Crimea
Topic Starter
I’m trying to access www.theaa.com [U.K. car breakdown company], via www.topcashback.co.uk, a reputable U.K. cashback site, but theaa.com is continually blocked, no matter what I do. I can access it when going direct to the site.
I’ve done the following:
1. Run Microsoft FixIt 50267 to replace my MVPS Hosts file with IE7’s default, which I presume it did; rebooted; tried cashback site link again, but was still blocked.
“tradedoubler” isn’t listed as a “Restricted site” in IE7.
2. Spybot S&D 1.6.2 – couldn’t locate “tradedoubler” in the hosts list, so I disabled the list. I was still blocked, so I uninstalled Spybot, cleaned out junk files using CCleaner and Temp File Cleaner by Old Timer, rebooted and tried again – still blocked.
3. Removed the block on ad/tracking hosts, in A-squared Anti-malware 5.0.
Tracking cookies: block silently
Ad/tracking hosts: don’t block
Malware hosts: don’t block
Exploiting hosts: don’t block
Fraudulent hosts: block & notify
Hijacking hosts: block & notify
Phishing hosts: don’t block
Warez hosts: block & notify
Other malicious hosts: don’t block
[This is how it was set-up when I originally installed it and I haven’t changed it.]
Rebooted and tried to access; still blocked. Tried disabling all above “Surf protection”, but with same results.
4. Removed A-squared all together, but no change.
5. Re-installed MVPS Hosts, but nullified every instance of "tradedoubler". No change.
OTL logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
PRC - C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
PRC - C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
PRC - C:\Program Files\Raxco\PerfectDisk10\PerfectDisk.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
PRC - C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
PRC - C:\Program Files\WinSplit Revolution\WinSplit.exe ()
PRC - C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
PRC - C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
PRC - C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
PRC - C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FastStone Capture\FSCapture.exe ()
PRC - C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
PRC - C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\SnagIt 7\TscHelp.exe (TechSmith Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AnVir Task Manager\AnvirHook62.dll (AnVir Software)
MOD - C:\Program Files\WinSplit Revolution\winsplithook.dll ()
MOD - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll (SourceTec Software Co., LTD)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV - (NMIndexingService) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TuneUp.ProgramStatisticsSvc) – C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
SRV - (TuneUp.Defrag) – C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV - (DfSdkS) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe (mst software GmbH, Germany)
SRV - (NMSAccessU) – C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
SRV - (OOCleverCacheAgent) – C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
========== Driver Services (SafeList) ==========
DRV - (Video3D) – C:\WINDOWS\System32\Drivers\Video3D32.sys File not found
DRV - (p17filt) – C:\WINDOWS\System32\drivers\p17filt.sys File not found
DRV - (MEMSWEEP2) – C:\WINDOWS\System32\5.tmp File not found
DRV - (EIO) – C:\WINDOWS\System32\drivers\EIO.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Arjun\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BOCDRIVE) – C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (epmntdrv) – C:\WINDOWS\system32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\WINDOWS\system32\EuGdiDrv.sys ()
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (DefragFS) – C:\WINDOWS\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) – C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (StarPortLite) StarPort Storage Controller (Lite) – C:\WINDOWS\system32\drivers\StarPortLite.sys (Rocket Division Software)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
DRV - (anf0100.sys) – C:\WINDOWS\system32\drivers\anf0100.sys (Netmarketing Pawel Wisniewski)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (Ntfs) – C:\WINDOWS\System32\drivers\ntfs.old (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (xfilt) – C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (LHDriver) – C:\WINDOWS\system32\drivers\LHDriver.sys ()
DRV - (LADriver) – C:\WINDOWS\system32\drivers\LADriver.sys ()
DRV - (LDDriver) – C:\WINDOWS\system32\drivers\LDDriver.sys ()
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (Sparrow) – C:\WINDOWS\System32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\drivers\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\drivers\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\drivers\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\drivers\ql1280.sys (QLogic Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/08/04 20:55:42 | 000,610,637 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 16306 more lines…
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ooccctrl.exe] C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.DLL ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ShellLess] C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [ADSM] File not found
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
O4 - HKCU..\Run: [Chameleon System Monitor] C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Invisible Security] File not found
O4 - HKCU..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
O4 - HKCU..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
O4 - HKCU..\Run: [Web Video Downloader] C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
O4 - HKCU..\Run: [Winsplit] C:\Program Files\WinSplit Revolution\WinSplit.exe ()
O4 - HKCU..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
O4 - HKLM..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe ()
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - Reg Error: Value error. File not found
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O15 - HKCU\..Trusted Domains: cool.ne.jp ([]* in My Computer)
O15 - HKCU\..Trusted Domains: emjcd.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: gamehouse.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: kqzyfj.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: pipni.cz ([]* in My Computer)
O15 - HKCU\..Trusted Domains: registerapi.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: spb.ru ([]* in My Computer)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: xat.com ([]* in My Computer)
O15 - HKCU\..Trusted Ranges: Range10 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range12 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range14 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range16 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range18 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range2 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range21 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range23 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range25 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range27 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range29 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range30 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range32 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range34 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range36 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range38 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range4 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range41 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range43 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range45 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range47 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range49 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range50 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range52 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range54 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range56 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range58 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range6 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range61 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range63 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range65 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range67 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range69 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range70 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range72 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range74 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range76 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range8 ([*]in My Computer)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/su/ocx/15030/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.1)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB (TmHcmsX Control)
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2D9F7B63-EC7C-43FF-A41D-6E9EC984A5B9} https://myaccount.gateway.gov.uk/ClientObjects/GGSecSign.cab (GGSecSign Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applicatio…torLauncher.cab (Keynote Connector Launcher 2)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1197990575718 (MUWebControl Class)
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} http://esupport.epson-europe.com/selftest/…rg/ESTPTest.cab (EPSON Web Printer-SelfTest Control Class)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab (WScanCtl Class)
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} http://www.nanoscan.com/cabs/nanoinst.cab (NanoInstaller Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab (ACNPlayer2 Class)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner 4.0 Launcher)
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} http://www.freedom.net/viruscenter/onlinev…cabs/cssweb.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://vpn.pharmalink.co.uk/dana-cached/se…perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/su/ocx/15030/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O19 - User stylesheet: User Stylesheet - Reg Error: Value error.
