\Play Abuse.lnk
[2010/05/22 07:31:56 | 000,001,234 | —- | C] () – C:\Documents and Settings\All Users\Desktop\The Tomb of Sammun-Mak.lnk
[2010/05/21 22:01:20 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Gabriel Knight 3 - Blood of the Sacred, Blood of the Damned.lnk
[2010/02/13 20:00:24 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2010/02/13 20:00:23 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2010/01/29 21:38:16 | 000,001,769 | —- | C] () – C:\WINDOWS\Language_trs.ini
[2010/01/24 22:44:48 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/01/24 20:21:45 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/01/22 08:17:43 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2010/01/20 21:05:59 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/01/16 19:11:29 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/09 15:50:11 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2010/01/09 15:50:11 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2010/01/08 08:05:00 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\ctrldll.dll
[2010/01/07 21:15:09 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2010/01/05 09:41:16 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2010/01/05 08:19:48 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2010/01/04 19:06:19 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/01/04 19:06:19 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/01/04 19:06:18 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/01/04 19:06:18 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/01/04 11:09:37 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/01/04 09:56:35 | 000,013,552 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/01/04 09:56:35 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/01/04 09:56:26 | 000,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/08/03 01:21:54 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2009/06/23 13:29:50 | 000,049,719 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/06/23 13:29:48 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/06/23 12:51:00 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2007/08/13 21:45:02 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 18:25:18 | 000,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini
========== LOP Check ==========
[2010/01/04 11:11:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/01/04 20:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/06/17 18:41:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/01/05 19:37:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/01/22 08:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/02/14 12:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tages
[2010/01/14 22:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/03 06:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/04 20:56:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/27 20:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Bioshock2
[2010/06/05 07:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\BitTorrent
[2010/06/09 19:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Canon
[2010/01/04 11:28:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2010/02/13 22:34:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\Games
[2010/02/12 21:10:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\LucasArts
[2010/05/15 18:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\runic games
[2010/01/22 08:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\ScanSoft
[2010/02/15 09:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\ScummVM
[2010/01/04 21:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Stuart Southerland\Application Data\TotalRecorder
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2008/04/11 08:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[1 C:\*.tmp files -> C:\*.tmp -> ]
< MD5 for: AGP440.SYS >
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2003/03/31 07:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/01/04 10:13:44 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2010/01/04 10:24:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010/04/06 20:46:42 | 000,446,464 | —- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGX.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010/01/04 03:43:23 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/01/04 03:43:23 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/01/04 03:43:23 | 000,438,272 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/06 21:42:04 | 004,687,872 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\drivers\ati2mtag.sys
[2010/06/17 18:41:28 | 000,015,944 | —- | M] () – C:\WINDOWS\system32\drivers\hitmanpro35.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/04/16 08:33:36 | 000,041,472 | —- | M] (Apple, Inc.) – C:\WINDOWS\system32\drivers\usbaapl.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434
< End of report >
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-06-20 17:04:32
Windows 5.1.2600 Service Pack 3
Running: nibp2usj.exe; Driver: C:\DOCUME~1\STUART~1\LOCALS~1\Temp\kwldapob.sys
—- Kernel code sections - GMER 1.0.15 —-
.rsrc C:\WINDOWS\System32\DRIVERS\intelppm.sys entry point in ".rsrc" section [0xF764D494]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6245000, 0x235F87, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0x9ED0E300, 0x3B638, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF77D7300, 0x1BEE, 0xE8000020]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[1156] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00F9000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\wuauclt.exe[1888] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C5000A
.text C:\WINDOWS\Explorer.EXE[1960] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
—- Devices - GMER 1.0.15 —-
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A411EC5
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IWKPJMSY\1x1pixel[1].gif 0 bytes
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PHD49P98\rt-arrow[1].png 219 bytes
File C:\WINDOWS\System32\DRIVERS\intelppm.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
Thanks!