NoHotAshes
Topic Starter
I have Norton Internet Security, and it is set to perform full system scans when idle, i noticed that today it removed 3 trojan horses, and another 3 trojan horses 2 weeks ago all located in the users/sun/java etc… im worried this isnt resolved even though Norton claims it is, also im running Vista 64 if that helps.
I greatly appriciate all time and effort given to me to help resolve my problem, thank you so much.
OTL logfile created on: 8/11/2010 12:56:19 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Dones\Desktop
64bit-Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 38.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 360.67 Gb Free Space | 38.72% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 149.77 Gb Free Space | 32.16% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DONES-PC
Current User Name: Dones
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Dones\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe (D-Link Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
PRC - C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
PRC - C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Dones\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcr90.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\asoehook.dll (Symantec Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (HFGService) – C:\Windows\SysNative\HFGService.dll (CSR, plc)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (pr2ah4nb) – C:\Windows\SysNative\pr2ah4nb.exe (CODEMASTERS)
SRV:64bit: - (dlbc_device) – C:\Windows\SysNative\dlbccoms.exe ( )
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SgtSch2Svc) – C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (dlbc_device) – C:\Windows\SysWow64\dlbccoms.exe ( )
========== Driver Services (SafeList) ==========
DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys File not found
DRV:64bit: - (LVcKap64) – C:\Windows\SysNative\DRIVERS\LVcKap64.sys File not found
DRV:64bit: - (libusb0) – C:\Windows\SysNative\drivers\libusb0.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV:64bit: - (SymIM) – C:\Windows\SysNative\DRIVERS\SymIMv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Ironx64.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMEFA64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ccHPx64.sys (Symantec Corporation)
DRV:64bit: - (BthAudioHF) – C:\Windows\SysNative\DRIVERS\BthAudioHF.sys (CSR, plc)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) – C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMDS64.SYS (Symantec Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (pbfilter) – C:\Program Files\PeerBlock\pbfilter.sys ()
DRV:64bit: - (hamachi) – C:\Windows\SysNative\DRIVERS\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (timounter) – C:\Windows\SysNative\DRIVERS\timntr.sys (Acronis)
DRV:64bit: - (tifsfilter) – C:\Windows\SysNative\DRIVERS\tifsfilt.sys (Acronis)
DRV:64bit: - (snapman) – C:\Windows\SysNative\DRIVERS\snapman.sys (Acronis)
DRV:64bit: - (tdrpman) – C:\Windows\SysNative\DRIVERS\tdrpman.sys (Acronis)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (sptd) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (AnyDVD) – C:\Windows\SysNative\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:64bit: - (LUsbFilt) – C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (VClone) – C:\Windows\SysNative\DRIVERS\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (irda) – C:\Windows\SysNative\DRIVERS\irda.sys (Microsoft Corporation)
DRV:64bit: - (MSIRCOMM) – C:\Windows\SysNative\DRIVERS\MSIRCOMM.sys (Microsoft Corporation)
DRV:64bit: - (STIrUsb) – C:\Windows\SysNative\DRIVERS\irstusb.sys (SigmaTel, Inc.)
DRV:64bit: - (ENTECH64) – C:\Windows\SysNative\DRIVERS\ENTECH64.sys (EnTech Taiwan)
DRV:64bit: - (pe3ah4nb) DiRT Environment Driver (pe3ah4nb) – C:\Windows\SysNative\drivers\pe3ah4nb.sys (CODEMASTERS)
DRV:64bit: - (ps6ah4nb) DiRT Synchronization Driver (ps6ah4nb) – C:\Windows\SysNative\drivers\ps6ah4nb.sys (CODEMASTERS)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\DRIVERS\LV302V64.SYS (Logitech Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100719.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100810.049\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100810.049\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100809.001\IDSviA64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (AnyDVD) – C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) – C:\Program Files (x86)\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
DRV - (libusb0) – C:\Windows\SysWOW64\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)
DRV - (NPF) – C:\Windows\SysWOW64\drivers\npf.sys (Politecnico di Torino)
DRV - (Aspi32) – C:\Windows\SysWow64\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:4.0.53.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/05/26 18:53:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/01/22 01:29:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/05 03:34:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/06 02:06:16 | 000,000,000 | —D | M]
[2009/01/11 01:51:24 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Extensions
[2010/08/09 02:25:42 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions
[2010/04/29 15:33:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/08 23:52:34 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2009/04/02 20:28:29 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2009/01/22 15:15:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2010/08/07 22:46:49 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/05/24 20:16:17 | 000,000,734 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Seagate Scheduler2 Service] C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [D-Link Network USB Utility] C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe (D-Link Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DesktopX] C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\desktopx.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: trymedia.com ([fe] * in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} http://fifa-online.easports.com/fo3-theme/…3AXLauncher.cab (EAFO3AXLauncher Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} http://service.futuremark.com/gom/receiver/tc/FMSI.cab (Futuremark SystemInfo)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20:64bit: - Winlogon\Notify\WB: DllName - Reg Error: Key error. - C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fast64.dll File not found
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files (x86)\Common Files\stardock\mcpcore.dll (Stardock)
O24 - Desktop WallPaper: C:\Windows\1920x1080_HD_Wallpaper_124_zixpkcom.bmp
O24 - Desktop BackupWallPaper: C:\Windows\1920x1080_HD_Wallpaper_124_zixpkcom.bmp
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O30:64bit: - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysNative\relog_ap.dll (Acronis)
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysWow64\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/03 23:10:21 | 000,214,408 | R— | M] (Konami Digital Entertainment Co., Ltd.) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2009/09/03 23:10:21 | 000,000,047 | R— | M] () - D:\Autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/08/11 00:54:22 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Dones\Desktop\OTL.exe
[2010/08/07 22:42:43 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Roaming\Skype
[2010/08/07 22:41:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/08/07 22:41:16 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2010/07/28 20:22:05 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\CrashRpt
[2010/07/28 20:21:45 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\Procaster
[2010/07/28 20:21:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Livestream Procaster
[2010/07/20 20:24:48 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\OnLive
[2009/04/04 02:20:49 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\dlbcusb1.dll
[2009/04/04 02:20:49 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\dlbcpmui.dll
[2009/04/04 02:20:49 | 000,483,328 | —- | C] ( ) – C:\Windows\SysWow64\dlbcjswr.dll
[2009/04/04 02:20:49 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\dlbcinpa.dll
[2009/04/04 02:20:49 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\dlbciesc.dll
[2009/04/04 02:20:49 | 000,323,584 | —- | C] ( ) – C:\Windows\SysWow64\DLBChcp.dll
[2009/04/04 02:20:49 | 000,073,728 | —- | C] ( ) – C:\Windows\SysWow64\dlbccu.dll
[2009/04/04 02:20:48 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\dlbcserv.dll
[2009/04/04 02:20:48 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\dlbchbn3.dll
[2009/04/04 02:20:48 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\dlbccomc.dll
[2009/04/04 02:20:48 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\dlbclmpm.dll
[2009/04/04 02:20:48 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\dlbccomm.dll
[2009/04/04 02:20:48 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\dlbcprox.dll
[2009/04/04 02:20:48 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\dlbcpplc.dll
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/11 01:00:11 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{EC65429A-C02E-4334-AECD-508638344B99}.job
[2010/08/11 00:56:40 | 006,553,600 | -HS- | M] () – C:\Users\Dones\ntuser.dat
[2010/08/11 00:54:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Dones\Desktop\OTL.exe
[2010/08/11 00:38:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/10 23:25:26 | 000,003,840 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/10 23:25:26 | 000,003,840 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/10 21:38:03 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/10 13:29:19 | 000,707,392 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/10 13:29:19 | 000,607,168 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/10 13:29:19 | 000,104,808 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/10 13:27:14 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/08/10 13:25:00 | 000,171,548 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/08/10 13:24:45 | 000,171,548 | —- | M] () – C:\ProgramData\nvModes.001
[2010/08/10 13:24:44 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/10 13:24:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/10 13:23:01 | 000,001,274 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/08/10 13:22:54 | 000,524,288 | -HS- | M] () – C:\Users\Dones\ntuser.dat{6975003a-8700-11de-8cc1-001fbc00cc81}.TMContainer00000000000000000001.regtrans-ms
[2010/08/10 13:22:54 | 000,065,536 | -HS- | M] () – C:\Users\Dones\ntuser.dat{6975003a-8700-11de-8cc1-001fbc00cc81}.TM.blf
[2010/08/10 13:22:43 | 005,276,977 | -H– | M] () – C:\Users\Dones\AppData\Local\IconCache.db
[2010/08/06 21:45:54 | 000,102,400 | —- | M] () – C:\Users\Dones\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/31 02:34:58 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010/07/31 02:34:58 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/20 19:57:25 | 000,360,516 | —- | C] () – C:\Users\Dones\AppData\Local\dd_vcredistMSI7399.txt
[2010/07/20 19:57:23 | 000,011,174 | —- | C] () – C:\Users\Dones\AppData\Local\dd_vcredistUI7399.txt
[2010/06/30 21:27:18 | 000,721,296 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/09/24 16:53:20 | 000,000,223 | —- | C] () – C:\Windows\SIERRA.INI
[2009/05/29 12:27:30 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/05/29 12:26:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/04 02:20:49 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\dlbcutil.dll
[2009/04/04 02:20:49 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\DLBCinst.dll
[2009/04/04 02:20:49 | 000,155,648 | —- | C] () – C:\Windows\SysWow64\dlbcinsb.dll
[2009/04/04 02:20:49 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\dlbccur.dll
[2009/03/20 15:25:02 | 000,041,808 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2009/01/22 20:30:44 | 000,000,258 | —- | C] () – C:\Windows\kaillera.ini
[2009/01/18 22:10:17 | 000,000,421 | —- | C] () – C:\Windows\dellstat.ini
[2009/01/15 15:21:41 | 000,000,604 | —- | C] () – C:\Windows\Thps3.INI
[2009/01/14 02:38:31 | 000,000,296 | —- | C] () – C:\Windows\game.ini
[2009/01/13 04:35:11 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/01/12 00:01:44 | 000,000,000 | —- | C] () – C:\Windows\WB.ini
[2009/01/11 01:15:24 | 000,000,277 | —- | C] () – C:\Windows\CDPlayer.ini
[2008/11/06 09:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2008/11/06 09:34:00 | 000,000,416 | —- | C] () – C:\Windows\SysWow64\dtu100.dll.manifest
[2008/01/20 19:47:53 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2002/03/02 04:10:02 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
========== LOP Check ==========
[2009/01/15 03:45:54 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Activision
[2009/11/10 14:27:52 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\AgeOfBooty
[2010/01/10 00:59:49 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Bioshock
[2010/01/05 04:22:18 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Braid
[2009/01/16 13:40:56 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
[2009/01/22 21:49:21 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2009/12/01 22:20:47 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2010/03/20 01:40:13 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command and Conquer 4
[2009/12/12 23:45:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command and Conquer 4 Beta
[2009/01/14 19:15:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools
[2009/01/13 04:12:42 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools Lite
[2009/01/13 04:11:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools Pro
[2009/04/02 20:01:27 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Damdai
[2009/01/17 01:41:20 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\fltk.org
[2009/01/29 23:37:44 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\fretsonfire