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 17:33:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619700398653440)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/05 16:25:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Arjun\Recent
[2010/08/05 00:51:19 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/07/21 06:13:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Arjun\My Documents\Aneesoft Flash Gallery Classic GOTD Edition
[2010/07/21 06:12:23 | 000,000,000 | —D | C] – C:\Program Files\Aneesoft
[2002/04/11 09:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/05 15:48:33 | 000,002,497 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Microsoft Office Word 2003.lnk
[2010/08/05 05:46:38 | 000,000,754 | —- | M] () – C:\Documents and Settings\Arjun\Application Data\AtomicAlarmClock.ini
[2010/08/05 05:46:29 | 000,063,804 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/08/05 05:46:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 05:46:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 05:45:27 | 030,932,992 | —- | M] () – C:\Documents and Settings\Arjun\NTUSER.DAT
[2010/08/05 05:45:27 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Arjun\ntuser.ini
[2010/08/05 00:51:20 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/08/04 20:55:42 | 000,610,637 | R— | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/08/04 18:12:27 | 000,610,087 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2010/08/04 15:45:31 | 001,014,645 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-181227.backup
[2010/08/03 15:46:08 | 001,014,343 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-154531.backup
[2010/08/03 02:54:09 | 000,128,000 | —- | M] () – C:\Documents and Settings\Arjun\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/30 18:05:54 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 06:12:52 | 000,000,865 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/07/13 02:42:06 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/21 06:12:52 | 000,000,865 | —- | C] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/03/17 23:17:31 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/02/06 01:24:03 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2010/02/06 01:24:03 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2010/02/06 01:24:03 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/07/18 00:53:57 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/06/23 03:47:55 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/23 03:47:54 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/29 21:02:56 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/05/19 21:31:54 | 000,000,037 | —- | C] () – C:\WINDOWS\SWFConverter.INI
[2009/03/24 05:42:57 | 000,000,023 | —- | C] () – C:\WINDOWS\SWFDecompiler.INI
[2009/02/28 18:14:57 | 000,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/12/29 05:10:48 | 000,000,140 | —- | C] () – C:\WINDOWS\System32\09wutili.sys
[2008/11/11 01:31:48 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
[2008/10/28 00:46:42 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/10/28 00:45:39 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE DX7000FEFDG.ini
[2008/09/19 22:57:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/09/19 22:54:18 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/28 20:10:46 | 000,143,360 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/06/05 01:22:02 | 000,000,080 | —- | C] () – C:\WINDOWS\DeliveryReader.INI
[2008/05/12 21:56:47 | 000,000,144 | —- | C] () – C:\WINDOWS\ScreenHunter.INI
[2008/01/02 00:44:23 | 000,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2008/01/02 00:44:22 | 000,585,791 | —- | C] () – C:\WINDOWS\gmer.dll
[2007/10/25 11:26:48 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2007/10/23 17:02:20 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.DLL
[2007/09/22 23:43:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2007/08/08 17:30:12 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/08/02 19:11:28 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2007/08/02 19:11:14 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2007/07/31 16:39:13 | 000,014,336 | —- | C] () – C:\WINDOWS\System32\drivers\LHDriver.sys
[2007/07/31 16:39:12 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\drivers\LADriver.sys
[2007/07/31 16:39:12 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\drivers\LDDriver.sys
[2007/07/30 16:19:07 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\OctaneARM.dll
[2007/07/27 16:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 16:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/07/14 14:49:05 | 000,000,004 | —- | C] () – C:\WINDOWS\jknradee.sys
[2007/04/05 21:45:54 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2007/04/02 15:10:50 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/20 09:58:08 | 000,999,424 | —- | C] () – C:\WINDOWS\System32\FathMail.dll
[2007/02/15 18:08:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/15 17:57:01 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2007/02/15 17:37:08 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2007/02/15 17:37:08 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2007/02/15 17:37:05 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2007/02/15 17:37:04 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2007/02/14 21:38:53 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/02/14 21:38:51 | 000,021,265 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/02/14 21:38:43 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/02/06 18:29:04 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/01 10:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/06/01 10:22:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/06/01 10:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/06/01 10:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 10:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/06/01 10:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/01 10:22:00 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/12/30 21:18:26 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/12/05 21:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 14:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2005/07/07 10:26:56 | 000,005,663 | —- | C] () – C:\WINDOWS\System32\Ludap17.ini
[2005/03/08 07:17:08 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/10/11 12:19:00 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\ASUSASV2.DLL
[2004/06/11 10:39:50 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\ACNePlayer.dll
[2003/10/02 18:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/11/09 03:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2007/10/27 21:13:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/09/03 22:44:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2010/06/17 23:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/05/17 21:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eltima Software
[2008/11/02 19:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/08/13 05:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\explauncher
[2009/07/22 05:20:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2007/12/13 00:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/09/12 17:40:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/09/04 21:18:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2009/08/13 05:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\launcher
[2007/12/31 22:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeoSoftTools
[2009/10/10 04:20:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Paragon
[2008/01/01 21:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prevx
[2010/08/05 05:46:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/27 19:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2008/11/02 19:05:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2008/10/28 04:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Watermark Factory
[2010/03/27 19:28:48 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/01/14 04:55:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{5DC53E13-E865-430F-97A7-98ACA32FC3D8}
[2009/05/24 21:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Amazon
[2009/10/16 21:22:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Apowersoft
[2009/09/25 01:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Ashampoo
[2009/06/22 03:40:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Audio Recorder Titanium
[2009/12/03 19:49:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Aunsoft
[2009/09/15 00:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Auslogics
[2009/10/05 01:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Autoplay Menu Designer
[2008/08/30 21:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ComfortSoftware
[2008/11/08 02:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Conceptworld
[2010/01/02 18:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ContentGuard
[2010/06/17 23:54:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\DAEMON Tools Pro
[2008/06/23 21:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktop Mechanic
[2009/12/19 19:10:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktopicon
[2010/06/21 04:15:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Digiarty
[2009/12/19 04:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EAST Technologies
[2010/05/14 18:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Eltima Software
[2008/10/28 01:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EPSON
[2009/05/23 19:20:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Gold Wave Editor Pro
[2009/08/10 01:56:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ImgBurn
[2009/05/25 17:55:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\iRecordMax Sound Recorder
[2008/08/14 09:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Juniper Networks
[2008/08/25 02:01:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\mojosoft
[2009/08/09 22:44:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Moyea
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\NeoSoftTools
[2007/07/27 21:22:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PandoraRecovery
[2008/03/22 00:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PrevxCSI
[2009/06/18 01:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Smart Audio Editor
[2009/05/29 21:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\StarBurn
[2010/04/06 04:14:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Tidy Start Menu
[2010/03/27 19:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\TuneUp Software
[2008/06/19 20:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Uniblue
[2008/03/27 17:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\WebStripper
[2009/10/24 02:46:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Winsplit Revolution
[2010/02/10 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Zoner
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\dllcache\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\i386\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\cache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\cache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\cache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/06/17 23:48:38 | 000,697,328 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2007/02/02 17:10:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/02/02 17:10:28 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/02/02 17:10:28 | 000,917,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 212 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60466E88
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44807EFA
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0C43407A
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C265C458
@Alternate Data Stream - 186 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:408F95E5
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56AC8DD1
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EFC3A3C4
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C97C8631
@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB6AC38B
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FB286BF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
OTL Extras logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"94:TCP" = 94:TCP:*:Enabled:VRS Recording System Web Control Panel
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IpSharkk\IpSharkk.exe" = C:\Program Files\IpSharkk\IpSharkk.exe:*:Enabled:IpSharkk – (ipsharkk.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{027B7883-3778-4E8C-B3FA-0A28A3209D32}" = Pixo
"{07771631-6FE6-4D78-A705-D146C0D328A1}_is1" = Aunsoft SWF Converter version 2.0.2.35
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0EDB29CF-5FFC-4824-9F13-3D1C4286CA98}_is1" = Audio Transcoder
"{10479E5C-2EC2-4A70-A816-4B0FF3D90FCD}_is1" = 3D Ebook Cover 1.0
"{12AEE067-4646-41E8-A6EA-FB2AD0E38D30}_is1" = Moyea PPT to DVD Burner Pro version 3.3.2.172
"{13CA4073-A66B-4F07-9491-B933018E63D2}_is1" = Moyea SWF to Video Converter Pro version 3.6.2.1
"{1719FAD6-2F6A-4F5E-BF2B-1F6F6F1E3806}_is1" = AnyBizSoft PDF Password Remover (Build 1.0.4)
"{1965C9BB-9114-4A50-AEC7-E62414BB117B}" = EASEUS Data Recovery Wizard Professional 4.3.6
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C63AA59-66B2-418C-BDF5-53A534DA5690}_is1" = Sothink SWF to Video Converter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Giga Ethernet Utility
"{208B53C3-FA83-40EF-BC07-ED61E78CC12A}}_is1" = Watermark Factory 2
"{20AC583C-A6FB-410A-807D-25308225C201}" = Paint.NET v3.35
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21CA58E1-3C5F-4893-A753-EB296503073D}_is1" = Moyea PPT to Video Converter version 1.6.0.40
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 20
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{2A6F734D-84CD-4472-877A-A070D76FAE74}_is1" = AnyBizSoft PDF to PowerPoint (Build [removed])
"{2CFE4799-CB85-456C-AABE-9BA2D02D81DB}" = Sky Broadband
"{30283233-3BE6-473D-A47C-ED964A2F78B4}_is1" = Inpaint 2.3
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150210}" = J2SE Runtime Environment 5.0 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39352E3D-43FF-44E7-AC2F-0ADA04AF9BB2}_is1" = Sothink HD Movie Maker
"{4218F0E1-CBAF-4D68-B6FE-B3504770829F}" = AutoStreamer
"{4360BB46-507E-4361-8DCB-4FF9BDC9907B}" = SnagIt 7
"{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 2.5.4)
"{485DF5E7-8379-4BFA-BAE1-9B8DBFE0D6B4}" = Paragon Drive Backup™ 9 Professional
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53480390-0EC4-429E-BBEE-78E19EEB03BD}" = O&O CleverCache
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8C52A46C-7961-4A81-AB4B-92CF65CB4772}_is1" = Sothink Web Video Downloader
"{8E3F691A-4972-47FF-9E09-1981B62A5D5A}_is1" = Moyea FLV Editor Ultimate version: 1.0.1.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0AC043C-9834-4F9E-B33E-1683FFE67EA4}" = FW LiveUpdate
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35001F0-F1E4-11DD-A38B-005056C00008}" = Paragon Partition Manager™ 9.5 Professional
"{A5FF2837-59C6-425B-8652-8CD385899F3F}" = uMark Professional 1.3
"{A855D6F0-DB2E-11DE-B032-005056C00008}" = Paragon Drive Backup™ 2010 Special Edition
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.03.11
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.8.7
"{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BF50CF00-7CE6-11DE-A06C-005056C00008}" = Paragon Virtualization Manager™ 9.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3C23D52-4FE6-484D-9A8C-B0A6E2803655}}_is1" = Aneesoft Flash Gallery Classic GOTD Edition
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3490D20-3AE0-459D-AAD6-59195140EAC2}_is1" = Sothink SWF Quicker
"{DB0BB9FA-1B60-4036-8E29-3D56D8085256}" = WOT for Internet Explorer
"{DBCF0030-9149-11DE-B8B6-005056C00008}" = Paragon Drive Copy™ 9.5 Personal
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2CAFC9F-95A1-4F27-9C1D-34DC9426A81B}" = Invisible Security Full
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EDF04509-B350-4EAB-BE77-5F2C87C33B35}_is1" = MPEG Video Wizard DVD 4.0.4.114 (06/2009)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20D1291-9FB8-46B1-BE46-6282F93C20E8}" = Registry Cleaner Pro
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 9.7 Professional Edition
"44953928-E730-4e8c-A2B2-3A85BC96A3D0_is1" = FileSeek 1.7.1
"7-Zip" = 7-Zip 4.57
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe flex sdk redistributed by sothink_is1" = 3.4.0.9271.1
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adolix PDF to Image for Giveawayoftheday_is1" = Adolix PDF to Image v1.2
"Advanced Audio Titanium_is1" = Audio Recorder Titanium v6.0.2
"Aimersoft HD Video Converter GOTD Edition_is1" = Aimersoft HD Video Converter(Build [removed])
"AllMedia Grabber4.0" = AllMedia Grabber
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.4
"AnVir Task Manager" = AnVir Task Manager
"Ashampoo Burning Studio 2010_is1" = Ashampoo Burning Studio 2010
"Ashampoo Burning Studio 9_is1" = Ashampoo Burning Studio 9.12
"Ashampoo Music Studio 2009_is1" = Ashampoo Music Studio 2009
"Ashampoo Snap 3_is1" = Ashampoo Snap 3.40
"Ashampoo UnInstaller 3_is1" = Ashampoo UnInstaller 3.12
"Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"Atomic Alarm Clock_is1" = Atomic Alarm Clock 5.81
"Autoplay Menu Designer_is1" = Autoplay Menu Designer 3.4
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Avira UnErase Personal" = Avira UnErase Personal
"AviSynth" = AviSynth 2.5
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video Editor 4_is1" = AVS Video Editor 4
"BusinessCardsMX3_is1" = BusinessCardsMX 3.92
"CCleaner" = CCleaner
"Chameleon Startup Manager 3" = Chameleon Startup Manager 3.2.0.723
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Corner-A ArtStudio" = Corner-A ArtStudio
"Cover Commander" = Cover Commander 3.0 by Insofta Development
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"CSSCOD" = Command On Demand for Command Software
"Dan Elwell's Broadband Speed Test_is1" = Dan Elwell's Broadband Speed Test
"Delivery" = Delivery
"Desktop Maestro_is1" = Desktop Maestro 2.0
"Device Control" = Device Control
"Disk Investigator_is1" = Disk Investigator v1.31
"Doc Scrubber_is1" = Doc Scrubber v1.1
"DriverGuide DriverScan" = DriverGuide DriverScan
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 5.0.1 Professional
"East-Tec Backup 2009_is1" = East-Tec Backup 2009 2.3
"East-Tec Eraser 2009_is1" = East-Tec Eraser 2009 Version 9.5
