Run OTL again and change the Extra registry button from none to use safe list
Regular log:
OTL logfile created on: 8/5/2010 5:13:23 PM - Run 6
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Owner\Desktop\New Folder
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 257.00 Mb Available Physical Memory | 50.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 33.55 Gb Free Space | 60.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DADSLAPTOP
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\New Folder\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Alltel Broadband Connect\AvqAutorun.exe ()
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe ( )
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\Desktop\New Folder\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\oxituxunakamika.dll ()
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (NWDLS) – C:\WINDOWS\System32\NWDLS.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (ManyCam) – C:\WINDOWS\System32\DRIVERS\ManyCam.sys File not found
DRV - (hwdatacard) – C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys File not found
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PTUMWVsp) – C:\WINDOWS\system32\drivers\PTUMWVsp.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTUMWNET) – C:\WINDOWS\system32\drivers\PTUMWNET.sys (DEVGURU Co., LTD.)
DRV - (PTUMWMdm) – C:\WINDOWS\system32\drivers\PTUMWMdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (PTUMWFLT) – C:\WINDOWS\system32\drivers\PTUMWFLT.sys (DEVGURU Co., LTD.)
DRV - (PTUMWCDF) – C:\WINDOWS\system32\drivers\PTUMWCDF.sys (DEVGURU Co., LTD.)
DRV - (PTUMWBus) – C:\WINDOWS\system32\drivers\PTUMWBus.sys (DEVGURU Co., LTD.)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (winusb) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (NETGEAR_WPN511_SERVICE) – C:\WINDOWS\system32\drivers\wpn511.sys (Atheros Communications, Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (maestro) ESS Maestro Audio Driver (WDM) – C:\WINDOWS\system32\drivers\es198xdl.sys (ESS Technology, Inc.)
DRV - (AWINDIS5) – C:\WINDOWS\system32\AWINDIS5.SYS (AMBIT Microsystems Corporation.)
DRV - (WDHAALBA) – C:\WINDOWS\system32\drivers\WDHAALBA.sys (3Com Corporation)
DRV - (atimtai) – C:\WINDOWS\system32\drivers\atimtai.sys (ATI Technologies Inc.)
DRV - (EL556ND5) – C:\WINDOWS\system32\drivers\EL556ND5.sys (3Com Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://msn.com/"
FF - prefs.js..network.proxy.autoconfig_url: "
http://localhost:9100/proxy.pac"
FF - HKLM\software\mozilla\Firefox\Extensions\\{135B5538-0D8D-4728-BDEE-04ADCAC68662}: C:\Documents and Settings\Owner\Local Settings\Application Data\{135B5538-0D8D-4728-BDEE-04ADCAC68662} [2010/07/16 16:35:44 | 000,000,000 | —D | M]
[2010/03/12 20:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/03/12 20:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/07/17 18:30:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\dmqhvk52.default\extensions
[2010/07/16 16:23:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\dmqhvk52.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
O1 HOSTS File: ([2006/02/28 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No CLSID value found.