[2009/12/15 18:18:50 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\GetRightToGo
[2010/08/09 02:06:45 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Hoyle
[2009/08/05 01:05:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Hoyle FaceCreator
[2009/02/16 15:47:16 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Leadertech
[2010/05/11 15:58:02 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LolClient
[2009/12/09 10:50:06 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010/07/20 20:01:57 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LucasArts
[2010/06/25 23:54:11 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\OnLive
[2009/01/17 03:41:38 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\PeerNetworking
[2009/01/16 00:58:30 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Red Alert 3
[2009/03/14 11:28:20 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Red Alert 3 Uprising
[2010/05/17 01:26:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\runic games
[2009/11/05 18:18:54 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\ScummVM
[2009/07/14 21:56:48 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Stardock
[2009/12/08 18:56:37 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Stella
[2009/03/13 00:43:41 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\The Creative Assembly
[2010/08/06 22:06:44 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\uTorrent
[2010/04/15 16:18:03 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Warsow 0.5
[2010/08/10 13:23:03 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/11 01:00:11 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{EC65429A-C02E-4334-AECD-508638344B99}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
< MD5 for: AGP440.SYS >
[2008/01/20 19:44:43 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 19:44:43 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/01/20 19:44:42 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 00:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008/01/20 19:44:51 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2008/01/20 19:48:51 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 00:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 19:46:20 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008/01/20 19:44:46 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/20 19:48:17 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 19:47:39 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 00:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\Windows:7A68269D7F5E6E28
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:05EE1EEF
< End of report >
OTL Extras logfile created on: 8/11/2010 12:56:19 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Dones\Desktop
64bit-Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 38.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 360.67 Gb Free Space | 38.72% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 149.77 Gb Free Space | 32.16% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DONES-PC
Current User Name: Dones
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.reg [@ = regfile] – regedit.exe "%1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.reg [@ = regfile] – regedit.exe "%1"
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [open] – regedit.exe "%1" File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" File not found
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1"
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = E1 0B B4 13 DC 5B C8 01 [binary data]
"VistaSp2" = 1C 99 E5 2E EE E0 C9 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DisabledInterfaces" = {C61106D9-8D8A-434C-89C7-8D40DA5A9F4B},{429A0854-407A-49E5-9B28-0F4FC5EF55E9},{B378EEC5-CE42-4B4F-96D2-10040AEBFFC6}
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04834A1B-402A-453B-9712-C9120C205613}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{18CE2797-4028-4BC9-94DE-529054DB4F68}" = lport=9303 | protocol=17 | dir=in | name=shareport network usb utility udp port |
"{1BA71B50-5EC7-4DA2-90F1-83D93794F2A4}" = rport=445 | protocol=6 | dir=out | app=system |
"{273CDDA3-4AA2-4737-A3F1-0E0CC327015D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{2FD5C1B2-391A-4FAE-B1F6-5A37ED35D68A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3674ECC9-B75A-47BA-BFAF-1EA0CACA11EB}" = lport=137 | protocol=17 | dir=in | app=system |
"{49C39786-21C7-429C-A87F-58142BF79849}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{563BBC83-E3E4-4306-A28A-B1618BC5A5EA}" = lport=445 | protocol=6 | dir=in | app=system |
"{5C50A5C1-FFCC-4122-ABED-18253E1072D2}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6ED14BE5-35F3-4E3E-B1A7-251DBBFF19DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8159E128-2878-44BA-A5D5-F5C9D96678A5}" = rport=139 | protocol=6 | dir=out | app=system |
"{8D6F657B-B164-4FC6-907D-A6CBA3CFCA2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8FEBAC15-DD8F-4F84-BFDF-5966876838C4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{91E5D527-CB57-4E2E-8B93-7EBF544DF31D}" = rport=137 | protocol=17 | dir=out | app=system |
"{9777678F-A987-4F7A-9865-070D8AD513E1}" = lport=138 | protocol=17 | dir=in | app=system |
"{A2F221DF-FEB4-4659-ADAB-ADA5902B76D4}" = lport=139 | protocol=6 | dir=in | app=system |
"{A6BD2AAA-B7DC-4D0D-98E6-9CB1D0405579}" = rport=138 | protocol=17 | dir=out | app=system |
"{B7A6447B-7290-4E9C-9E42-E43FDBBF1765}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{BE365E51-5606-4D26-B0DF-9C45A9C5E9E0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C7F6FBA7-399B-41AE-941A-280C306B4E7C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D4244FC2-F954-4610-9C09-95A064471674}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F50FAD15-64C3-4621-A2BA-AAD2BCC37BAF}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{006C4CEB-2750-4968-AB9F-6C21D87ED120}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_launcher.exe |
"{00F292A4-1902-4113-B8A9-B9CBFBA2092E}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{03C91F59-665D-4761-BAC7-437B93216D59}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{03CE70B8-1095-4B0A-A500-40204BC1EDF6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0523EAE0-30E2-4F4B-9473-2E13D0907ADE}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dlbcpswx.exe |
"{06EC8E86-DA21-4A24-A430-14F6BCE0A01E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\farcry2.exe |
"{07DDE7BF-9851-4507-B35F-A429374E5298}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2launcher.exe |
"{0AA07516-0D0D-4B7B-B345-01A5102B5B21}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{0B1C7953-8967-4A13-BDC7-D1CE6028DDBE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2launcher.exe |
"{0C103A3D-6F4B-447F-A1CC-48E2D7A08495}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{0C85ED93-3AA5-4583-9FD3-C0362D0AFB84}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{0CD641A1-5879-402B-9263-CC377D5D9A48}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{1081AB83-F7BD-46B8-BC52-3430712200E7}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{109B57EC-7523-4924-AAE1-6BCFD838C5C4}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{1218549B-A87A-4263-A553-E7B74EA274D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_launcher.exe |
"{1225530E-2405-493E-B350-40FD3F7802F2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\counter-strike source\hl2.exe |
"{140FCE5E-A5CC-44F2-A334-606A8940E7FE}" = protocol=17 | dir=in | app=c:\windows\system32\dlbccoms.exe |
"{160378D6-684B-4552-9521-EB14EA9461D6}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{1645D26F-11D2-4B1C-99F5-BDB30F29A0DB}" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\frozen throne.exe |
"{166309E9-2934-4D4C-A9C5-6E47149DFC78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_dx11.exe |
"{18D38253-1963-43B8-BD37-32C9EFB72016}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic.exe |
"{1B03C043-9927-4C08-8244-8C3B73D12BD4}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{1C7C4AEA-41CA-4CCA-B2FB-73F17282DC58}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{1F40D2F1-77EE-4F8C-8411-F162E10533EB}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{1F5A55D1-30DF-4201-8014-A583927AB9FF}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\dirt2\dirt2_game.exe |
"{246C9129-FB46-4A81-A404-7F742F46A14C}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{2483BD15-6243-4EFC-9814-4710E0E9AD29}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp.exe |
"{24B0597D-CA44-4A35-A0D9-610CE998618A}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{2665AF1A-926B-4F80-B023-1256424136BA}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{27410C5A-455C-4179-B5CA-20AF010099B3}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2editor.exe |
"{27FB60CC-78BB-4740-A80B-B206C3F0B368}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{287A7504-3ED8-4422-BA11-928C95D1CEA0}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_online.exe |
"{2939EA62-4CFE-44E5-9BAB-7622565953A4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\farcry2.exe |
"{29D76080-4FAC-4C97-B2F2-448F8DA223A3}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_ds.exe |
"{2A5C3354-18F8-47A8-88FC-CDBA5F076117}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\yuplay\yuplay.exe |
"{2A75C3A7-409E-43C2-A508-DCE67438E68E}" = protocol=17 | dir=in | app=c:\windows\syswow64\dlbccoms.exe |
"{2BAEF3CA-8E90-4173-814A-A7421E47DDD1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{2D731700-5245-4572-B233-32453A91741E}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{2EC9528C-E515-4AF8-9627-AFCCCAE5AC08}" = protocol=17 | dir=in | app=c:\program files (x86)\d-link\shareport\shareport network usb utility.exe |
"{325FD1E9-02E9-41CE-92CA-AE54100FD614}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{33F04660-7BD3-41AE-A852-FBF9595AD9D3}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{36FE0761-2DEA-428A-A692-14ADD7BA9782}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{372AF75F-D943-4B9A-BC2F-EF1E5F28E72D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{3843FB3C-6ECB-4834-9DF2-76B47F756881}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{387F76F8-573E-4288-9CB6-5CE045613102}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{394996AA-11BB-4884-8F2B-8B611C90D377}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{39C782A8-B74C-4EFB-A8E2-21EF62875D71}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx10.exe |
"{3E60DAA1-862B-4163-9FDB-88B6E441203D}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx10.exe |
"{3F359D1A-A088-49B7-9DF3-633573D1DC19}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx9.exe |
"{3FB50702-1B62-47F7-B747-74E7ED9371EA}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{4124D868-F17F-4C99-9D9D-98A21945FA4F}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2editor.exe |
"{4155BC2D-6FA7-42F7-BBD4-69967C9C1A5C}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{43912291-7195-4DD5-86B3-CD04CDDA1100}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxbccoms.exe |
"{45768261-30E1-4F4E-AC38-AB94F690EEDD}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\streetfighteriv\streetfighteriv.exe |
"{469073EF-D068-465B-8B35-17F6EFDA3A7F}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{4787034F-31C0-4C0E-89CE-50E8F0C5B7CB}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{4879E9DC-DA62-4E9A-8FD4-632B29D1CFA5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{4A31302C-3091-4DDC-AD2B-F9861DE8D6BD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4B87687E-5963-4444-A37E-B4DF710BB515}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{4BAF2CFD-BA4D-4949-A54E-FB9244914FE1}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{4D8524AB-211A-461E-A1C7-131A50FD0692}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\launcher.exe |
"{4E012FDB-2164-48BB-B3A1-F5D1B1C2BE7C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\source sdk base 2007\hl2.exe |
"{4E5992D4-9B7D-48D4-8522-D67D861065E8}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |
"{4E72379D-31F3-4386-8829-A3100D715DB5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{5062758C-E332-4537-BFCE-C8CB4C7351C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{5487F451-0A54-4DDF-8FF7-04BF2F2CF77A}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\acess.exe |
"{54E77BA0-7DBA-4424-9E88-04305DF6AACE}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{54ECFB31-C136-4EED-89EF-CCA35559F963}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic.exe |
"{553F99B2-6589-415B-9CD9-14C3D8BB494D}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{55629155-5B70-49EB-9E7F-4D7207D79B08}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\garrysmod\hl2.exe |
"{5C5B856B-7565-48B8-8A0C-261B2F1139F2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{5C6A0802-0EA8-4046-917B-3AC0C6D22A7D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{5D957571-F571-410C-8696-2719DA0E1F62}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{5E5F83E2-5780-47D5-B30A-58180AF38659}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{5FD9C04D-2BC4-40F4-A87D-194AE8E01981}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{60110B34-C196-46E0-BF98-70F181BFFEB3}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{60BCB793-85B3-4AAC-8D1A-576692A820B7}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\yuplay\yuplay.exe |
"{6392814D-453B-472F-AC69-0811976FC14A}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |
"{6F1E3A67-0B4A-4537-AEE8-BC31F20FC4E7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
"{6F31F179-1ADD-46FD-BD65-BD6D59720EBF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\counter-strike source\hl2.exe |
"{6FB09D1C-22E0-41AF-84BD-63AF71FCFB86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
"{709DAD37-1B87-4ECD-8863-B7AA28EFBA67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\garrysmod\hl2.exe |
