This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32.Hiloti.gen!D (and possibly others?)

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently I got hit up with a ridiculous amount of trojans. I believe I removed most of them with the help of Avira AntiVir and by clearing out the suspicious files from my AppData folders, but then I BlueScreen'd after a bit (think that's a problem my computer has with the internet in certain rooms, though) and had to restart. The computer spent an unusual amount of time at the pre-loading stage (where the logo of the manufacturer is shown) and then it started up again. Then Windows Defender told me that the Win32.Hiloti.gen!D trojan was on my computer, in two files in my Local files, and then asked me to remove then. The files are C:\Users\Kirby\AppData\Local\inarafoxosivolup.dll and C:\Users\Kirby\AppData\Local\ska08.(forget extenstion name). I removed them, and now it's asking me to restart. I will, but before I do I wanted to ask what I should do next, as now I'm unsure I removed everything from the initial infection.

inarafoxosivolup.dll is still in my Local folder, and I can't seem to get rid of it. It's properties claim it as an ACLSet2 file, whatever that means, and claims to be last modified in 2008.

I'm running Windows Vista Home Premium (32-bit) Service Pack 1, on a Compaq C777CL Notebook laptop. Thanks in advance for helping me out.

Posting the OTL.txt log from OTL:
OTL logfile created on: 9/3/2010 10:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Kirby\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 30.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.52 Gb Total Space | 22.36 Gb Free Space | 16.26% Space Free | Partition Type: NTFS
Drive D: | 11.53 Gb Total Space | 2.03 Gb Free Space | 17.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KIRBY-PC
Current User Name: Kirby
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Kirby\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\SecureW2\sw2_tray.exe (SecureW2 B.V.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (http://tortoisesvn.net)
PRC - C:\Program Files\WTouch\WTouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Evernote\Evernote3\EvernoteTray.exe (Evernote Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\System32\WTablet\Wacom_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wisptis.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe (National Instruments, Inc.)
PRC - C:\Windows\System32\lktsrv.exe (National Instruments, Inc.)
PRC - C:\Windows\System32\lkads.exe (National Instruments, Inc.)
PRC - C:\Windows\System32\nisvcloc.exe (National Instruments Corp.)
PRC - C:\Windows\System32\lkcitdl.exe (National Instruments, Inc.)
PRC - C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe ()
PRC - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Kirby\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV - (TabletServicePen) – C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (TabletServiceWacom) – C:\Windows\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (msvsmon90) – c:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (NIDomainService) – C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe (National Instruments, Inc.)
SRV - (lkTimeSync) – C:\Windows\System32\lktsrv.exe (National Instruments, Inc.)
SRV - (lkClassAds) – C:\Windows\System32\lkads.exe (National Instruments, Inc.)
SRV - (niSvcLoc) – C:\Windows\System32\nisvcloc.exe (National Instruments Corp.)
SRV - (LkCitadelServer) – C:\Windows\System32\lkcitdl.exe (National Instruments, Inc.)
SRV - (Adobe Version Cue CS2) – C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (SymIM) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (ojaeeuny) – C:\Windows\System32\drivers\ojaeeuny.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (notecable) NoteCable Driver (WDM) – C:\Windows\System32\drivers\notcable.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (evudmdm) Epivalley® – C:\Windows\System32\drivers\evudmdm.sys (MCCI Corporation)
DRV - (evudserd) Epivalley® Device Status 1 Driver (WDM) – C:\Windows\System32\drivers\evudserd.sys (MCCI Corporation)
DRV - (evuddiag) Epivalley® Device Status 2 Driver (WDM) – C:\Windows\System32\drivers\evuddiag.sys (MCCI Corporation)
DRV - (evudbus) Epivalley® Composite Device driver (WDM) – C:\Windows\System32\drivers\evudbus.sys (MCCI Corporation)
DRV - (evudmdfl) ~Epivalley® – C:\Windows\System32\drivers\evudmdfl.sys (MCCI Corporation)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (wacmoumonitor) – C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (WacomVTHid) – C:\Windows\System32\drivers\WacomVTHid.sys (Wacom Technology)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (seehcri) – C:\Windows\System32\drivers\seehcri.sys (Sony Ericsson Mobile Communications)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (CamdVideo) – C:\Windows\System32\drivers\CamdVideo.sys (Windows ® 2000 DDK provider)
DRV - (CamdAudio) – C:\Windows\System32\drivers\CamdAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (RsFx0102) – C:\Windows\System32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HSFHWAZL) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (a016obex) – C:\Windows\System32\drivers\a016obex.sys (MCCI Corporation)
DRV - (a016mdm) – C:\Windows\System32\drivers\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt) Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM) – C:\Windows\System32\drivers\a016mgmt.sys (MCCI Corporation)
DRV - (a016mdfl) – C:\Windows\System32\drivers\a016mdfl.sys (MCCI Corporation)
DRV - (a016bus) Sony Ericsson Device A016 driver (WDM) – C:\Windows\System32\drivers\a016bus.sys (MCCI Corporation)
DRV - (tbhsd) – C:\Windows\System32\drivers\tbhsd.sys (RapidSolution Software AG)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\Windows\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (BCM43XV) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ggsemc) – C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (cvintdrv) – C:\Windows\System32\drivers\cvintdrv.sys ()
DRV - (WINIO) – C:\Windows\System32\winio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.gamingw.net/forums/index.php"
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.11
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js..extensions.enabledItems: [removed]:2.00.100530
FF - prefs.js..extensions.enabledItems: {57ECB6B5-A28C-4E00-92D6-90C74D942452}:1.9.1
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/05 10:06:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/13 13:37:34 | 000,000,000 | —D | M]