"EAX" = Creative EAX Console
"EAXSet" = Creative EAX Settings
"eCover Engineer Full Version_is1" = eCover Engineer 6.0 - Full Version
"eCover Engineer v3.02 FREE ecovers pack_is1" = eCover Engineer v3.02 ecovers pack
"eCover Engineer v4 FREE ecovers pack_is1" = eCover Engineer v4 ecovers pack
"eDATA Unerase" = eDATA Unerase
"Edraw Max_is1" = Edraw Max 4
"EPSON Printer and Utilities" = EPSON Printer Software
"ESCX6900F_DX7000F User's Guide" = ESCX6900F_DX7000F User's Guide
"EsetOnlineScanner" = ESET Online Scanner
"ExpressBurn" = Express Burn
"Extra DVD Ripper Professional_is1" = Extra DVD Ripper Professional 6.43
"Fast Video Converter_is1" = Fast Video Converter 1.0
"FastStone Capture" = FastStone Capture 5.3
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"Flash Movie Player" = Flash Movie Player 1.5
"FLV Player" = FLV Player 2.0, build 24
"FREE eCovers for eCoverEngineer_is1" = FREE eCovers for eCoverEngineer from 5.0
"FREE Templates for eCoverEngineer_is1" = FREE Templates for eCoverEngineer
"FreeUndelete" = FreeUndelete
"Glary Utilities_is1" = Glary Utilities Pro 2.18.0.786
"Gold Wave Editor Pro_is1" = Gold Wave Editor Pro v10.2.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Image Mender" = Image Mender 1.1
"ImgBurn" = ImgBurn
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"iRecordMax Sound Recorder_is1" = iRecordMax Sound Recorder v7.1.3
"IrfanView" = IrfanView (remove only)
"IsoBuster_is1" = IsoBuster 2.4
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"KeynoteConnector" = Keynote Connector
"LockDisk_is1" = LockDisk 2.80
"MFZ0CODEC" = MFZ0 codec (Remove Only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MRU-Blaster_is1" = MRU-Blaster v1.5 (Database 3/28/2004)
"MultiStage Recovery_is1" = MultiStage Recovery 3.6
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PandoraRecovery" = PandoraRecovery (Remove Only)
"PDFZilla_is1" = PDFZilla V1.2.9
"PhotoPerfect Express_is1" = PhotoPerfect Express 1.00
"PKR" = PKR
"RealPlayer 6.0" = RealPlayer
"Recover PDF Password_is1" = Recover PDF Password [removed]
"Recuva" = Recuva
"Registry Cleaner Pro" = Registry Cleaner Pro
"Revo Uninstaller" = Revo Uninstaller 1.85
"ShellLess_is1" = ShellLess Explorer 1.07
"Simpo PDF Merge & Split_is1" = Simpo PDF Merge & Split 2.0.0.5
"Smart Audio Editor_is1" = Smart Audio Editor v7.7.1 Build 78
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SPEAKER" = Creative Speaker Settings
"SSC Service Utility_is1" = SSC Service Utility v4.30
"StarBurn(GiveAwayOfTheDay)_is1" = StarBurn(GiveAwayOfTheDay) Version 12 (Build 0x20090527)
"SWF & FLV Toolbox 4_is1" = SWF & FLV Toolbox 4.0 (build 4.0.0.440)
"Tidy Start Menu" = Tidy Start Menu
"Turbo File Uneraser_is1" = Turbo File Uneraser 1.1
"UltimateDefrag V1 FREE Public Domain Version" = UltimateDefrag V1 FREE Public Domain Version
"Undelete Plus_is1" = Undelete Plus 2.9
"Unlocker" = Unlocker 1.8.7
"VideoGet_is1" = VideoGet
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR archiver
"WinSplit Revolution" = WinSplit Revolution (v9.02)
"WinX Blu-ray Decrypter_is1" = WinX Blu-ray Decrypter 2.0
"WinX DVD Author_is1" = WinX DVD Author 5.5.8
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 5.9.2
"WinX HD Video Converter Deluxe GOTD Edition_is1" = WinX HD Video Converter Deluxe 3.7
"Wondershare DVD Ripper Platinum_is1" = Wondershare DVD Ripper Platinum(Build [removed])
"Wondershare DVD to Flash Converter_is1" = Wondershare DVD to Flash Converter(Build [removed])
"Wondershare Flash Slideshow Builder GAOTD Edition_is1" = Wondershare Flash Slideshow Builder ([removed])
"Wondershare Music Converter_is1" = Wondershare Music Converter(Build 1.1.0.0)
"Wondershare Photo Collage Studio GAOTD Edition_is1" = Wondershare Photo Collage Studio [removed]
"Wondershare Photo Story Gold GAOTD Edition_is1" = Wondershare Photo Story Gold GAOTD Edition [removed]
"Wondershare QuizCreator 3.0 For GOTD_is1" = QuizCreator
"Wondershare Video Converter Platinum_is1" = Wondershare Video Converter Platinum(Build [removed])
"Wondershare Video to DVD Burner_is1" = Wondershare Video to DVD Burner(Build 2.0.17)
"Wondershare Video to DVD Converter_is1" = Wondershare Video to DVD Converter(Build [removed])
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Zilla Data Nuker_is1" = Zilla Data Nuker 2.0.0.0
"Zinio Reader" = Zinio Reader
"ZonerPhotoStudio12_EN_is1" = Zoner Photo Studio 12
"ZSoft Uninstaller" = ZSoft Uninstaller 2.4.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Term_Services" = Juniper Terminal Services Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"WinDirStat" = WinDirStat 1.1.2
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 19/07/2010 23:25:31 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0666251c.
Error - 21/07/2010 01:09:02 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0486251c.
Error - 24/07/2010 00:32:24 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x07c5251c.
Error - 24/07/2010 17:24:07 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application update.exe, version 10.0.0.29, faulting module
msvcr90.dll, version 9.0.30729.4148, fault address 0x000375b4.
Error - 24/07/2010 18:15:16 | Computer Name = POWERC250107 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 26/07/2010 00:28:01 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x04b7251c.
Error - 27/07/2010 00:51:09 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0713251c.
Error - 28/07/2010 22:18:55 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x052e251c.
Error - 03/08/2010 00:37:54 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x077d251c.
Error - 03/08/2010 19:19:30 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application flvplayer.exe, version 0.0.0.0, faulting module
flashplayer.3.1.1e.ocx, version 9.0.115.0, fault address 0x000c1dc3.
[ System Events ]
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Machine Debug Manager service terminated unexpectedly. It has
done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The O&O CleverCache Agent service terminated unexpectedly. It has
done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NMSAccessU service terminated unexpectedly. It has done this
1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The PDAgent service terminated unexpectedly. It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The ProtexisLicensing service terminated unexpectedly. It has done
this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The TuneUp Program Statistics Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:46:50 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7000
Description = The EIO service failed to start due to the following error: %%2
[ TuneUp Events ]
Error - 08/05/2010 11:27:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:11', '\device\harddiskvolume1\documents
and settings\all users\application data\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','2952',0)
Error - 08/05/2010 11:27:41 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:41', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2488',0)
Error - 09/05/2010 12:13:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-09 17:13:11', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2400',0)
Error - 14/05/2010 20:48:05 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 01:48:05', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','504',0)
Error - 14/05/2010 21:09:15 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 02:09:15', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1312',0)
Error - 29/05/2010 00:12:33 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-29 05:12:33', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1428',0)
Error - 31/05/2010 14:42:03 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
SET Outdated='1'
Error - 31/05/2010 14:42:04 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
SET Outdated='1'
Error - 03/07/2010 22:59:45 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:45', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\unins000.exe','2108',0)
Error - 03/07/2010 22:59:55 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:55', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbamgui.exe','3308',0)
< End of report >
Thanks for any help you can give.
I’ve done the following:
1. Run Microsoft FixIt 50267 to replace my MVPS Hosts file with IE7’s default, which I presume it did; rebooted; tried cashback site link again, but was still blocked.
“tradedoubler” isn’t listed as a “Restricted site” in IE7.
2. Spybot S&D 1.6.2 – couldn’t locate “tradedoubler” in the hosts list, so I disabled the list. I was still blocked, so I uninstalled Spybot, cleaned out junk files using CCleaner and Temp File Cleaner by Old Timer, rebooted and tried again – still blocked.
3. Removed the block on ad/tracking hosts, in A-squared Anti-malware 5.0.
Tracking cookies: block silently
Ad/tracking hosts: don’t block
Malware hosts: don’t block
Exploiting hosts: don’t block
Fraudulent hosts: block & notify
Hijacking hosts: block & notify
Phishing hosts: don’t block
Warez hosts: block & notify
Other malicious hosts: don’t block
[This is how it was set-up when I originally installed it and I haven’t changed it.]
Rebooted and tried to access; still blocked. Tried disabling all above “Surf protection”, but with same results.