"{750B4961-C3F5-45D0-A55B-86378E049B35}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{78494A53-6E3D-4B9D-821F-7F8543F57484}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{7C8D961D-99C0-4564-A1DE-6EA442B9BA19}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{80199352-9A75-4120-91FA-D0189F95267A}" = protocol=6 | dir=in | app=c:\windows\system32\dlbccoms.exe |
"{81232931-5007-4DEE-921C-C83473BDA063}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd\powerdvd.exe |
"{81ED2498-676F-4228-9D61-7813A9176CFD}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{82B16AB8-AC96-4017-AD10-343CC440FA43}" = protocol=6 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqw.exe |
"{838021D2-52BA-4D8D-8A34-89B4CCBAC287}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{8504136D-9EEB-4CA2-80FD-95D9A366F454}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8597CDBE-5802-43A3-AF48-8B00BB23775D}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |
"{861FAD37-FA6D-46DA-9DF6-159A73894091}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{86E4A46E-5372-493E-9580-01C881D5EAFB}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{88771F0C-A26A-4452-AB9B-C5A848748CCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{88CC72F4-DA7C-468E-8464-1C563F94E08F}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{88F7EED0-EE36-4989-AE90-64D7675C6E8E}" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\frozen throne.exe |
"{8BEDF6FD-4098-48F4-93A6-0E06642C742D}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx9.exe |
"{8C731E6D-CDBE-48A3-9CC2-A0C4710C09B7}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{8D36BAAE-8CD9-46C2-A942-C19C316521FB}" = protocol=17 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqw.exe |
"{8EB93A50-7B08-43D6-B1A0-85CCB6586407}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_dx11.exe |
"{8FDB8BE4-0288-40A7-A6A0-0B022032F8CB}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |
"{9325B76E-8667-4268-8B12-C778C2519C1A}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{946C9681-F8C0-4244-A016-2BE3E08601F5}" = protocol=17 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{9726F1B7-5D81-4428-95D9-9F208977BD1E}" = protocol=6 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{99F88108-C9E6-457F-8992-E21E12B8B591}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |
"{9BFF58CF-11A8-4AAF-A6E5-E07748A2EB84}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp.exe |
"{9EBDF23C-7558-4CC7-A7B5-C97A17789FC9}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{9FC4BD5A-D4E8-4B52-BFFD-2D7217FC2B84}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A13FA77E-925F-44B7-9D5E-F81D6DAC88B6}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{A7CFB5C2-16C0-4554-BAA6-343499598315}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |
"{A9FDD883-0760-4EB0-854F-631F84A6296D}" = protocol=6 | dir=in | app=c:\program files (x86)\hamachi\hamachi.exe |
"{ABE75208-E57E-4745-897E-28F744E2B1C2}" = protocol=17 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe |
"{AE43C2F1-627F-46CB-87C1-80F7B40082A3}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{B20D3A54-8686-4747-A798-F424BBBFA204}" = protocol=6 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqwded.exe |
"{B2546304-B2FB-4C55-8887-B70CE1C953CA}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{B3424C1B-0F6E-48F9-AC6E-C5B55D512E4A}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{B42BAF6E-2FB9-4512-B571-6C60B1532FFD}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{B4D2E295-CBED-401A-9338-5B56BE7E6E69}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{B7D9375F-82AF-41C9-AD5F-7D3FE277911E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{B82A7EFC-73A5-4DC7-A321-2F39E9E1CCF3}" = protocol=6 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe |
"{B82F3CF9-C94E-4AD3-8B3F-BBBB3BC3318B}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{B952F51C-E717-4D8E-AD6F-0C5EA400F07E}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_online.exe |
"{B9EFCCD3-4380-4C9D-AF8F-CA652B44448B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{BA989581-3AB1-46CB-86CE-7BC8C4416FC1}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{BAA96FD3-073E-4012-8E93-4AEAC10E8FAB}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{BBDAD807-F3A1-4C3F-9437-99C40D5BBEA6}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{BC503510-4003-4562-8930-92C73E3F0157}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{C064A3B5-2097-40EB-BED8-6391C2A11414}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxbccoms.exe |
"{C0ADC49F-76F1-4F7A-B4A0-2DB039E6D368}" = protocol=6 | dir=in | app=c:\program files (x86)\unreal tournament 3\binaries\ut3.exe |
"{C1B84679-E3A8-4C6E-8DFC-2A92AC9D0675}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C1CF81ED-3423-47B1-AD72-DC44336F6A87}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C29721CA-DD8B-49D2-96EC-3B6FA009ED7F}" = protocol=6 | dir=in | app=c:\program files (x86)\d-link\shareport\shareport network usb utility.exe |
"{C5B42362-85E9-4221-B6E9-F61AC722D33A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\thrones.exe |
"{C9E67D95-C597-4491-9C01-08DEBDEEB9C9}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{CD32A017-3656-424E-8920-9B97BC00F237}" = protocol=17 | dir=in | app=c:\program files (x86)\unreal tournament 3\binaries\ut3.exe |
"{CE17DE69-0D53-487C-85A2-4CD5FF4DC6CC}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\dirt2\dirt2_game.exe |
"{CF06C858-7DF6-43F9-A74A-C6D8F90DD6CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{D0EA8789-EB7A-4177-87FC-91DBCA1FF2B5}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{D1157E4F-D0C2-4E6D-90BB-507A3D8E09C1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\thrones.exe |
"{D150EC70-0556-49ED-AE89-E3A8985A6D07}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{D1E03868-D64C-42A8-8119-981C71DCDC0D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{D5A8BEF0-8B69-4495-B313-A83C22E287B9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D638C540-C692-4923-B882-664C4D403258}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{D76AEE81-295F-4F63-BFE0-CE358158D918}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DD7B26C4-7E2B-45A5-B989-142AA0C2FBD3}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\streetfighteriv\streetfighteriv.exe |
"{DF11B8FE-C69E-43C1-9169-2C175A324BC0}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{E0E4721A-4229-4ACA-94B2-8E1C14B06C2C}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_ds.exe |
"{E1C13049-5F11-4DE6-841D-1875BE7389DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E47121E7-055D-41CE-92D4-9517F71EE911}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\acess.exe |
"{E6A6BF3D-8F10-487C-B9D7-CF7A3CA5D2EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\source sdk base 2007\hl2.exe |
"{E7B10A1D-DAD8-4C47-B77D-8CA61C761539}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E939A5C5-D789-429D-8341-55344ADD0FD2}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dlbcpswx.exe |
"{E9B51242-48CA-4559-AC33-5ED6A72CE8AB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{E9D3D29C-A87E-4D00-8BA9-C1FA0A2F9413}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{EBBE6564-0A70-49DC-81E0-4C406FF0264B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{EC3A65C3-3D7B-4FEC-ACD4-327713108C4D}" = protocol=17 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqwded.exe |
"{EEB6C271-8405-4E74-8360-86C0015E730F}" = protocol=17 | dir=in | app=c:\program files (x86)\hamachi\hamachi.exe |
"{F06F1DE3-D2A3-4B13-86CA-D2253B08C152}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{F4B8FCA3-A31F-4AD2-B047-80748D58BF57}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{F522638C-977B-4F0E-90FF-ACB25C12E826}" = protocol=6 | dir=in | app=c:\windows\syswow64\dlbccoms.exe |
"{F6756F33-B659-40A8-AE26-DE238ADF4B04}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\launcher.exe |
"{FA5EB6D0-9455-449D-A294-953FD813B5AF}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{FC767B71-FEA7-4908-8D1E-CD3B8A722CCA}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{FCB9257B-E969-43CB-BD6F-D70D16DB7075}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{FDCECB12-CE76-4F03-ABFC-233FA2103F8B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{FDE6FCB5-F355-40AB-91CF-70E285F41698}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.0.0 (r181)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{64A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java™ SE Development Kit 6 Update 11 (64-bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8753DF4D-64B0-474E-9A97-0AB5585D9A53}" = Logitech Gaming Software 5.04
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"SP6" = Logitech SetPoint 6.0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty® - World at War™ 1.6 Patch
"{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
"{127B684B-A002-44C8-99A7-6CF8F1E26873}" = PunkBuster for Battlefield 1942
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235BBFC6-D863-4066-A01A-3BD504C31033}" = Nero 7 Ultra Edition
"{24508D50-EB8F-4FE6-B69D-B4935D8745EF}_is1" = Warsow 0.5
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010
"{28526951-55EF-4901-A0CA-B9AC966D1DD1}" = Split/Second
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"{32A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java™ SE Development Kit 6 Update 11
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3E4B349F-10B5-4586-9D99-489A90A8B228}" = Sid Meier's Civilization 4 - Warlords
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F425F12-3A1B-4511-97B2-E2BB4701B745}" = Crysis Wars®
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{43E506CC-6633-4F2A-8D8E-4A95D2384393}" = Crysis Wars® Patch
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{50D4CB89-AF34-4978-96DC-C3034062E901}" = Battlefield 2: Special Forces
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{52D1D62C-FEAB-4580-849E-1DB624BADBBD}" = DiRT2
"{5454083B-1308-4485-BF17-111000028701}" = Grand Theft Auto: Episodes from Liberty City
"{5454083B-1308-4485-BF17-1110000B8301}" = Grand Theft Auto IV
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{57B89E30-0BBA-4F20-9F2C-8E8CDE1CEDB6}" = DiRT
"{59ABBDF0-E1E5-48AF-85FB-F523A08C3490}" = STREET FIGHTER IV
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{5BDAA2F7-8E48-4AFF-AA92-B559D0CDF1AD}" = Serious Sam: The Second Encounter
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60147180-8370-44BC-9BBD-E554D86F0BA3}" = Livestream Procaster
"{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
"{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}" = Command & Conquer The First Decade
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68BD9036-0952-4849-AE7A-963BB53EDB71}" = GGPO
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6FE3B0CE-37C1-4825-908A-5A84C9B4EC2F}" = EA SPORTS™ FIFA Online
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty® - World at War™ 1.7 Patch
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{815050E5-F545-11D4-9569-004095812ACC}" = Serious Sam: The First Encounter
"{82696435-8572-4D8B-A230-D1AA567D0F0F}" = Command & Conquer™ 4 Tiberian Twilight
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8F5A0981-5CDC-41D0-BCA2-AD3B777FC358}" = Thrustmaster Force Feedback Driver
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"{932FB3F3-594D-4600-ABFA-F2DE80A14214}" = Marvel™ - Ultimate Alliance
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout™ Paradise The Ultimate Box
"{9B63540D-D942-4C38-B42E-A48AE0145970}" = Virtua Tennis™ 2009
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - Quake Wars™
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{bd8defa4-19fa-4964-9692-f1112d8a62d9}}_is1" = Wings of Prey [removed]
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard
"{CC2422C9-F7B5-4175-B295-5EC2283AA674}" = Command & Conquer™ 3: Kane's Wrath
"{CD1DF19E-4ED2-43F5-9E07-D4DD22D1671E}" = EVGA E-LEET
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D07643A3-CE41-4286-8C78-EB9C83E76DDB}" = PunkBuster for Battlefield Vietnam
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 ESD
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"{D88064EC-0864-420E-99D5-E34828ABF39D}" = SharePort Network USB Utility
"{DA2A851C-6E2B-4677-9DA5-5ED9A3B227E2}" = Quake Live Internet Explorer Plugin
"{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}" = Command & Conquer™ Red Alert™ 3 Uprising
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E35B3C63-E958-4E31-A178-95D22024109A}" = Battlefield Vietnam™
"{E4511CEC-2E60-4076-95B6-0E193269EB86}" = MicroMachines V4
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2835483-37F2-4123-B4FE-0E77D58447F2}" = Far Cry 2
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"AnyDVD" = AnyDVD
"bgbennyboyCMIReplacementSetup_is1" = Curse Of Monkey Island
"bgbennyboyEMIReplacementSetup_is1" = Escape From Monkey Island
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Company of Heroes" = Company of Heroes
"Crysis WARHEAD®" = Crysis WARHEAD®
"Crysis Wars®" = Crysis Wars®
"Crysis Wars® Patch" = Crysis Wars® Patch
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"dBpowerAMP Ogg Vorbis Codec" = dBpowerAMP Ogg Vorbis Codec
"dBpowerAMP WMA V9 Codec" = dBpowerAMP WMA V9 Codec
"Dell Photo Printer 720" = Dell Photo Printer 720
"DesktopX" = DesktopX
"DivX Setup.divx.com" = DivX Setup
"Download Manager" = Download Manager 2.3.10
"DVD Decrypter" = DVD Decrypter (Remove Only)
"EADM" = EA Download Manager
"ERUNT_is1" = ERUNT 1.1j
"Fraps" = Fraps (remove only)
"GamersInternetTunnel_is1" = GIT v0.99 BETA 4
"GoldenEye Source" = GoldenEye: Source - HalfLife 2 Mod
"Google Updater" = Google Updater
"Hoyle Casino 2009" = Hoyle Casino 2009
"Impulse" = Impulse
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty® - World at War™ 1.6 Patch
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD Ultra
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty® - World at War™ 1.7 Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"InstallShield_{932FB3F3-594D-4600-ABFA-F2DE80A14214}" = Marvel™ - Ultimate Alliance
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mIRC" = mIRC