O4 - HKLM..\Run: [{9AA8FE27-89A8-99BA-8b85-9AE9B9ABA99F}] C:\Program Files\Alltel Broadband Connect\AvqAutoRun.exe ()
O4 - HKLM..\Run: [Aciruduy] C:\WINDOWS\oxituxunakamika.DLL ()
O4 - HKLM..\Run: [AS00_WPN511] C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe ( )
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/01 07:20:43 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{5e766f60-39c7-11df-b5f2-0004765121dc}\Shell - "" = AutoRun
O33 - MountPoints2\{5e766f60-39c7-11df-b5f2-0004765121dc}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5e766f60-39c7-11df-b5f2-0004765121dc}\Shell\AutoRun\command - "" = E:\Start.exe – File not found
O33 - MountPoints2\{5e766f60-39c7-11df-b5f2-0004765121dc}\Shell\menu1\command - "" = E:\Start.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68130555115339776)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/05 15:41:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\New Folder
[2010/08/04 20:20:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\gmer
[2010/08/04 10:49:33 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/04 10:13:12 | 002,077,424 | R— | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\WindowsXP-KB894391-x86-ENU.exe
[2010/08/03 03:02:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/21 13:25:21 | 000,000,000 | —D | C] – C:\Program Files\CleanCache 3.0
[2010/07/19 04:03:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/07/19 04:03:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/19 04:03:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/19 04:03:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/19 04:03:02 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/18 16:33:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Knights of Avalon
[2010/07/18 12:20:32 | 000,000,000 | -HSD | C] – C:\found.000
[2010/07/16 22:21:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\WMTools Downloaded Files
[2010/07/16 16:52:43 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/16 16:52:05 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/16 16:35:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{135B5538-0D8D-4728-BDEE-04ADCAC68662}
[2010/07/16 14:08:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla
[2010/07/16 02:17:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ManyCam
[2010/07/14 10:23:08 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/12 19:47:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder (3)
[2010/07/10 17:38:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder (2)
[2010/07/09 19:50:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\ManyCam
[2010/07/08 15:21:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My Received Files
[2010/07/08 15:06:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Tracing
[2010/07/08 15:04:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2010/07/08 15:04:33 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2010/07/08 15:03:55 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/07/08 13:57:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder
[2010/07/08 11:22:08 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/07/08 11:22:07 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/07/07 14:14:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/05 17:14:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2C12008B-DCD1-4FEE-99CC-4B6BF5A15177}.job
[2010/08/05 17:10:55 | 000,622,592 | —- | M] () – C:\Documents and Settings\Owner\My Documents\db1.mdb
[2010/08/05 17:10:52 | 000,010,240 | —- | M] () – C:\Documents and Settings\Owner\My Documents\LCDGMSlist.wdb
[2010/08/05 16:42:46 | 000,000,374 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/08/05 16:41:14 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/05 16:41:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 16:40:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 16:40:54 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2010/08/05 16:39:53 | 003,670,016 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/08/05 16:39:53 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/08/05 16:39:36 | 000,025,600 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Starfox Timeline.doc
[2010/08/05 14:32:07 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/05 02:07:20 | 001,982,936 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/08/05 01:58:27 | 000,000,000 | —- | M] () – C:\WINDOWS\Rnipanuveruq.bin
[2010/08/04 19:20:54 | 000,284,915 | R— | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/08/04 10:57:02 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/04 10:49:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2010/08/04 00:00:55 | 000,000,712 | —- | M] () – C:\Documents and Settings\Owner\My Documents\GHremoval.bat
[2010/08/04 00:00:40 | 000,000,527 | —- | M] () – C:\Documents and Settings\Owner\My Documents\GHundo.bat
[2010/08/04 00:00:36 | 002,077,424 | R— | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\WindowsXP-KB894391-x86-ENU.exe
[2010/08/03 03:02:30 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/03 02:16:49 | 000,000,120 | —- | M] () – C:\WINDOWS\Opevequfiraw.dat