4. Removed A-squared all together, but no change.
5. Re-installed MVPS Hosts, but nullified every instance of "tradedoubler". No change.
OTL logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
PRC - C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
PRC - C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
PRC - C:\Program Files\Raxco\PerfectDisk10\PerfectDisk.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
PRC - C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
PRC - C:\Program Files\WinSplit Revolution\WinSplit.exe ()
PRC - C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
PRC - C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
PRC - C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
PRC - C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FastStone Capture\FSCapture.exe ()
PRC - C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
PRC - C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\system32\PSIService.exe ()
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\SnagIt 7\TscHelp.exe (TechSmith Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Arjun\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AnVir Task Manager\AnvirHook62.dll (AnVir Software)
MOD - C:\Program Files\WinSplit Revolution\winsplithook.dll ()
MOD - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll (SourceTec Software Co., LTD)
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV - (NMIndexingService) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TuneUp.ProgramStatisticsSvc) – C:\WINDOWS\system32\TUProgSt.exe (TuneUp Software)
SRV - (TuneUp.Defrag) – C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (PDEngine) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV - (PDAgent) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV - (DfSdkS) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe (mst software GmbH, Germany)
SRV - (NMSAccessU) – C:\Program Files\Digiarty\WinX DVD Author 5.5\NMSAccessU.exe ()
SRV - (OOCleverCacheAgent) – C:\Program Files\OO Software\CleverCache\ooccag.exe (O&O Software GmbH)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
========== Driver Services (SafeList) ==========
DRV - (Video3D) – C:\WINDOWS\System32\Drivers\Video3D32.sys File not found
DRV - (p17filt) – C:\WINDOWS\System32\drivers\p17filt.sys File not found
DRV - (MEMSWEEP2) – C:\WINDOWS\System32\5.tmp File not found
DRV - (EIO) – C:\WINDOWS\System32\drivers\EIO.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Arjun\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BOCDRIVE) – C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (epmntdrv) – C:\WINDOWS\system32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\WINDOWS\system32\EuGdiDrv.sys ()
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (DefragFS) – C:\WINDOWS\System32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) – C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV - (StarPortLite) StarPort Storage Controller (Lite) – C:\WINDOWS\system32\drivers\StarPortLite.sys (Rocket Division Software)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()
DRV - (anf0100.sys) – C:\WINDOWS\system32\drivers\anf0100.sys (Netmarketing Pawel Wisniewski)
DRV - (P17) – C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (Ntfs) – C:\WINDOWS\System32\drivers\ntfs.old (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (xfilt) – C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
DRV - (videX32) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (LHDriver) – C:\WINDOWS\system32\drivers\LHDriver.sys ()
DRV - (LADriver) – C:\WINDOWS\system32\drivers\LADriver.sys ()
DRV - (LDDriver) – C:\WINDOWS\system32\drivers\LDDriver.sys ()
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (Sparrow) – C:\WINDOWS\System32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\drivers\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\drivers\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\drivers\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\System32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\drivers\ql1280.sys (QLogic Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/08/04 20:55:42 | 000,610,637 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 16306 more lines…
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ooccctrl.exe] C:\Program Files\OO Software\CleverCache\ooccctrl.exe (O&O Software GmbH)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.DLL ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ShellLess] C:\Program Files\ShellLess\ShellLess.exe (ShellLessWorks Software)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe (SSC Localization Group)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [ADSM] File not found
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
O4 - HKCU..\Run: [Chameleon System Monitor] C:\Program Files\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Invisible Security] File not found
O4 - HKCU..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
O4 - HKCU..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe (ashampoo GmbH & Co. KG)
O4 - HKCU..\Run: [Web Video Downloader] C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
O4 - HKCU..\Run: [Winsplit] C:\Program Files\WinSplit Revolution\WinSplit.exe ()
O4 - HKCU..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioReader.exe (Zinio, LLC)
O4 - HKLM..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe (TechSmith Corporation)
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe ()
O4 - Startup: C:\Documents and Settings\Arjun\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Webpage Capture - {1F958B09-6612-7a0e-9223-4C7324C57B23} - Reg Error: Value error. File not found
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O15 - HKCU\..Trusted Domains: cool.ne.jp ([]* in My Computer)
O15 - HKCU\..Trusted Domains: emjcd.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: gamehouse.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: kqzyfj.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: pipni.cz ([]* in My Computer)
O15 - HKCU\..Trusted Domains: registerapi.com ([]* in My Computer)
O15 - HKCU\..Trusted Domains: spb.ru ([]* in My Computer)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: xat.com ([]* in My Computer)
O15 - HKCU\..Trusted Ranges: Range10 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range12 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range14 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range16 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range18 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range2 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range21 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range23 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range25 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range27 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range29 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range30 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range32 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range34 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range36 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range38 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range4 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range41 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range43 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range45 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range47 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range49 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range50 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range52 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range54 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range56 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range58 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range6 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range61 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range63 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range65 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range67 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range69 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range70 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range72 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range74 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range76 ([*]in My Computer)
O15 - HKCU\..Trusted Ranges: Range8 ([*]in My Computer)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/su/ocx/15030/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.1)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB (TmHcmsX Control)
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2D9F7B63-EC7C-43FF-A41D-6E9EC984A5B9} https://myaccount.gateway.gov.uk/ClientObjects/GGSecSign.cab (GGSecSign Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} http://webeffective.keynote.com/applicatio…torLauncher.cab (Keynote Connector Launcher 2)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1197990575718 (MUWebControl Class)
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} http://esupport.epson-europe.com/selftest/…rg/ESTPTest.cab (EPSON Web Printer-SelfTest Control Class)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab (WScanCtl Class)
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} http://www.nanoscan.com/cabs/nanoinst.cab (NanoInstaller Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab (ACNPlayer2 Class)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner 4.0 Launcher)
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} http://www.freedom.net/viruscenter/onlinev…cabs/cssweb.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://vpn.pharmalink.co.uk/dana-cached/se…perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/su/ocx/15030/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O19 - User stylesheet: User Stylesheet - Reg Error: Value error.