"Monkey Island 2 Special Edition LeChuck’s Revenge" = Monkey Island® 2 Special Edition: LeChuck’s Revenge®
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Nidesoft DVD Ripper_is1" = Nidesoft DVD Ripper v3.0
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OnLive" = OnLive
"OpenAL" = OpenAL
"Painkiller Black Edition" = Painkiller Black Edition
"PFPortChecker" = PFPortChecker 1.0.28
"Precision" = EVGA Precision 1.3.3
"PROPLUS" = Microsoft Office Professional Plus 2007
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer
"RiseOfNationsExpansion 1.0" = Rise of Nations
"SHOUTcastDSP" = SHOUTcast Source DSP 1.9.0 (remove only)
"SpeedFan" = SpeedFan (remove only)
"Starcraft" = Starcraft
"Steam App 10500" = Empire: Total War
"Steam App 10680" = Aliens vs Predator
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 20570" = Warhammer 40,000: Dawn of War II - Chaos Rising
"Steam App 218" = Source SDK Base - Orange Box
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 25700" = Madballs in…Babo: Invasion
"Steam App 280" = Half-Life: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 360" = Half-Life Deathmatch: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 4000" = Garry's Mod
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 630" = Alien Swarm
"Tales of Monkey Island - Lair of the Leviathan" = Tales of Monkey Island - Lair of the Leviathan
"Tales of Monkey Island - Launch of the Screaming Narwhal" = Tales of Monkey Island - Launch of the Screaming Narwhal
"Tales of Monkey Island - Rise of the Pirate God" = Tales of Monkey Island - Rise of the Pirate God
"Tales of Monkey Island - The Siege of Spinner Cay" = Tales of Monkey Island - The Siege of Spinner Cay
"Tales of Monkey Island - The Trial and Execution of Guybrush Threepwood" = Tales of Monkey Island - The Trial and Execution of Guybrush Threepwood
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"The Secret of Monkey Island Special Edition" = The Secret of Monkey Island Special Edition
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"Tomb Raider - Legend" = Tomb Raider - Legend (remove only)
"Tomb Raider: Anniversary" = Tomb Raider: Anniversary 1.0
"Tomb Raider: Underworld" = Tomb Raider: Underworld 1.0
"Torchlight" = Torchlight
"Trials 2 SE" = Trials 2 Second Edition
"Trine_is1" = Trine 1.03
"UnrealTournament" = Unreal Tournament G.O.T.Y. Edition
"UT2004" = Unreal Tournament 2004
"VideoGet_is1" = Nuclear Coffee - VideoGet
"Warcraft III" = Warcraft III
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 3.0
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"Xfire" = Xfire (remove only)
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"yuPlay êëèåíò_is1" = yuPlay client 0.7.7
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"InstallShield_{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/10/2010 5:41:03 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 5:57:52 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 6:27:29 AM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 6:27:29 AM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 6:28:25 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 7:07:39 AM | Computer Name = Dones-PC | Source = Application Error | ID = 1000
Description = Faulting application BF1942.exe, version 0.0.0.0, time stamp 0x417564c4,
faulting module BF1942.exe, version 0.0.0.0, time stamp 0x417564c4, exception code
0xc0000005, fault offset 0x002016fb, process id 0x9ec, application start time 0x01cb088ce6494c71.
Error - 6/10/2010 7:09:18 AM | Computer Name = Dones-PC | Source = Application Error | ID = 1000
Description = Faulting application BF1942.exe, version 0.0.0.0, time stamp 0x417564c4,
faulting module BF1942.exe, version 0.0.0.0, time stamp 0x417564c4, exception code
0xc0000005, fault offset 0x002016fb, process id 0xc54, application start time 0x01cb088d29136f8c.
Error - 6/10/2010 4:30:10 PM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 4:30:10 PM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 4:30:49 PM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:31 PM | Computer Name = Dones-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\Aspi32.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.
Error - 8/10/2010 4:25:10 PM | Computer Name = Dones-PC | Source = ps6ah4nb | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.
Error - 8/10/2010 4:26:10 PM | Computer Name = Dones-PC | Source = Service Control Manager | ID = 7026
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:15:19 AM, on 8/11/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Users\Dones\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [D-Link Network USB Utility] C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe -mini
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [DesktopX] "C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\desktopx.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files (x86)\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O15 - Trusted Zone: fe.trymedia.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} (EAFO3AXLauncher Control) - http://fifa-online.easports.com/fo3-theme/…3AXLauncher.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - http://service.futuremark.com/gom/receiver/tc/FMSI.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: dlbc_device - - C:\Windows\system32\dlbccoms.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: DiRT Drivers Auto Removal (pr2ah4nb) (pr2ah4nb) - Unknown owner - C:\Windows\system32\pr2ah4nb.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 10278 bytes
DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 1:18:28.61 on Wed 08/11/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3062.838 [GMT -7:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\dlbccoms.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Windows\system32\svchost.exe -k bthaudiosvc
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\mobsync.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Users\Dones\Desktop\HiJackThis.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dones\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\daemon.exe" -autorun
uRun: [DesktopX] "c:\program files (x86)\stardock\object desktop\desktopx\desktopx.exe"
mRun: [DiscWizardMonitor.exe] c:\program files (x86)\seagate\discwizard\DiscWizardMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files (x86)\seagate\discwizard\TimounterMonitor.exe
mRun: [D-Link Network USB Utility] c:\program files (x86)\d-link\shareport\SharePort Network USB Utility.exe -mini
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files (x86)\belkin\bluetooth software\btsendto_ie_ctx.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
Trusted Zone: trymedia.com\fe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} - hxxp://fifa-online.easports.com/fo3-theme/addons/EAFO3AXLauncher.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/gom/receiver/tc/FMSI.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~2\common~1\stardock\mcpcore.dll
LSA: Authentication Packages = msv1_0 relog_ap
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [Seagate Scheduler2 Service] "c:\program files (x86)\common files\seagate\schedule2\schedhlp.exe"
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
================= FIREFOX ===================
FF - ProfilePath - c:\users\dones\applic~1\mozilla\firefox\profiles\i2cgbi12.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\download manager\npfpdlm.dll
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files (x86)\onlive\firefoxplugin\npolgdet.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: c:\users\dones\application data\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\users\dones\application data\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [2007-7-19 72296]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [2007-7-19 102000]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-5-25 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-5-25 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100719.001\BHDrvx64.sys [2010-7-19 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-5-25 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100809.001\IDSviA64.sys [2010-8-10 463408]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-5-25 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-5-25 451120]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe -k bthaudiosvc [2008-1-20 27648]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-5-25 126392]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\common files\seagate\schedule2\schedul2.exe [2008-6-24 605464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-11-20 240232]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\drivers\BthAudioHF.sys [2010-2-5 56728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-27 132656]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-12-18 135664]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc –> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 ENTECH64;ENTECH64;c:\windows\system32\drivers\Entech64.sys [2009-1-17 12744]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-4-6 50072]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-5-25 19544]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework64\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-5-29 89920]
S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\logmein hamachi\hamachi-2.exe [2010-3-30 1823112]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-08-08 05:41:16 0 d—–r- c:\program files (x86)\Skype
2010-08-07 01:38:44 11584512 —-a-w- c:\windows\syswow64\shell32.dll
2010-07-29 03:21:44 0 d—–w- c:\program files (x86)\Livestream Procaster
==================== Find3M ====================
2010-08-10 20:25:00 171548 —-a-w- c:\programdata\nvModes.dat
2010-08-10 08:04:44 51200 —-a-w- c:\windows\inf\infpub.dat
2010-08-10 08:04:44 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-08-10 08:04:42 86016 —-a-w- c:\windows\inf\infstor.dat
2010-07-31 09:34:58 218808 —-a-w- c:\windows\syswow64\PnkBstrB.exe
2010-06-09 02:18:44 2427248 —-a-w- c:\windows\syswow64\pbsvc_heroes.exe
2010-06-07 08:22:36 794408 —-a-w- c:\windows\syswow64\pbsvc.exe
2010-05-26 17:23:46 48128 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 17:06:41 34304 —-a-w- c:\windows\syswow64\atmlib.dll
2010-05-26 15:10:41 366080 —-a-w- c:\windows\system32\atmfd.dll
2010-05-26 14:47:41 289792 —-a-w- c:\windows\syswow64\atmfd.dll
2009-10-30 08:45:30 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:18:21 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:18:21 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-10 00:33:54 245760 –sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 1:18:41.89 ===============
I greatly appriciate all time and effort given to me to help resolve my problem, thank you so much.
OTL logfile created on: 8/11/2010 12:56:19 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Dones\Desktop
64bit-Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 38.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 360.67 Gb Free Space | 38.72% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 149.77 Gb Free Space | 32.16% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DONES-PC
Current User Name: Dones
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Dones\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe (D-Link Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
PRC - C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
PRC - C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe ()
========== Modules (SafeList) ==========
MOD - C:\Users\Dones\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcr90.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\asoehook.dll (Symantec Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini File not found
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (HFGService) – C:\Windows\SysNative\HFGService.dll (CSR, plc)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (pr2ah4nb) – C:\Windows\SysNative\pr2ah4nb.exe (CODEMASTERS)
SRV:64bit: - (dlbc_device) – C:\Windows\SysNative\dlbccoms.exe ( )
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (SgtSch2Svc) – C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (dlbc_device) – C:\Windows\SysWow64\dlbccoms.exe ( )
========== Driver Services (SafeList) ==========
DRV:64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys File not found
DRV:64bit: - (LVcKap64) – C:\Windows\SysNative\DRIVERS\LVcKap64.sys File not found
DRV:64bit: - (libusb0) – C:\Windows\SysNative\drivers\libusb0.sys File not found
DRV:64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SYMTDIV.SYS (Symantec Corporation)
DRV:64bit: - (SymIM) – C:\Windows\SysNative\DRIVERS\SymIMv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\Ironx64.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMEFA64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1107000.00C\SRTSP64.SYS (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SRTSPX64.SYS (Symantec Corporation)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\ccHPx64.sys (Symantec Corporation)
DRV:64bit: - (BthAudioHF) – C:\Windows\SysNative\DRIVERS\BthAudioHF.sys (CSR, plc)
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (L8042Kbd) – C:\Windows\SysNative\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1107000.00C\SYMDS64.SYS (Symantec Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (pbfilter) – C:\Program Files\PeerBlock\pbfilter.sys ()
DRV:64bit: - (hamachi) – C:\Windows\SysNative\DRIVERS\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (timounter) – C:\Windows\SysNative\DRIVERS\timntr.sys (Acronis)
DRV:64bit: - (tifsfilter) – C:\Windows\SysNative\DRIVERS\tifsfilt.sys (Acronis)
DRV:64bit: - (snapman) – C:\Windows\SysNative\DRIVERS\snapman.sys (Acronis)
DRV:64bit: - (tdrpman) – C:\Windows\SysNative\DRIVERS\tdrpman.sys (Acronis)
DRV:64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:64bit: - (WmFilter) – C:\Windows\SysNative\drivers\WmFilter.sys (Logitech Inc.)