[2010/07/31 13:33:49 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/07/30 21:41:52 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/07/29 21:15:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/29 16:47:22 | 000,024,957 | —- | M] () – C:\Documents and Settings\Owner\My Documents\LinkGee.jpg
[2010/07/29 16:27:06 | 000,234,375 | —- | M] () – C:\Documents and Settings\Owner\My Documents\1280434737697.jpg
[2010/07/29 10:53:10 | 000,088,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\EXPRESS.doc 2.doc
[2010/07/22 11:49:28 | 000,024,064 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/17 18:35:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\Application Data\.googlewebacchosts
[2010/07/16 14:54:21 | 000,000,800 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/15 10:41:06 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/14 10:48:07 | 000,000,215 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Tom Clancy's Ghost Recon.url
[2010/07/12 20:40:25 | 000,027,136 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Nathan Lipke Resume -.doc
[2010/07/11 22:12:17 | 000,000,815 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/08 20:48:19 | 000,000,572 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Localnet.lnk
[2010/07/08 16:33:20 | 001,423,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/08 15:06:13 | 000,023,800 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/08 14:02:46 | 000,073,216 | —- | M] () – C:\Documents and Settings\Owner\My Documents\SCREW YOU Keynesian economics.doc
[2010/07/07 11:49:51 | 000,001,791 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/06 18:52:36 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/08/05 17:10:52 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\My Documents\LCDGMSlist.wdb
[2010/08/05 16:39:36 | 000,025,600 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Starfox Timeline.doc
[2010/08/05 01:31:17 | 536,375,296 | -HS- | C] () – C:\hiberfil.sys
[2010/08/04 19:31:59 | 000,284,915 | R— | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/08/04 11:19:34 | 000,000,712 | —- | C] () – C:\Documents and Settings\Owner\My Documents\GHremoval.bat
[2010/08/04 10:49:34 | 000,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2010/08/04 00:00:39 | 000,000,527 | —- | C] () – C:\Documents and Settings\Owner\My Documents\GHundo.bat
[2010/07/29 16:47:27 | 000,024,957 | —- | C] () – C:\Documents and Settings\Owner\My Documents\LinkGee.jpg
[2010/07/29 16:28:22 | 000,234,375 | —- | C] () – C:\Documents and Settings\Owner\My Documents\1280434737697.jpg
[2010/07/28 01:18:49 | 000,088,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\EXPRESS.doc 2.doc
[2010/07/22 16:30:08 | 000,622,592 | —- | C] () – C:\Documents and Settings\Owner\My Documents\db1.mdb
[2010/07/19 13:29:56 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/16 16:35:46 | 000,000,120 | —- | C] () – C:\WINDOWS\Opevequfiraw.dat
[2010/07/16 16:35:46 | 000,000,000 | —- | C] () – C:\WINDOWS\Rnipanuveruq.bin
[2010/07/16 14:54:18 | 000,000,800 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/14 10:48:07 | 000,000,215 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Tom Clancy's Ghost Recon.url
[2010/07/12 20:07:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Nathan Lipke Resume -.doc
[2010/07/11 21:08:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\.googlewebacchosts
[2010/07/08 20:48:19 | 000,000,572 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Localnet.lnk
[2010/07/07 13:05:36 | 000,073,216 | —- | C] () – C:\Documents and Settings\Owner\My Documents\SCREW YOU Keynesian economics.doc
[2010/04/20 21:07:55 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/27 13:42:23 | 000,010,440 | —- | C] () – C:\WINDOWS\System32\ptumwcit.dll
[2010/03/07 19:23:52 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/03/07 19:22:49 | 000,000,079 | —- | C] () – C:\WINDOWS\EPSCX7400.ini
[2010/03/02 23:22:38 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2010/03/02 22:06:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/01 07:42:40 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\kill.dll
[2006/02/28 08:00:00 | 000,178,688 | —- | C] () – C:\WINDOWS\oxituxunakamika.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/03/01 07:20:43 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/05/21 22:51:27 | 000,000,212 | RHS- | M] () – C:\boot.ini
[2010/03/01 07:20:43 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/05 02:18:02 | 000,000,105 | —- | M] () – C:\gi.txt
[2010/08/05 16:40:54 | 536,375,296 | -HS- | M] () – C:\hiberfil.sys
[2010/03/01 07:20:43 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/03/01 07:20:43 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/03/01 19:16:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/05 16:40:52 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/03/01 07:19:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010/01/12 14:26:36 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/01/12 14:26:36 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/01/12 14:26:36 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 20:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 20:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/13 20:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-15 14:41:07