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Arjun\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 17:33:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619700398653440)
========== Files/Folders - Created Within 30 Days ==========
[2010/08/05 16:25:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Arjun\Recent
[2010/08/05 00:51:19 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/07/21 06:13:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Arjun\My Documents\Aneesoft Flash Gallery Classic GOTD Edition
[2010/07/21 06:12:23 | 000,000,000 | —D | C] – C:\Program Files\Aneesoft
[2002/04/11 09:41:06 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/05 15:48:33 | 000,002,497 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Microsoft Office Word 2003.lnk
[2010/08/05 05:46:38 | 000,000,754 | —- | M] () – C:\Documents and Settings\Arjun\Application Data\AtomicAlarmClock.ini
[2010/08/05 05:46:29 | 000,063,804 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/08/05 05:46:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 05:46:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 05:45:27 | 030,932,992 | —- | M] () – C:\Documents and Settings\Arjun\NTUSER.DAT
[2010/08/05 05:45:27 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Arjun\ntuser.ini
[2010/08/05 00:51:20 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Arjun\Desktop\OTL.exe
[2010/08/04 20:55:42 | 000,610,637 | R— | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/08/04 18:12:27 | 000,610,087 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
[2010/08/04 15:45:31 | 001,014,645 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-181227.backup
[2010/08/03 15:46:08 | 001,014,343 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20100804-154531.backup
[2010/08/03 02:54:09 | 000,128,000 | —- | M] () – C:\Documents and Settings\Arjun\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/30 18:05:54 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 06:12:52 | 000,000,865 | —- | M] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/07/13 02:42:06 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[56 C:\Documents and Settings\All Users\Documents\*.tmp files -> C:\Documents and Settings\All Users\Documents\*.tmp -> ]
[11 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/21 06:12:52 | 000,000,865 | —- | C] () – C:\Documents and Settings\Arjun\Desktop\Aneesoft Flash Gallery Classic GOTD Edition.lnk
[2010/03/17 23:17:31 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/02/06 01:24:03 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2010/02/06 01:24:03 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2010/02/06 01:24:03 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/07/18 00:53:57 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/06/23 03:47:55 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/23 03:47:54 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/29 21:02:56 | 000,697,328 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/05/19 21:31:54 | 000,000,037 | —- | C] () – C:\WINDOWS\SWFConverter.INI
[2009/03/24 05:42:57 | 000,000,023 | —- | C] () – C:\WINDOWS\SWFDecompiler.INI
[2009/02/28 18:14:57 | 000,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/12/29 05:10:48 | 000,000,140 | —- | C] () – C:\WINDOWS\System32\09wutili.sys
[2008/11/11 01:31:48 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
[2008/10/28 00:46:42 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/10/28 00:45:39 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE DX7000FEFDG.ini
[2008/09/19 22:57:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/19 22:55:10 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/09/19 22:54:18 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/28 20:10:46 | 000,143,360 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/06/05 01:22:02 | 000,000,080 | —- | C] () – C:\WINDOWS\DeliveryReader.INI
[2008/05/12 21:56:47 | 000,000,144 | —- | C] () – C:\WINDOWS\ScreenHunter.INI
[2008/01/02 00:44:23 | 000,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2008/01/02 00:44:22 | 000,585,791 | —- | C] () – C:\WINDOWS\gmer.dll
[2007/10/25 11:26:48 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2007/10/23 17:02:20 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\P17.DLL
[2007/09/22 23:43:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2007/08/08 17:30:12 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2007/08/02 19:11:28 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2007/08/02 19:11:14 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2007/07/31 16:39:13 | 000,014,336 | —- | C] () – C:\WINDOWS\System32\drivers\LHDriver.sys
[2007/07/31 16:39:12 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\drivers\LADriver.sys
[2007/07/31 16:39:12 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\drivers\LDDriver.sys
[2007/07/30 16:19:07 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\OctaneARM.dll
[2007/07/27 16:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 16:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/07/14 14:49:05 | 000,000,004 | —- | C] () – C:\WINDOWS\jknradee.sys
[2007/04/05 21:45:54 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2007/04/02 15:10:50 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/20 09:58:08 | 000,999,424 | —- | C] () – C:\WINDOWS\System32\FathMail.dll
[2007/02/15 18:08:04 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/15 17:57:01 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2007/02/15 17:37:08 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2007/02/15 17:37:08 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2007/02/15 17:37:05 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2007/02/15 17:37:05 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2007/02/15 17:37:05 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2007/02/15 17:37:04 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2007/02/14 21:38:53 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/02/14 21:38:51 | 000,021,265 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/02/14 21:38:43 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/02/06 18:29:04 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/06/01 10:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/06/01 10:22:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/06/01 10:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/06/01 10:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 10:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/06/01 10:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/01 10:22:00 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/12/30 21:18:26 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/12/05 21:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 14:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2005/07/07 10:26:56 | 000,005,663 | —- | C] () – C:\WINDOWS\System32\Ludap17.ini
[2005/03/08 07:17:08 | 000,000,075 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/10/11 12:19:00 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\ASUSASV2.DLL
[2004/06/11 10:39:50 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\ACNePlayer.dll
[2003/10/02 18:48:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\P17CPI.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/11/09 03:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2007/10/27 21:13:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/09/03 22:44:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2010/06/17 23:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010/05/17 21:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eltima Software
[2008/11/02 19:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/08/13 05:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\explauncher
[2009/07/22 05:20:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2007/12/13 00:08:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/09/12 17:40:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/09/04 21:18:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2009/08/13 05:32:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\launcher
[2007/12/31 22:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NeoSoftTools
[2009/10/10 04:20:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Paragon
[2008/01/01 21:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prevx
[2010/08/05 05:46:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/27 19:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2008/11/02 19:05:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2008/10/28 04:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Watermark Factory
[2010/03/27 19:28:48 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/01/14 04:55:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{5DC53E13-E865-430F-97A7-98ACA32FC3D8}
[2009/05/24 21:57:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Amazon
[2009/10/16 21:22:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Apowersoft
[2009/09/25 01:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Ashampoo
[2009/06/22 03:40:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Audio Recorder Titanium
[2009/12/03 19:49:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Aunsoft
[2009/09/15 00:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Auslogics
[2009/10/05 01:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Autoplay Menu Designer
[2008/08/30 21:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ComfortSoftware