DRV:64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:64bit: - (sptd) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (AnyDVD) – C:\Windows\SysNative\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:64bit: - (LUsbFilt) – C:\Windows\SysNative\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV:64bit: - (VClone) – C:\Windows\SysNative\DRIVERS\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (irda) – C:\Windows\SysNative\DRIVERS\irda.sys (Microsoft Corporation)
DRV:64bit: - (MSIRCOMM) – C:\Windows\SysNative\DRIVERS\MSIRCOMM.sys (Microsoft Corporation)
DRV:64bit: - (STIrUsb) – C:\Windows\SysNative\DRIVERS\irstusb.sys (SigmaTel, Inc.)
DRV:64bit: - (ENTECH64) – C:\Windows\SysNative\DRIVERS\ENTECH64.sys (EnTech Taiwan)
DRV:64bit: - (pe3ah4nb) DiRT Environment Driver (pe3ah4nb) – C:\Windows\SysNative\drivers\pe3ah4nb.sys (CODEMASTERS)
DRV:64bit: - (ps6ah4nb) DiRT Synchronization Driver (ps6ah4nb) – C:\Windows\SysNative\drivers\ps6ah4nb.sys (CODEMASTERS)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\DRIVERS\LV302V64.SYS (Logitech Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100719.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100810.049\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100810.049\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100809.001\IDSviA64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (AnyDVD) – C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) – C:\Program Files (x86)\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)
DRV - (libusb0) – C:\Windows\SysWOW64\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)
DRV - (NPF) – C:\Windows\SysWOW64\drivers\npf.sys (Politecnico di Torino)
DRV - (Aspi32) – C:\Windows\SysWow64\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:4.0.53.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/05/26 18:53:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/01/22 01:29:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/05 03:34:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/06 02:06:16 | 000,000,000 | —D | M]
[2009/01/11 01:51:24 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Extensions
[2010/08/09 02:25:42 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions
[2010/04/29 15:33:12 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/08 23:52:34 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2009/04/02 20:28:29 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2009/01/22 15:15:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Mozilla\Firefox\Profiles\i2cgbi12.default\extensions\[removed]
[2010/08/07 22:46:49 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/05/24 20:16:17 | 000,000,734 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Seagate Scheduler2 Service] C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [D-Link Network USB Utility] C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe (D-Link Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DesktopX] C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\desktopx.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: trymedia.com ([fe] * in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} http://fifa-online.easports.com/fo3-theme/…3AXLauncher.cab (EAFO3AXLauncher Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} http://service.futuremark.com/gom/receiver/tc/FMSI.cab (Futuremark SystemInfo)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20:64bit: - Winlogon\Notify\WB: DllName - Reg Error: Key error. - C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fast64.dll File not found
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files (x86)\Common Files\stardock\mcpcore.dll (Stardock)
O24 - Desktop WallPaper: C:\Windows\1920x1080_HD_Wallpaper_124_zixpkcom.bmp
O24 - Desktop BackupWallPaper: C:\Windows\1920x1080_HD_Wallpaper_124_zixpkcom.bmp
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O30:64bit: - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysNative\relog_ap.dll (Acronis)
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\SysWow64\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/03 23:10:21 | 000,214,408 | R— | M] (Konami Digital Entertainment Co., Ltd.) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2009/09/03 23:10:21 | 000,000,047 | R— | M] () - D:\Autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/08/11 00:54:22 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Dones\Desktop\OTL.exe
[2010/08/07 22:42:43 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Roaming\Skype
[2010/08/07 22:41:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/08/07 22:41:16 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2010/07/28 20:22:05 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\CrashRpt
[2010/07/28 20:21:45 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\Procaster
[2010/07/28 20:21:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Livestream Procaster
[2010/07/20 20:24:48 | 000,000,000 | —D | C] – C:\Users\Dones\AppData\Local\OnLive
[2009/04/04 02:20:49 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\dlbcusb1.dll
[2009/04/04 02:20:49 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\dlbcpmui.dll
[2009/04/04 02:20:49 | 000,483,328 | —- | C] ( ) – C:\Windows\SysWow64\dlbcjswr.dll
[2009/04/04 02:20:49 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\dlbcinpa.dll
[2009/04/04 02:20:49 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\dlbciesc.dll
[2009/04/04 02:20:49 | 000,323,584 | —- | C] ( ) – C:\Windows\SysWow64\DLBChcp.dll
[2009/04/04 02:20:49 | 000,073,728 | —- | C] ( ) – C:\Windows\SysWow64\dlbccu.dll
[2009/04/04 02:20:48 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\dlbcserv.dll
[2009/04/04 02:20:48 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\dlbchbn3.dll
[2009/04/04 02:20:48 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\dlbccomc.dll
[2009/04/04 02:20:48 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\dlbclmpm.dll
[2009/04/04 02:20:48 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\dlbccomm.dll
[2009/04/04 02:20:48 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\dlbcprox.dll
[2009/04/04 02:20:48 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\dlbcpplc.dll
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/11 01:00:11 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{EC65429A-C02E-4334-AECD-508638344B99}.job
[2010/08/11 00:56:40 | 006,553,600 | -HS- | M] () – C:\Users\Dones\ntuser.dat
[2010/08/11 00:54:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Dones\Desktop\OTL.exe
[2010/08/11 00:38:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/10 23:25:26 | 000,003,840 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/10 23:25:26 | 000,003,840 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/10 21:38:03 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/10 13:29:19 | 000,707,392 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/10 13:29:19 | 000,607,168 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/10 13:29:19 | 000,104,808 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/10 13:27:14 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/08/10 13:25:00 | 000,171,548 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/08/10 13:24:45 | 000,171,548 | —- | M] () – C:\ProgramData\nvModes.001
[2010/08/10 13:24:44 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/10 13:24:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/10 13:23:01 | 000,001,274 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/08/10 13:22:54 | 000,524,288 | -HS- | M] () – C:\Users\Dones\ntuser.dat{6975003a-8700-11de-8cc1-001fbc00cc81}.TMContainer00000000000000000001.regtrans-ms
[2010/08/10 13:22:54 | 000,065,536 | -HS- | M] () – C:\Users\Dones\ntuser.dat{6975003a-8700-11de-8cc1-001fbc00cc81}.TM.blf
[2010/08/10 13:22:43 | 005,276,977 | -H– | M] () – C:\Users\Dones\AppData\Local\IconCache.db
[2010/08/06 21:45:54 | 000,102,400 | —- | M] () – C:\Users\Dones\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/31 02:34:58 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010/07/31 02:34:58 | 000,218,808 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/20 19:57:25 | 000,360,516 | —- | C] () – C:\Users\Dones\AppData\Local\dd_vcredistMSI7399.txt
[2010/07/20 19:57:23 | 000,011,174 | —- | C] () – C:\Users\Dones\AppData\Local\dd_vcredistUI7399.txt
[2010/06/30 21:27:18 | 000,721,296 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/09/24 16:53:20 | 000,000,223 | —- | C] () – C:\Windows\SIERRA.INI
[2009/05/29 12:27:30 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/05/29 12:26:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/04 02:20:49 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\dlbcutil.dll
[2009/04/04 02:20:49 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\DLBCinst.dll
[2009/04/04 02:20:49 | 000,155,648 | —- | C] () – C:\Windows\SysWow64\dlbcinsb.dll
[2009/04/04 02:20:49 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\dlbccur.dll
[2009/03/20 15:25:02 | 000,041,808 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2009/01/22 20:30:44 | 000,000,258 | —- | C] () – C:\Windows\kaillera.ini
[2009/01/18 22:10:17 | 000,000,421 | —- | C] () – C:\Windows\dellstat.ini
[2009/01/15 15:21:41 | 000,000,604 | —- | C] () – C:\Windows\Thps3.INI
[2009/01/14 02:38:31 | 000,000,296 | —- | C] () – C:\Windows\game.ini
[2009/01/13 04:35:11 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/01/12 00:01:44 | 000,000,000 | —- | C] () – C:\Windows\WB.ini
[2009/01/11 01:15:24 | 000,000,277 | —- | C] () – C:\Windows\CDPlayer.ini
[2008/11/06 09:37:32 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2008/11/06 09:34:00 | 000,000,416 | —- | C] () – C:\Windows\SysWow64\dtu100.dll.manifest
[2008/01/20 19:47:53 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2002/03/02 04:10:02 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
========== LOP Check ==========
[2009/01/15 03:45:54 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Activision
[2009/11/10 14:27:52 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\AgeOfBooty
[2010/01/10 00:59:49 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Bioshock
[2010/01/05 04:22:18 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Braid
[2009/01/16 13:40:56 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
[2009/01/22 21:49:21 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2009/12/01 22:20:47 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2010/03/20 01:40:13 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command and Conquer 4
[2009/12/12 23:45:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Command and Conquer 4 Beta
[2009/01/14 19:15:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools
[2009/01/13 04:12:42 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools Lite
[2009/01/13 04:11:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\DAEMON Tools Pro
[2009/04/02 20:01:27 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Damdai
[2009/01/17 01:41:20 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\fltk.org
[2009/01/29 23:37:44 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\fretsonfire
[2009/12/15 18:18:50 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\GetRightToGo
[2010/08/09 02:06:45 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Hoyle
[2009/08/05 01:05:46 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Hoyle FaceCreator
[2009/02/16 15:47:16 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Leadertech
[2010/05/11 15:58:02 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LolClient
[2009/12/09 10:50:06 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010/07/20 20:01:57 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\LucasArts
[2010/06/25 23:54:11 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\OnLive
[2009/01/17 03:41:38 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\PeerNetworking
[2009/01/16 00:58:30 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Red Alert 3
[2009/03/14 11:28:20 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Red Alert 3 Uprising
[2010/05/17 01:26:04 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\runic games
[2009/11/05 18:18:54 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\ScummVM
[2009/07/14 21:56:48 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Stardock
[2009/12/08 18:56:37 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Stella
[2009/03/13 00:43:41 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\The Creative Assembly
[2010/08/06 22:06:44 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\uTorrent
[2010/04/15 16:18:03 | 000,000,000 | —D | M] – C:\Users\Dones\AppData\Roaming\Warsow 0.5
[2010/08/10 13:23:03 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/11 01:00:11 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{EC65429A-C02E-4334-AECD-508638344B99}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
< MD5 for: AGP440.SYS >