< End of report >
Here's the extras:
OTL Extras logfile created on: 8/5/2010 5:13:23 PM - Run 6
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Owner\Desktop\New Folder
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 257.00 Mb Available Physical Memory | 50.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 33.55 Gb Free Space | 60.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DADSLAPTOP
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Documents and Settings\Owner\Local Settings\Temp\usmt\migwiz.exe" = C:\Documents and Settings\Owner\Local Settings\Temp\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – File not found
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Steam\steamapps\common\altitude\altitude.exe" = C:\Program Files\Steam\steamapps\common\altitude\altitude.exe:*:Enabled:altitude – ()
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Steam\steamapps\common\ghost recon\GhostRecon.exe" = C:\Program Files\Steam\steamapps\common\ghost recon\GhostRecon.exe:*:Enabled:Tom Clancy's Ghost Recon – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1C336D20-A089-4818-9C56-96AD81BF5A11}" = PANTECH USB Modem V2
"{20431786-1593-4A49-A48F-B062410D249B}" = Mobile PhoneTools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24ADC0E4-8D3E-40C4-9106-F2DE5E9112F1}" = EPSON Stylus CX7400 Series Scanner Driver Update
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{6336C0CC-BA32-4949-9D3D-C86B76147CCA}" = Alltel Broadband Connect
"{67A15C5A-67C9-4F7A-B151-0CCE6C008487}" = NETGEAR RangeMax™ Wireless PC Card WPN511
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CleanCache 3.0_is1" = CleanCache 3.5
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"FLV Player" = FLV Player 2.0 (build 25)
"Google Chrome" = Google Chrome
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"RarZilla Free Unrar" = RarZilla Free Unrar
"Steam App 15300" = Tom Clancy's Ghost Recon
"Steam App 400" = Portal
"Steam App 41300" = Altitude
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WETCable" = Windows Easy Transfer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/5/2010 1:54:26 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 8/5/2010 1:55:44 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 1:55:53 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1001
Description = Fault bucket 1950385353.
Error - 8/5/2010 2:01:17 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 2:11:57 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 2:32:07 PM | Computer Name = DADSLAPTOP | Source = Google Update | ID = 20
Description =
Error - 8/5/2010 3:14:19 PM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
[ Application Events ]
Error - 8/5/2010 1:54:26 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 8/5/2010 1:54:27 AM | Computer Name = DADSLAPTOP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 8/5/2010 1:55:44 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 1:55:53 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1001
Description = Fault bucket 1950385353.
Error - 8/5/2010 2:01:17 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 2:11:57 AM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
Error - 8/5/2010 2:32:07 PM | Computer Name = DADSLAPTOP | Source = Google Update | ID = 20
Description =
Error - 8/5/2010 3:14:19 PM | Computer Name = DADSLAPTOP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x001a3b57.
[ System Events ]
Error - 8/5/2010 2:08:54 AM | Computer Name = DADSLAPTOP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 8/5/2010 2:08:55 AM | Computer Name = DADSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The FLEXnet Licensing Service service failed to start due to the following
error: %%3
Error - 8/5/2010 2:10:20 PM | Computer Name = DADSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The FLEXnet Licensing Service service failed to start due to the following
error: %%3
Error - 8/5/2010 2:10:29 PM | Computer Name = DADSLAPTOP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 8/5/2010 2:10:29 PM | Computer Name = DADSLAPTOP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 8/5/2010 3:32:03 PM | Computer Name = DADSLAPTOP | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Windows Management Instrumentation
service, but this action failed with the following error: %%1056
Error - 8/5/2010 3:52:00 PM | Computer Name = DADSLAPTOP | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Windows Management Instrumentation
service, but this action failed with the following error: %%1056
Error - 8/5/2010 4:41:09 PM | Computer Name = DADSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The FLEXnet Licensing Service service failed to start due to the following
error: %%3
Error - 8/5/2010 4:41:22 PM | Computer Name = DADSLAPTOP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 8/5/2010 4:41:22 PM | Computer Name = DADSLAPTOP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
< End of report >