[2008/08/29 01:12:53 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Mozilla\Extensions
[2010/09/03 21:54:33 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions
[2010/02/19 13:12:24 | 000,000,000 | —D | M] (All-in-One Sidebar) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2010/07/04 22:17:16 | 000,000,000 | —D | M] (Rikaichan) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82}
[2010/01/15 23:11:38 | 000,000,000 | —D | M] (Session Manager) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2008/08/29 01:17:02 | 000,000,000 | —D | M] (Abstract Classic) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}
[2009/01/26 10:51:27 | 000,000,000 | —D | M] (oldbar) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2010/04/21 01:21:03 | 000,000,000 | —D | M] (Japanese-English Dictionary for rikaichan) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{6D898772-AD34-4c16-86BB-9DE787A5DEA0}
[2010/02/15 20:40:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/01/15 23:11:38 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/16 15:18:07 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/07/06 15:53:57 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\extensions\[removed]
[2010/09/03 13:15:53 | 000,002,682 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\ann-encyclopedia.xml
[2009/01/20 03:15:43 | 000,002,076 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\baka-updates.xml
[2010/06/11 05:10:52 | 000,000,914 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\dictionarycom.xml
[2009/05/14 14:06:50 | 000,001,033 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\gendou.xml
[2010/08/30 13:18:17 | 000,002,786 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\google-images.xml
[2010/08/30 13:18:17 | 000,002,580 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\imdb.xml
[2010/08/30 13:18:17 | 000,001,894 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\isohunt—bittorrent.xml
[2010/08/30 13:18:19 | 000,002,610 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\manga-updates.xml
[2010/08/30 13:18:17 | 000,001,942 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\mycroft-project.xml
[2010/06/11 05:10:19 | 000,000,911 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\thesauruscom.xml
[2010/08/30 13:18:17 | 000,001,209 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\tv-tropes.xml
[2010/08/30 13:18:17 | 000,002,201 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\tvcom-search.xml
[2008/11/16 16:02:57 | 000,002,006 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\urban-dictionary.xml
[2008/12/09 15:35:56 | 000,000,705 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\webster.xml
[2010/08/30 13:18:17 | 000,002,087 | —- | M] () – C:\Users\Kirby\AppData\Roaming\Mozilla\Firefox\Profiles\23brnvv4.default\searchplugins\youtube.xml