[2008/11/08 02:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Conceptworld
[2010/01/02 18:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ContentGuard
[2010/06/17 23:54:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\DAEMON Tools Pro
[2008/06/23 21:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktop Mechanic
[2009/12/19 19:10:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Desktopicon
[2010/06/21 04:15:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Digiarty
[2009/12/19 04:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EAST Technologies
[2010/05/14 18:34:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Eltima Software
[2008/10/28 01:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\EPSON
[2009/05/23 19:20:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Gold Wave Editor Pro
[2009/08/10 01:56:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\ImgBurn
[2009/05/25 17:55:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\iRecordMax Sound Recorder
[2008/08/14 09:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Juniper Networks
[2008/08/25 02:01:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\mojosoft
[2009/08/09 22:44:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Moyea
[2010/06/24 02:45:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\NeoSoftTools
[2007/07/27 21:22:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PandoraRecovery
[2008/03/22 00:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\PrevxCSI
[2009/06/18 01:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Smart Audio Editor
[2009/05/29 21:29:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\StarBurn
[2010/04/06 04:14:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Tidy Start Menu
[2010/03/27 19:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\TuneUp Software
[2008/06/19 20:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Uniblue
[2008/03/27 17:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\WebStripper
[2009/10/24 02:46:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Winsplit Revolution
[2010/02/10 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Arjun\Application Data\Zoner
[2010/08/05 05:46:27 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\dllcache\agp440.sys
< MD5 for: ATAPI.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\i386\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\cache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\cache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\cache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/06/17 23:48:38 | 000,697,328 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2007/02/02 17:10:28 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/02/02 17:10:28 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/02/02 17:10:28 | 000,917,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 212 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60466E88
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44807EFA
@Alternate Data Stream - 203 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0C43407A
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C265C458
@Alternate Data Stream - 186 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:408F95E5
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56AC8DD1
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EFC3A3C4
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C97C8631
@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB6AC38B
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FB286BF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
OTL Extras logfile created on: 05/08/2010 16:27:41 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Arjun\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1,023.00 Mb Total Physical Memory | 565.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 3.96 Gb Free Space | 20.27% Space Free | Partition Type: NTFS
Drive D: | 278.55 Gb Total Space | 30.08 Gb Free Space | 10.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POWERC250107
Current User Name: Arjun
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"94:TCP" = 94:TCP:*:Enabled:VRS Recording System Web Control Panel
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IpSharkk\IpSharkk.exe" = C:\Program Files\IpSharkk\IpSharkk.exe:*:Enabled:IpSharkk – (ipsharkk.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{027B7883-3778-4E8C-B3FA-0A28A3209D32}" = Pixo
"{07771631-6FE6-4D78-A705-D146C0D328A1}_is1" = Aunsoft SWF Converter version 2.0.2.35
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0EDB29CF-5FFC-4824-9F13-3D1C4286CA98}_is1" = Audio Transcoder
"{10479E5C-2EC2-4A70-A816-4B0FF3D90FCD}_is1" = 3D Ebook Cover 1.0
"{12AEE067-4646-41E8-A6EA-FB2AD0E38D30}_is1" = Moyea PPT to DVD Burner Pro version 3.3.2.172
"{13CA4073-A66B-4F07-9491-B933018E63D2}_is1" = Moyea SWF to Video Converter Pro version 3.6.2.1
"{1719FAD6-2F6A-4F5E-BF2B-1F6F6F1E3806}_is1" = AnyBizSoft PDF Password Remover (Build 1.0.4)
"{1965C9BB-9114-4A50-AEC7-E62414BB117B}" = EASEUS Data Recovery Wizard Professional 4.3.6
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}" = Sound Blaster Audigy
"{1C63AA59-66B2-418C-BDF5-53A534DA5690}_is1" = Sothink SWF to Video Converter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Giga Ethernet Utility
"{208B53C3-FA83-40EF-BC07-ED61E78CC12A}}_is1" = Watermark Factory 2
"{20AC583C-A6FB-410A-807D-25308225C201}" = Paint.NET v3.35
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{21CA58E1-3C5F-4893-A753-EB296503073D}_is1" = Moyea PPT to Video Converter version 1.6.0.40
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 20
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{2A6F734D-84CD-4472-877A-A070D76FAE74}_is1" = AnyBizSoft PDF to PowerPoint (Build [removed])
"{2CFE4799-CB85-456C-AABE-9BA2D02D81DB}" = Sky Broadband
"{30283233-3BE6-473D-A47C-ED964A2F78B4}_is1" = Inpaint 2.3
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150210}" = J2SE Runtime Environment 5.0 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39352E3D-43FF-44E7-AC2F-0ADA04AF9BB2}_is1" = Sothink HD Movie Maker
"{4218F0E1-CBAF-4D68-B6FE-B3504770829F}" = AutoStreamer
"{4360BB46-507E-4361-8DCB-4FF9BDC9907B}" = SnagIt 7
"{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 2.5.4)
"{485DF5E7-8379-4BFA-BAE1-9B8DBFE0D6B4}" = Paragon Drive Backup™ 9 Professional
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53480390-0EC4-429E-BBEE-78E19EEB03BD}" = O&O CleverCache
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8C52A46C-7961-4A81-AB4B-92CF65CB4772}_is1" = Sothink Web Video Downloader
"{8E3F691A-4972-47FF-9E09-1981B62A5D5A}_is1" = Moyea FLV Editor Ultimate version: 1.0.1.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0AC043C-9834-4F9E-B33E-1683FFE67EA4}" = FW LiveUpdate
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35001F0-F1E4-11DD-A38B-005056C00008}" = Paragon Partition Manager™ 9.5 Professional
"{A5FF2837-59C6-425B-8652-8CD385899F3F}" = uMark Professional 1.3
"{A855D6F0-DB2E-11DE-B032-005056C00008}" = Paragon Drive Backup™ 2010 Special Edition
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.03.11
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.8.7
"{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1" = Sothink SWF Decompiler
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{BF50CF00-7CE6-11DE-A06C-005056C00008}" = Paragon Virtualization Manager™ 9.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3C23D52-4FE6-484D-9A8C-B0A6E2803655}}_is1" = Aneesoft Flash Gallery Classic GOTD Edition
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3490D20-3AE0-459D-AAD6-59195140EAC2}_is1" = Sothink SWF Quicker
"{DB0BB9FA-1B60-4036-8E29-3D56D8085256}" = WOT for Internet Explorer
"{DBCF0030-9149-11DE-B8B6-005056C00008}" = Paragon Drive Copy™ 9.5 Personal
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2CAFC9F-95A1-4F27-9C1D-34DC9426A81B}" = Invisible Security Full
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EDF04509-B350-4EAB-BE77-5F2C87C33B35}_is1" = MPEG Video Wizard DVD 4.0.4.114 (06/2009)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20D1291-9FB8-46B1-BE46-6282F93C20E8}" = Registry Cleaner Pro
"{F7E1CA14-B39D-452A-960B-39423DDDD933}" = DriveImage XML (Private Edition)
"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 9.7 Professional Edition
"44953928-E730-4e8c-A2B2-3A85BC96A3D0_is1" = FileSeek 1.7.1
"7-Zip" = 7-Zip 4.57
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe flex sdk redistributed by sothink_is1" = 3.4.0.9271.1
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adolix PDF to Image for Giveawayoftheday_is1" = Adolix PDF to Image v1.2
"Advanced Audio Titanium_is1" = Audio Recorder Titanium v6.0.2
"Aimersoft HD Video Converter GOTD Edition_is1" = Aimersoft HD Video Converter(Build [removed])
"AllMedia Grabber4.0" = AllMedia Grabber
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.4
"AnVir Task Manager" = AnVir Task Manager
"Ashampoo Burning Studio 2010_is1" = Ashampoo Burning Studio 2010
"Ashampoo Burning Studio 9_is1" = Ashampoo Burning Studio 9.12
"Ashampoo Music Studio 2009_is1" = Ashampoo Music Studio 2009
"Ashampoo Snap 3_is1" = Ashampoo Snap 3.40
"Ashampoo UnInstaller 3_is1" = Ashampoo UnInstaller 3.12
"Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.60
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"Atomic Alarm Clock_is1" = Atomic Alarm Clock 5.81
"Autoplay Menu Designer_is1" = Autoplay Menu Designer 3.4
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Avira UnErase Personal" = Avira UnErase Personal