[2008/01/20 19:44:43 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 19:44:43 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/01/20 19:44:42 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 00:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008/01/20 19:44:51 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2008/01/20 19:48:51 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 00:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 19:46:20 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008/01/20 19:44:46 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/20 19:48:17 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 19:47:39 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 00:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\Windows:7A68269D7F5E6E28
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:05EE1EEF
< End of report >
OTL Extras logfile created on: 8/11/2010 12:56:19 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Dones\Desktop
64bit-Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 38.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 360.67 Gb Free Space | 38.72% Space Free | Partition Type: NTFS
Drive D: | 5.38 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 149.77 Gb Free Space | 32.16% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DONES-PC
Current User Name: Dones
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.reg [@ = regfile] – regedit.exe "%1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.reg [@ = regfile] – regedit.exe "%1"
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [open] – regedit.exe "%1" File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" File not found
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1"
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V"
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = E1 0B B4 13 DC 5B C8 01 [binary data]
"VistaSp2" = 1C 99 E5 2E EE E0 C9 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DisabledInterfaces" = {C61106D9-8D8A-434C-89C7-8D40DA5A9F4B},{429A0854-407A-49E5-9B28-0F4FC5EF55E9},{B378EEC5-CE42-4B4F-96D2-10040AEBFFC6}
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04834A1B-402A-453B-9712-C9120C205613}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{18CE2797-4028-4BC9-94DE-529054DB4F68}" = lport=9303 | protocol=17 | dir=in | name=shareport network usb utility udp port |
"{1BA71B50-5EC7-4DA2-90F1-83D93794F2A4}" = rport=445 | protocol=6 | dir=out | app=system |
"{273CDDA3-4AA2-4737-A3F1-0E0CC327015D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{2FD5C1B2-391A-4FAE-B1F6-5A37ED35D68A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3674ECC9-B75A-47BA-BFAF-1EA0CACA11EB}" = lport=137 | protocol=17 | dir=in | app=system |
"{49C39786-21C7-429C-A87F-58142BF79849}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{563BBC83-E3E4-4306-A28A-B1618BC5A5EA}" = lport=445 | protocol=6 | dir=in | app=system |
"{5C50A5C1-FFCC-4122-ABED-18253E1072D2}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6ED14BE5-35F3-4E3E-B1A7-251DBBFF19DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8159E128-2878-44BA-A5D5-F5C9D96678A5}" = rport=139 | protocol=6 | dir=out | app=system |
"{8D6F657B-B164-4FC6-907D-A6CBA3CFCA2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8FEBAC15-DD8F-4F84-BFDF-5966876838C4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{91E5D527-CB57-4E2E-8B93-7EBF544DF31D}" = rport=137 | protocol=17 | dir=out | app=system |
"{9777678F-A987-4F7A-9865-070D8AD513E1}" = lport=138 | protocol=17 | dir=in | app=system |
"{A2F221DF-FEB4-4659-ADAB-ADA5902B76D4}" = lport=139 | protocol=6 | dir=in | app=system |
"{A6BD2AAA-B7DC-4D0D-98E6-9CB1D0405579}" = rport=138 | protocol=17 | dir=out | app=system |
"{B7A6447B-7290-4E9C-9E42-E43FDBBF1765}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{BE365E51-5606-4D26-B0DF-9C45A9C5E9E0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C7F6FBA7-399B-41AE-941A-280C306B4E7C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D4244FC2-F954-4610-9C09-95A064471674}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F50FAD15-64C3-4621-A2BA-AAD2BCC37BAF}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{006C4CEB-2750-4968-AB9F-6C21D87ED120}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_launcher.exe |
"{00F292A4-1902-4113-B8A9-B9CBFBA2092E}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{03C91F59-665D-4761-BAC7-437B93216D59}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{03CE70B8-1095-4B0A-A500-40204BC1EDF6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0523EAE0-30E2-4F4B-9473-2E13D0907ADE}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dlbcpswx.exe |
"{06EC8E86-DA21-4A24-A430-14F6BCE0A01E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\farcry2.exe |
"{07DDE7BF-9851-4507-B35F-A429374E5298}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2launcher.exe |
"{0AA07516-0D0D-4B7B-B345-01A5102B5B21}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{0B1C7953-8967-4A13-BDC7-D1CE6028DDBE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2launcher.exe |
"{0C103A3D-6F4B-447F-A1CC-48E2D7A08495}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{0C85ED93-3AA5-4583-9FD3-C0362D0AFB84}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{0CD641A1-5879-402B-9263-CC377D5D9A48}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{1081AB83-F7BD-46B8-BC52-3430712200E7}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{109B57EC-7523-4924-AAE1-6BCFD838C5C4}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{1218549B-A87A-4263-A553-E7B74EA274D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_launcher.exe |
"{1225530E-2405-493E-B350-40FD3F7802F2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\counter-strike source\hl2.exe |
"{140FCE5E-A5CC-44F2-A334-606A8940E7FE}" = protocol=17 | dir=in | app=c:\windows\system32\dlbccoms.exe |
"{160378D6-684B-4552-9521-EB14EA9461D6}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{1645D26F-11D2-4B1C-99F5-BDB30F29A0DB}" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\frozen throne.exe |
"{166309E9-2934-4D4C-A9C5-6E47149DFC78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_dx11.exe |
"{18D38253-1963-43B8-BD37-32C9EFB72016}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic.exe |
"{1B03C043-9927-4C08-8244-8C3B73D12BD4}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{1C7C4AEA-41CA-4CCA-B2FB-73F17282DC58}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{1F40D2F1-77EE-4F8C-8411-F162E10533EB}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{1F5A55D1-30DF-4201-8014-A583927AB9FF}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\dirt2\dirt2_game.exe |
"{246C9129-FB46-4A81-A404-7F742F46A14C}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{2483BD15-6243-4EFC-9814-4710E0E9AD29}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp.exe |
"{24B0597D-CA44-4A35-A0D9-610CE998618A}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{2665AF1A-926B-4F80-B023-1256424136BA}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{27410C5A-455C-4179-B5CA-20AF010099B3}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2editor.exe |
"{27FB60CC-78BB-4740-A80B-B206C3F0B368}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{287A7504-3ED8-4422-BA11-928C95D1CEA0}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_online.exe |
"{2939EA62-4CFE-44E5-9BAB-7622565953A4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\farcry2.exe |
"{29D76080-4FAC-4C97-B2F2-448F8DA223A3}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_ds.exe |
"{2A5C3354-18F8-47A8-88FC-CDBA5F076117}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\yuplay\yuplay.exe |
"{2A75C3A7-409E-43C2-A508-DCE67438E68E}" = protocol=17 | dir=in | app=c:\windows\syswow64\dlbccoms.exe |
"{2BAEF3CA-8E90-4173-814A-A7421E47DDD1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{2D731700-5245-4572-B233-32453A91741E}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{2EC9528C-E515-4AF8-9627-AFCCCAE5AC08}" = protocol=17 | dir=in | app=c:\program files (x86)\d-link\shareport\shareport network usb utility.exe |
"{325FD1E9-02E9-41CE-92CA-AE54100FD614}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{33F04660-7BD3-41AE-A852-FBF9595AD9D3}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{36FE0761-2DEA-428A-A692-14ADD7BA9782}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{372AF75F-D943-4B9A-BC2F-EF1E5F28E72D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{3843FB3C-6ECB-4834-9DF2-76B47F756881}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{387F76F8-573E-4288-9CB6-5CE045613102}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |
"{394996AA-11BB-4884-8F2B-8B611C90D377}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{39C782A8-B74C-4EFB-A8E2-21EF62875D71}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx10.exe |
"{3E60DAA1-862B-4163-9FDB-88B6E441203D}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx10.exe |
"{3F359D1A-A088-49B7-9DF3-633573D1DC19}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx9.exe |
"{3FB50702-1B62-47F7-B747-74E7ED9371EA}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{4124D868-F17F-4C99-9D9D-98A21945FA4F}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\far cry 2\bin\fc2editor.exe |
"{4155BC2D-6FA7-42F7-BBD4-69967C9C1A5C}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysis.exe |
"{43912291-7195-4DD5-86B3-CD04CDDA1100}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxbccoms.exe |
"{45768261-30E1-4F4E-AC38-AB94F690EEDD}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\streetfighteriv\streetfighteriv.exe |
"{469073EF-D068-465B-8B35-17F6EFDA3A7F}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{4787034F-31C0-4C0E-89CE-50E8F0C5B7CB}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{4879E9DC-DA62-4E9A-8FD4-632B29D1CFA5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{4A31302C-3091-4DDC-AD2B-F9861DE8D6BD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4B87687E-5963-4444-A37E-B4DF710BB515}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{4BAF2CFD-BA4D-4949-A54E-FB9244914FE1}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{4D8524AB-211A-461E-A1C7-131A50FD0692}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\launcher.exe |
"{4E012FDB-2164-48BB-B3A1-F5D1B1C2BE7C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\source sdk base 2007\hl2.exe |
"{4E5992D4-9B7D-48D4-8522-D67D861065E8}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |
"{4E72379D-31F3-4386-8829-A3100D715DB5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{5062758C-E332-4537-BFCE-C8CB4C7351C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{5487F451-0A54-4DDF-8FF7-04BF2F2CF77A}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\acess.exe |
"{54E77BA0-7DBA-4424-9E88-04305DF6AACE}" = protocol=6 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{54ECFB31-C136-4EED-89EF-CCA35559F963}" = protocol=6 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic.exe |
"{553F99B2-6589-415B-9CD9-14C3D8BB494D}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{55629155-5B70-49EB-9E7F-4D7207D79B08}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\garrysmod\hl2.exe |
"{5C5B856B-7565-48B8-8A0C-261B2F1139F2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{5C6A0802-0EA8-4046-917B-3AC0C6D22A7D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{5D957571-F571-410C-8696-2719DA0E1F62}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{5E5F83E2-5780-47D5-B30A-58180AF38659}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{5FD9C04D-2BC4-40F4-A87D-194AE8E01981}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{60110B34-C196-46E0-BF98-70F181BFFEB3}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{60BCB793-85B3-4AAC-8D1A-576692A820B7}" = protocol=17 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\yuplay\yuplay.exe |
"{6392814D-453B-472F-AC69-0811976FC14A}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |
"{6F1E3A67-0B4A-4537-AEE8-BC31F20FC4E7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
"{6F31F179-1ADD-46FD-BD65-BD6D59720EBF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\counter-strike source\hl2.exe |
"{6FB09D1C-22E0-41AF-84BD-63AF71FCFB86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
"{709DAD37-1B87-4ECD-8863-B7AA28EFBA67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\garrysmod\hl2.exe |
"{750B4961-C3F5-45D0-A55B-86378E049B35}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{78494A53-6E3D-4B9D-821F-7F8543F57484}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{7C8D961D-99C0-4564-A1DE-6EA442B9BA19}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{80199352-9A75-4120-91FA-D0189F95267A}" = protocol=6 | dir=in | app=c:\windows\system32\dlbccoms.exe |
"{81232931-5007-4DEE-921C-C83473BDA063}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd\powerdvd.exe |
"{81ED2498-676F-4228-9D61-7813A9176CFD}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{82B16AB8-AC96-4017-AD10-343CC440FA43}" = protocol=6 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqw.exe |
"{838021D2-52BA-4D8D-8A34-89B4CCBAC287}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{8504136D-9EEB-4CA2-80FD-95D9A366F454}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8597CDBE-5802-43A3-AF48-8B00BB23775D}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |
"{861FAD37-FA6D-46DA-9DF6-159A73894091}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysis.exe |
"{86E4A46E-5372-493E-9580-01C881D5EAFB}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{88771F0C-A26A-4452-AB9B-C5A848748CCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{88CC72F4-DA7C-468E-8464-1C563F94E08F}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{88F7EED0-EE36-4989-AE90-64D7675C6E8E}" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\frozen throne.exe |
"{8BEDF6FD-4098-48F4-93A6-0E06642C742D}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\resident evil 5\re5dx9.exe |
"{8C731E6D-CDBE-48A3-9CC2-A0C4710C09B7}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |
"{8D36BAAE-8CD9-46C2-A942-C19C316521FB}" = protocol=17 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqw.exe |
"{8EB93A50-7B08-43D6-B1A0-85CCB6586407}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp_dx11.exe |
"{8FDB8BE4-0288-40A7-A6A0-0B022032F8CB}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |
"{9325B76E-8667-4268-8B12-C778C2519C1A}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{946C9681-F8C0-4244-A016-2BE3E08601F5}" = protocol=17 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{9726F1B7-5D81-4428-95D9-9F208977BD1E}" = protocol=6 | dir=in | app=c:\windows\system32\lxbccoms.exe |
"{99F88108-C9E6-457F-8992-E21E12B8B591}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |
"{9BFF58CF-11A8-4AAF-A6E5-E07748A2EB84}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aliens vs predator\avp.exe |
"{9EBDF23C-7558-4CC7-A7B5-C97A17789FC9}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2 - beta\bfbc2betaupdater.exe |
"{9FC4BD5A-D4E8-4B52-BFFD-2D7217FC2B84}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A13FA77E-925F-44B7-9D5E-F81D6DAC88B6}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
"{A7CFB5C2-16C0-4554-BAA6-343499598315}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |
"{A9FDD883-0760-4EB0-854F-631F84A6296D}" = protocol=6 | dir=in | app=c:\program files (x86)\hamachi\hamachi.exe |
"{ABE75208-E57E-4745-897E-28F744E2B1C2}" = protocol=17 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe |
"{AE43C2F1-627F-46CB-87C1-80F7B40082A3}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{B20D3A54-8686-4747-A798-F424BBBFA204}" = protocol=6 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqwded.exe |
"{B2546304-B2FB-4C55-8887-B70CE1C953CA}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\rockstar games social club\rgsclauncher.exe |
"{B3424C1B-0F6E-48F9-AC6E-C5B55D512E4A}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{B42BAF6E-2FB9-4512-B571-6C60B1532FFD}" = protocol=17 | dir=in | app=c:\program files (x86)\rockstar games\eflc\launcheflc.exe |
"{B4D2E295-CBED-401A-9338-5B56BE7E6E69}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{B7D9375F-82AF-41C9-AD5F-7D3FE277911E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{B82A7EFC-73A5-4DC7-A321-2F39E9E1CCF3}" = protocol=6 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe |
"{B82F3CF9-C94E-4AD3-8B3F-BBBB3BC3318B}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{B952F51C-E717-4D8E-AD6F-0C5EA400F07E}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_online.exe |
"{B9EFCCD3-4380-4C9D-AF8F-CA652B44448B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{BA989581-3AB1-46CB-86CE-7BC8C4416FC1}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{BAA96FD3-073E-4012-8E93-4AEAC10E8FAB}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{BBDAD807-F3A1-4C3F-9437-99C40D5BBEA6}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{BC503510-4003-4562-8930-92C73E3F0157}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{C064A3B5-2097-40EB-BED8-6391C2A11414}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxbccoms.exe |
"{C0ADC49F-76F1-4F7A-B4A0-2DB039E6D368}" = protocol=6 | dir=in | app=c:\program files (x86)\unreal tournament 3\binaries\ut3.exe |
"{C1B84679-E3A8-4C6E-8DFC-2A92AC9D0675}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C1CF81ED-3423-47B1-AD72-DC44336F6A87}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C29721CA-DD8B-49D2-96EC-3B6FA009ED7F}" = protocol=6 | dir=in | app=c:\program files (x86)\d-link\shareport\shareport network usb utility.exe |
"{C5B42362-85E9-4221-B6E9-F61AC722D33A}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\thrones.exe |
"{C9E67D95-C597-4491-9C01-08DEBDEEB9C9}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{CD32A017-3656-424E-8920-9B97BC00F237}" = protocol=17 | dir=in | app=c:\program files (x86)\unreal tournament 3\binaries\ut3.exe |
"{CE17DE69-0D53-487C-85A2-4CD5FF4DC6CC}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\dirt2\dirt2_game.exe |
"{CF06C858-7DF6-43F9-A74A-C6D8F90DD6CC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{D0EA8789-EB7A-4177-87FC-91DBCA1FF2B5}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\crytek\crysis\bin64\crysisdedicatedserver.exe |
"{D1157E4F-D0C2-4E6D-90BB-507A3D8E09C1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of nations\thrones.exe |
"{D150EC70-0556-49ED-AE89-E3A8985A6D07}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{D1E03868-D64C-42A8-8119-981C71DCDC0D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{D5A8BEF0-8B69-4495-B313-A83C22E287B9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D638C540-C692-4923-B882-664C4D403258}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{D76AEE81-295F-4F63-BFE0-CE358158D918}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DD7B26C4-7E2B-45A5-B989-142AA0C2FBD3}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\streetfighteriv\streetfighteriv.exe |
"{DF11B8FE-C69E-43C1-9169-2C175A324BC0}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{E0E4721A-4229-4ACA-94B2-8E1C14B06C2C}" = protocol=17 | dir=in | app=c:\program files (x86)\sierra entertainment\world in conflict\wic_ds.exe |
"{E1C13049-5F11-4DE6-841D-1875BE7389DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E47121E7-055D-41CE-92D4-9517F71EE911}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\acess.exe |
"{E6A6BF3D-8F10-487C-B9D7-CF7A3CA5D2EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nohotashes\source sdk base 2007\hl2.exe |
"{E7B10A1D-DAD8-4C47-B77D-8CA61C761539}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E939A5C5-D789-429D-8341-55344ADD0FD2}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dlbcpswx.exe |
"{E9B51242-48CA-4559-AC33-5ED6A72CE8AB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{E9D3D29C-A87E-4D00-8BA9-C1FA0A2F9413}" = protocol=17 | dir=in | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{EBBE6564-0A70-49DC-81E0-4C406FF0264B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{EC3A65C3-3D7B-4FEC-ACD4-327713108C4D}" = protocol=17 | dir=in | app=c:\program files (x86)\id software\enemy territory - quake wars\etqwded.exe |
"{EEB6C271-8405-4E74-8360-86C0015E730F}" = protocol=17 | dir=in | app=c:\program files (x86)\hamachi\hamachi.exe |
"{F06F1DE3-D2A3-4B13-86CA-D2253B08C152}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{F4B8FCA3-A31F-4AD2-B047-80748D58BF57}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe |
"{F522638C-977B-4F0E-90FF-ACB25C12E826}" = protocol=6 | dir=in | app=c:\windows\syswow64\dlbccoms.exe |
"{F6756F33-B659-40A8-AE26-DE238ADF4B04}" = protocol=6 | dir=in | app=c:\program files (x86)\gaijin\wings of prey\launcher.exe |
"{FA5EB6D0-9455-449D-A294-953FD813B5AF}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |
"{FC767B71-FEA7-4908-8D1E-CD3B8A722CCA}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{FCB9257B-E969-43CB-BD6F-D70D16DB7075}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwawmp.exe |
"{FDCECB12-CE76-4F03-ABFC-233FA2103F8B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{FDE6FCB5-F355-40AB-91CF-70E285F41698}" = protocol=6 | dir=in | app=c:\program files (x86)\activision\call of duty - world at war\codwaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.0.0 (r181)
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{64A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java™ SE Development Kit 6 Update 11 (64-bit)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8753DF4D-64B0-474E-9A97-0AB5585D9A53}" = Logitech Gaming Software 5.04
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"SP6" = Logitech SetPoint 6.0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty® - World at War™ 1.6 Patch
"{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
"{127B684B-A002-44C8-99A7-6CF8F1E26873}" = PunkBuster for Battlefield 1942
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235BBFC6-D863-4066-A01A-3BD504C31033}" = Nero 7 Ultra Edition
"{24508D50-EB8F-4FE6-B69D-B4935D8745EF}_is1" = Warsow 0.5
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}" = Pro Evolution Soccer 2010
"{28526951-55EF-4901-A0CA-B9AC966D1DD1}" = Split/Second
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"{32A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java™ SE Development Kit 6 Update 11
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3E4B349F-10B5-4586-9D99-489A90A8B228}" = Sid Meier's Civilization 4 - Warlords
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F425F12-3A1B-4511-97B2-E2BB4701B745}" = Crysis Wars®
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{43E506CC-6633-4F2A-8D8E-4A95D2384393}" = Crysis Wars® Patch
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{50D4CB89-AF34-4978-96DC-C3034062E901}" = Battlefield 2: Special Forces
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{52D1D62C-FEAB-4580-849E-1DB624BADBBD}" = DiRT2
"{5454083B-1308-4485-BF17-111000028701}" = Grand Theft Auto: Episodes from Liberty City
"{5454083B-1308-4485-BF17-1110000B8301}" = Grand Theft Auto IV
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{57B89E30-0BBA-4F20-9F2C-8E8CDE1CEDB6}" = DiRT
"{59ABBDF0-E1E5-48AF-85FB-F523A08C3490}" = STREET FIGHTER IV
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{5BDAA2F7-8E48-4AFF-AA92-B559D0CDF1AD}" = Serious Sam: The Second Encounter
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60147180-8370-44BC-9BBD-E554D86F0BA3}" = Livestream Procaster
"{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
"{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}" = Command & Conquer The First Decade
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68BD9036-0952-4849-AE7A-963BB53EDB71}" = GGPO
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6FE3B0CE-37C1-4825-908A-5A84C9B4EC2F}" = EA SPORTS™ FIFA Online
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty® - World at War™ 1.7 Patch
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{815050E5-F545-11D4-9569-004095812ACC}" = Serious Sam: The First Encounter
"{82696435-8572-4D8B-A230-D1AA567D0F0F}" = Command & Conquer™ 4 Tiberian Twilight
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8F5A0981-5CDC-41D0-BCA2-AD3B777FC358}" = Thrustmaster Force Feedback Driver
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"{932FB3F3-594D-4600-ABFA-F2DE80A14214}" = Marvel™ - Ultimate Alliance
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout™ Paradise The Ultimate Box
"{9B63540D-D942-4C38-B42E-A48AE0145970}" = Virtua Tennis™ 2009
"{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B73B4A99-4173-4747-BBEC-0F05E966F9D2}" = Battlefield 1942: Secret Weapons of WWII
"{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - Quake Wars™
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{bd8defa4-19fa-4964-9692-f1112d8a62d9}}_is1" = Wings of Prey [removed]
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard
"{CC2422C9-F7B5-4175-B295-5EC2283AA674}" = Command & Conquer™ 3: Kane's Wrath
"{CD1DF19E-4ED2-43F5-9E07-D4DD22D1671E}" = EVGA E-LEET
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D07643A3-CE41-4286-8C78-EB9C83E76DDB}" = PunkBuster for Battlefield Vietnam
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 ESD
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"{D88064EC-0864-420E-99D5-E34828ABF39D}" = SharePort Network USB Utility
"{DA2A851C-6E2B-4677-9DA5-5ED9A3B227E2}" = Quake Live Internet Explorer Plugin
"{DDE59617-F59A-473B-BC4E-C2B81F6CD38D}" = Command & Conquer™ Red Alert™ 3 Uprising
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E35B3C63-E958-4E31-A178-95D22024109A}" = Battlefield Vietnam™
"{E4511CEC-2E60-4076-95B6-0E193269EB86}" = MicroMachines V4
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2835483-37F2-4123-B4FE-0E77D58447F2}" = Far Cry 2
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"AnyDVD" = AnyDVD
"bgbennyboyCMIReplacementSetup_is1" = Curse Of Monkey Island
"bgbennyboyEMIReplacementSetup_is1" = Escape From Monkey Island
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Company of Heroes" = Company of Heroes
"Crysis WARHEAD®" = Crysis WARHEAD®
"Crysis Wars®" = Crysis Wars®
"Crysis Wars® Patch" = Crysis Wars® Patch
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"dBpowerAMP Ogg Vorbis Codec" = dBpowerAMP Ogg Vorbis Codec