"AviSynth" = AviSynth 2.5
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video Editor 4_is1" = AVS Video Editor 4
"BusinessCardsMX3_is1" = BusinessCardsMX 3.92
"CCleaner" = CCleaner
"Chameleon Startup Manager 3" = Chameleon Startup Manager 3.2.0.723
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Corner-A ArtStudio" = Corner-A ArtStudio
"Cover Commander" = Cover Commander 3.0 by Insofta Development
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"CSSCOD" = Command On Demand for Command Software
"Dan Elwell's Broadband Speed Test_is1" = Dan Elwell's Broadband Speed Test
"Delivery" = Delivery
"Desktop Maestro_is1" = Desktop Maestro 2.0
"Device Control" = Device Control
"Disk Investigator_is1" = Disk Investigator v1.31
"Doc Scrubber_is1" = Doc Scrubber v1.1
"DriverGuide DriverScan" = DriverGuide DriverScan
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 5.0.1 Professional
"East-Tec Backup 2009_is1" = East-Tec Backup 2009 2.3
"East-Tec Eraser 2009_is1" = East-Tec Eraser 2009 Version 9.5
"EAX" = Creative EAX Console
"EAXSet" = Creative EAX Settings
"eCover Engineer Full Version_is1" = eCover Engineer 6.0 - Full Version
"eCover Engineer v3.02 FREE ecovers pack_is1" = eCover Engineer v3.02 ecovers pack
"eCover Engineer v4 FREE ecovers pack_is1" = eCover Engineer v4 ecovers pack
"eDATA Unerase" = eDATA Unerase
"Edraw Max_is1" = Edraw Max 4
"EPSON Printer and Utilities" = EPSON Printer Software
"ESCX6900F_DX7000F User's Guide" = ESCX6900F_DX7000F User's Guide
"EsetOnlineScanner" = ESET Online Scanner
"ExpressBurn" = Express Burn
"Extra DVD Ripper Professional_is1" = Extra DVD Ripper Professional 6.43
"Fast Video Converter_is1" = Fast Video Converter 1.0
"FastStone Capture" = FastStone Capture 5.3
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"Flash Movie Player" = Flash Movie Player 1.5
"FLV Player" = FLV Player 2.0, build 24
"FREE eCovers for eCoverEngineer_is1" = FREE eCovers for eCoverEngineer from 5.0
"FREE Templates for eCoverEngineer_is1" = FREE Templates for eCoverEngineer
"FreeUndelete" = FreeUndelete
"Glary Utilities_is1" = Glary Utilities Pro 2.18.0.786
"Gold Wave Editor Pro_is1" = Gold Wave Editor Pro v10.2.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Image Mender" = Image Mender 1.1
"ImgBurn" = ImgBurn
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8}" = ASUS Utilities
"iRecordMax Sound Recorder_is1" = iRecordMax Sound Recorder v7.1.3
"IrfanView" = IrfanView (remove only)
"IsoBuster_is1" = IsoBuster 2.4
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"KeynoteConnector" = Keynote Connector
"LockDisk_is1" = LockDisk 2.80
"MFZ0CODEC" = MFZ0 codec (Remove Only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MRU-Blaster_is1" = MRU-Blaster v1.5 (Database 3/28/2004)
"MultiStage Recovery_is1" = MultiStage Recovery 3.6
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PandoraRecovery" = PandoraRecovery (Remove Only)
"PDFZilla_is1" = PDFZilla V1.2.9
"PhotoPerfect Express_is1" = PhotoPerfect Express 1.00
"PKR" = PKR
"RealPlayer 6.0" = RealPlayer
"Recover PDF Password_is1" = Recover PDF Password [removed]
"Recuva" = Recuva
"Registry Cleaner Pro" = Registry Cleaner Pro
"Revo Uninstaller" = Revo Uninstaller 1.85
"ShellLess_is1" = ShellLess Explorer 1.07
"Simpo PDF Merge & Split_is1" = Simpo PDF Merge & Split 2.0.0.5
"Smart Audio Editor_is1" = Smart Audio Editor v7.7.1 Build 78
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SPEAKER" = Creative Speaker Settings
"SSC Service Utility_is1" = SSC Service Utility v4.30
"StarBurn(GiveAwayOfTheDay)_is1" = StarBurn(GiveAwayOfTheDay) Version 12 (Build 0x20090527)
"SWF & FLV Toolbox 4_is1" = SWF & FLV Toolbox 4.0 (build 4.0.0.440)
"Tidy Start Menu" = Tidy Start Menu
"Turbo File Uneraser_is1" = Turbo File Uneraser 1.1
"UltimateDefrag V1 FREE Public Domain Version" = UltimateDefrag V1 FREE Public Domain Version
"Undelete Plus_is1" = Undelete Plus 2.9
"Unlocker" = Unlocker 1.8.7
"VideoGet_is1" = VideoGet
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"WinRAR archiver" = WinRAR archiver
"WinSplit Revolution" = WinSplit Revolution (v9.02)
"WinX Blu-ray Decrypter_is1" = WinX Blu-ray Decrypter 2.0
"WinX DVD Author_is1" = WinX DVD Author 5.5.8
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 5.9.2
"WinX HD Video Converter Deluxe GOTD Edition_is1" = WinX HD Video Converter Deluxe 3.7
"Wondershare DVD Ripper Platinum_is1" = Wondershare DVD Ripper Platinum(Build [removed])
"Wondershare DVD to Flash Converter_is1" = Wondershare DVD to Flash Converter(Build [removed])
"Wondershare Flash Slideshow Builder GAOTD Edition_is1" = Wondershare Flash Slideshow Builder ([removed])
"Wondershare Music Converter_is1" = Wondershare Music Converter(Build 1.1.0.0)
"Wondershare Photo Collage Studio GAOTD Edition_is1" = Wondershare Photo Collage Studio [removed]
"Wondershare Photo Story Gold GAOTD Edition_is1" = Wondershare Photo Story Gold GAOTD Edition [removed]
"Wondershare QuizCreator 3.0 For GOTD_is1" = QuizCreator
"Wondershare Video Converter Platinum_is1" = Wondershare Video Converter Platinum(Build [removed])
"Wondershare Video to DVD Burner_is1" = Wondershare Video to DVD Burner(Build 2.0.17)
"Wondershare Video to DVD Converter_is1" = Wondershare Video to DVD Converter(Build [removed])
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Zilla Data Nuker_is1" = Zilla Data Nuker 2.0.0.0
"Zinio Reader" = Zinio Reader
"ZonerPhotoStudio12_EN_is1" = Zoner Photo Studio 12
"ZSoft Uninstaller" = ZSoft Uninstaller 2.4.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Term_Services" = Juniper Terminal Services Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"WinDirStat" = WinDirStat 1.1.2
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 19/07/2010 23:25:31 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0666251c.
Error - 21/07/2010 01:09:02 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0486251c.
Error - 24/07/2010 00:32:24 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x07c5251c.
Error - 24/07/2010 17:24:07 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application update.exe, version 10.0.0.29, faulting module
msvcr90.dll, version 9.0.30729.4148, fault address 0x000375b4.
Error - 24/07/2010 18:15:16 | Computer Name = POWERC250107 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 26/07/2010 00:28:01 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x04b7251c.
Error - 27/07/2010 00:51:09 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x0713251c.
Error - 28/07/2010 22:18:55 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x052e251c.
Error - 03/08/2010 00:37:54 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x077d251c.
Error - 03/08/2010 19:19:30 | Computer Name = POWERC250107 | Source = Application Error | ID = 1000
Description = Faulting application flvplayer.exe, version 0.0.0.0, faulting module
flashplayer.3.1.1e.ocx, version 9.0.115.0, fault address 0x000c1dc3.
[ System Events ]
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Machine Debug Manager service terminated unexpectedly. It has
done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The O&O CleverCache Agent service terminated unexpectedly. It has
done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The NMSAccessU service terminated unexpectedly. It has done this
1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The PDAgent service terminated unexpectedly. It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The ProtexisLicensing service terminated unexpectedly. It has done
this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The TuneUp Program Statistics Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:45:19 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).
Error - 05/08/2010 00:46:50 | Computer Name = POWERC250107 | Source = Service Control Manager | ID = 7000
Description = The EIO service failed to start due to the following error: %%2
[ TuneUp Events ]
Error - 08/05/2010 11:27:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:11', '\device\harddiskvolume1\documents
and settings\all users\application data\malwarebytes\malwarebytes' anti-malware\mbam-setup.exe','2952',0)
Error - 08/05/2010 11:27:41 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-08 16:27:41', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2488',0)
Error - 09/05/2010 12:13:11 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-09 17:13:11', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2400',0)
Error - 14/05/2010 20:48:05 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 01:48:05', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','504',0)
Error - 14/05/2010 21:09:15 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-15 02:09:15', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1312',0)
Error - 29/05/2010 00:12:33 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-05-29 05:12:33', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','1428',0)
Error - 31/05/2010 14:42:03 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
SET Outdated='1'
Error - 31/05/2010 14:42:04 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
SET Outdated='1'
Error - 03/07/2010 22:59:45 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:45', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\unins000.exe','2108',0)
Error - 03/07/2010 22:59:55 | Computer Name = POWERC250107 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-07-04 03:59:55', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbamgui.exe','3308',0)
< End of report >
Thanks for any help you can give.