"dBpowerAMP WMA V9 Codec" = dBpowerAMP WMA V9 Codec
"Dell Photo Printer 720" = Dell Photo Printer 720
"DesktopX" = DesktopX
"DivX Setup.divx.com" = DivX Setup
"Download Manager" = Download Manager 2.3.10
"DVD Decrypter" = DVD Decrypter (Remove Only)
"EADM" = EA Download Manager
"ERUNT_is1" = ERUNT 1.1j
"Fraps" = Fraps (remove only)
"GamersInternetTunnel_is1" = GIT v0.99 BETA 4
"GoldenEye Source" = GoldenEye: Source - HalfLife 2 Mod
"Google Updater" = Google Updater
"Hoyle Casino 2009" = Hoyle Casino 2009
"Impulse" = Impulse
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty® - World at War™ 1.6 Patch
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD Ultra
"InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572}" = Call of Duty® - World at War™ 1.7 Patch
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"InstallShield_{932FB3F3-594D-4600-ABFA-F2DE80A14214}" = Marvel™ - Ultimate Alliance
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B}" = Call of Duty® - World at War™ 1.1 Patch
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty® 4 - Modern Warfare™
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mIRC" = mIRC
"Monkey Island 2 Special Edition LeChuck’s Revenge" = Monkey Island® 2 Special Edition: LeChuck’s Revenge®
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"Nidesoft DVD Ripper_is1" = Nidesoft DVD Ripper v3.0
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OnLive" = OnLive
"OpenAL" = OpenAL
"Painkiller Black Edition" = Painkiller Black Edition
"PFPortChecker" = PFPortChecker 1.0.28
"Precision" = EVGA Precision 1.3.3
"PROPLUS" = Microsoft Office Professional Plus 2007
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer
"RiseOfNationsExpansion 1.0" = Rise of Nations
"SHOUTcastDSP" = SHOUTcast Source DSP 1.9.0 (remove only)
"SpeedFan" = SpeedFan (remove only)
"Starcraft" = Starcraft
"Steam App 10500" = Empire: Total War
"Steam App 10680" = Aliens vs Predator
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 20570" = Warhammer 40,000: Dawn of War II - Chaos Rising
"Steam App 218" = Source SDK Base - Orange Box
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 25700" = Madballs in…Babo: Invasion
"Steam App 280" = Half-Life: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 360" = Half-Life Deathmatch: Source
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 4000" = Garry's Mod
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 630" = Alien Swarm
"Tales of Monkey Island - Lair of the Leviathan" = Tales of Monkey Island - Lair of the Leviathan
"Tales of Monkey Island - Launch of the Screaming Narwhal" = Tales of Monkey Island - Launch of the Screaming Narwhal
"Tales of Monkey Island - Rise of the Pirate God" = Tales of Monkey Island - Rise of the Pirate God
"Tales of Monkey Island - The Siege of Spinner Cay" = Tales of Monkey Island - The Siege of Spinner Cay
"Tales of Monkey Island - The Trial and Execution of Guybrush Threepwood" = Tales of Monkey Island - The Trial and Execution of Guybrush Threepwood
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"The Secret of Monkey Island Special Edition" = The Secret of Monkey Island Special Edition
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"Tomb Raider - Legend" = Tomb Raider - Legend (remove only)
"Tomb Raider: Anniversary" = Tomb Raider: Anniversary 1.0
"Tomb Raider: Underworld" = Tomb Raider: Underworld 1.0
"Torchlight" = Torchlight
"Trials 2 SE" = Trials 2 Second Edition
"Trine_is1" = Trine 1.03
"UnrealTournament" = Unreal Tournament G.O.T.Y. Edition
"UT2004" = Unreal Tournament 2004
"VideoGet_is1" = Nuclear Coffee - VideoGet
"Warcraft III" = Warcraft III
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 3.0
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"Xfire" = Xfire (remove only)
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"yuPlay êëèåíò_is1" = yuPlay client 0.7.7
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"InstallShield_{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/10/2010 5:41:03 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 5:57:52 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 6:27:29 AM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 6:27:29 AM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 6:28:25 AM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 7:07:39 AM | Computer Name = Dones-PC | Source = Application Error | ID = 1000
Description = Faulting application BF1942.exe, version 0.0.0.0, time stamp 0x417564c4,
faulting module BF1942.exe, version 0.0.0.0, time stamp 0x417564c4, exception code
0xc0000005, fault offset 0x002016fb, process id 0x9ec, application start time 0x01cb088ce6494c71.
Error - 6/10/2010 7:09:18 AM | Computer Name = Dones-PC | Source = Application Error | ID = 1000
Description = Faulting application BF1942.exe, version 0.0.0.0, time stamp 0x417564c4,
faulting module BF1942.exe, version 0.0.0.0, time stamp 0x417564c4, exception code
0xc0000005, fault offset 0x002016fb, process id 0xc54, application start time 0x01cb088d29136f8c.
Error - 6/10/2010 4:30:10 PM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 4:30:10 PM | Computer Name = Dones-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\id
Software\Enemy Territory - QUAKE Wars\ServerLauncher.exe".Error in manifest or
policy file "" on line . A component version required by the application conflicts
with another component version already active. Conflicting components are:. Component
1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
Error - 6/10/2010 4:30:49 PM | Computer Name = Dones-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:22 PM | Computer Name = Dones-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 2
Description =
Error - 8/10/2010 4:24:31 PM | Computer Name = Dones-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\Aspi32.SYS has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.
Error - 8/10/2010 4:25:10 PM | Computer Name = Dones-PC | Source = ps6ah4nb | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.
Error - 8/10/2010 4:26:10 PM | Computer Name = Dones-PC | Source = Service Control Manager | ID = 7026
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:15:19 AM, on 8/11/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Users\Dones\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [D-Link Network USB Utility] C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe -mini
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [DesktopX] "C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\desktopx.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files (x86)\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O15 - Trusted Zone: fe.trymedia.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} (EAFO3AXLauncher Control) - http://fifa-online.easports.com/fo3-theme/…3AXLauncher.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - http://service.futuremark.com/gom/receiver/tc/FMSI.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: dlbc_device - - C:\Windows\system32\dlbccoms.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: DiRT Drivers Auto Removal (pr2ah4nb) (pr2ah4nb) - Unknown owner - C:\Windows\system32\pr2ah4nb.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 10278 bytes
DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 1:18:28.61 on Wed 08/11/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3062.838 [GMT -7:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\dlbccoms.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Windows\system32\svchost.exe -k bthaudiosvc
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\mobsync.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Users\Dones\Desktop\HiJackThis.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dones\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\17.7.0.12\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\17.7.0.12\coIEPlg.dll
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\daemon.exe" -autorun
uRun: [DesktopX] "c:\program files (x86)\stardock\object desktop\desktopx\desktopx.exe"
mRun: [DiscWizardMonitor.exe] c:\program files (x86)\seagate\discwizard\DiscWizardMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files (x86)\seagate\discwizard\TimounterMonitor.exe
mRun: [D-Link Network USB Utility] c:\program files (x86)\d-link\shareport\SharePort Network USB Utility.exe -mini
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files (x86)\belkin\bluetooth software\btsendto_ie_ctx.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
Trusted Zone: trymedia.com\fe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {6678BE91-1E04-4A4A-9C32-63145EA79C2A} - hxxp://fifa-online.easports.com/fo3-theme/addons/EAFO3AXLauncher.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.53.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/gom/receiver/tc/FMSI.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~2\common~1\stardock\mcpcore.dll
LSA: Authentication Packages = msv1_0 relog_ap
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [Seagate Scheduler2 Service] "c:\program files (x86)\common files\seagate\schedule2\schedhlp.exe"
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
================= FIREFOX ===================
FF - ProfilePath - c:\users\dones\applic~1\mozilla\firefox\profiles\i2cgbi12.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\download manager\npfpdlm.dll
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files (x86)\onlive\firefoxplugin\npolgdet.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: c:\users\dones\application data\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\users\dones\application data\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [2007-7-19 72296]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [2007-7-19 102000]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nisx64\1107000.00c\symds64.sys [2010-5-25 433200]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1107000.00c\symefa64.sys [2010-5-25 221232]
R1 BHDrvx64;BHDrvx64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\bashdefs\20100719.001\BHDrvx64.sys [2010-7-19 945200]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1107000.00c\cchpx64.sys [2010-5-25 615040]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.0.0.136\definitions\ipsdefs\20100809.001\IDSviA64.sys [2010-8-10 463408]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nisx64\1107000.00c\ironx64.sys [2010-5-25 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nisx64\1107000.00c\symtdiv.sys [2010-5-25 451120]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 HFGService;Handsfree Headset Service;c:\windows\system32\svchost.exe -k bthaudiosvc [2008-1-20 27648]
R2 NIS;Norton Internet Security;c:\program files (x86)\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-5-25 126392]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\common files\seagate\schedule2\schedul2.exe [2008-6-24 605464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-11-20 240232]
R3 BthAudioHF;BthAudioHF Service;c:\windows\system32\drivers\BthAudioHF.sys [2010-2-5 56728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-27 132656]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-12-18 135664]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc –> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 ENTECH64;ENTECH64;c:\windows\system32\drivers\Entech64.sys [2009-1-17 12744]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-4-6 50072]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-5-25 19544]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework64\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-5-29 89920]
S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\logmein hamachi\hamachi-2.exe [2010-3-30 1823112]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-08-08 05:41:16 0 d—–r- c:\program files (x86)\Skype
2010-08-07 01:38:44 11584512 —-a-w- c:\windows\syswow64\shell32.dll
2010-07-29 03:21:44 0 d—–w- c:\program files (x86)\Livestream Procaster
==================== Find3M ====================
2010-08-10 20:25:00 171548 —-a-w- c:\programdata\nvModes.dat
2010-08-10 08:04:44 51200 —-a-w- c:\windows\inf\infpub.dat
2010-08-10 08:04:44 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-08-10 08:04:42 86016 —-a-w- c:\windows\inf\infstor.dat
2010-07-31 09:34:58 218808 —-a-w- c:\windows\syswow64\PnkBstrB.exe
2010-06-09 02:18:44 2427248 —-a-w- c:\windows\syswow64\pbsvc_heroes.exe
2010-06-07 08:22:36 794408 —-a-w- c:\windows\syswow64\pbsvc.exe
2010-05-26 17:23:46 48128 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 17:06:41 34304 —-a-w- c:\windows\syswow64\atmlib.dll
2010-05-26 15:10:41 366080 —-a-w- c:\windows\system32\atmfd.dll
2010-05-26 14:47:41 289792 —-a-w- c:\windows\syswow64\atmfd.dll
2009-10-30 08:45:30 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:18:21 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:18:21 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-10 00:33:54 245760 –sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 1:18:41.89 ===============