[2009/10/04 15:44:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/10/03 22:32:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2005/10/12 16:04:02 | 000,020,480 | —- | M] (National Instruments) – C:\Program Files\Mozilla Firefox\plugins\NPLV80Win32.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2009/04/25 17:08:28 | 000,000,791 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Sytems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SecureW2 Tray] C:\Program Files\SecureW2\sw2_tray.exe (SecureW2 B.V.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VaCtrl] C:\Program Files\VoiceAge\Common\VaCtrl.exe (VoiceAge Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKCU..\Run: [acxwersomn.exe] C:\Users\Kirby\AppData\Local\Temp\acxwersomn.exe File not found
O4 - HKCU..\Run: [ahcopces] C:\Users\Kirby\AppData\Local\pdxtwu\rsybsftav.exe File not found
O4 - HKCU..\Run: [ahloyduv] C:\Users\Kirby\AppData\Local\gjdowl\rkbmsftav.exe File not found
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [bhbnoxgi] C:\Users\Kirby\AppData\Local\skjhwx\rtrpsftav.exe File not found
O4 - HKCU..\Run: [cgolcmul] C:\Users\Kirby\AppData\Local\hsbnuo\rebisftav.exe File not found
O4 - HKCU..\Run: [COM+ Manager] C:\Users\Kirby\.COMMgr\complmgr.exe File not found
O4 - HKCU..\Run: [dgglslei] C:\Users\Kirby\AppData\Local\rmvsux\rnywsftav.exe File not found
O4 - HKCU..\Run: [kqsbokuq] C:\Users\Kirby\AppData\Local\intqvbcwj\xmrjqfyshdw.exe File not found
O4 - HKCU..\Run: [popaomhk] C:\Users\Kirby\AppData\Local\hakjchgvq\mvkwsnlshdw.exe File not found
O4 - HKCU..\Run: [tjwindon] C:\Users\Kirby\AppData\Local\hmyapw\rdvysftav.exe File not found
O4 - HKCU..\Run: [uieutkuo] C:\Users\Kirby\AppData\Local\cqhqce\rvbusftav.exe File not found
O4 - HKCU..\Run: [ujnudmlr] C:\Users\Kirby\AppData\Local\swmmcu\rmdhsftav.exe File not found
O4 - HKCU..\Run: [vdhhuqdx] C:\Users\Kirby\AppData\Local\bmgrvqbld\xvimdgfshdw.exe File not found
O4 - HKCU..\Run: [vicgrqln] C:\Users\Kirby\AppData\Local\gollnw\rwdfsftav.exe File not found
O4 - HKCU..\Run: [vikfyoeg] C:\Users\Kirby\AppData\Local\acbunp\roygsftav.exe File not found
O4 - HKCU..\Run: [vilgbscq] C:\Users\Kirby\AppData\Local\wuqhnm\rngrsftav.exe File not found
O4 - HKCU..\Run: [wibfpmnd] C:\Users\Kirby\AppData\Local\jvwana\rxwusftav.exe File not found
O4 - HKCU..\Run: [wirfglxa] C:\Users\Kirby\AppData\Local\spremj\rgtisftav.exe File not found
O4 - HKCU..\Run: [xhgdtald] C:\Users\Kirby\AppData\Local\ixjkla\rqdbsftav.exe File not found
O4 - HKCU..\Run: [xixemdsk] C:\Users\Kirby\AppData\Local\oksblg\ryiysftav.exe File not found
O4 - HKCU..\Run: [xiyrnsec] C:\Users\Kirby\AppData\Local\ntauyr\ryyesftav.exe File not found
O4 - HKCU..\Run: [yhecsvnt] C:\Users\Kirby\AppData\Local\lftyld\rrwqsftav.exe File not found
O4 - HKCU..\Run: [yheprgcc] C:\Users\Kirby\AppData\Local\mvmfxr\rrglsftav.exe File not found
O4 - HKCU..\Run: [yhfptlal] C:\Users\Kirby\AppData\Local\jocrxo\rrnvsftav.exe File not found
O4 - HKCU..\Run: [yhvpkjji] C:\Users\Kirby\AppData\Local\tiwvxx\rakjsftav.exe File not found
O4 - Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Anki.lnk = C:\Program Files\Anki\Anki.exe (Damien Elmes)
O4 - Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Evernote.lnk = C:\Program Files\Evernote\Evernote3\EvernoteTray.exe (Evernote Corporation)
O4 - Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\foobar2000.lnk = C:\Program Files\foobar2000\foobar2000.exe ()
O4 - Startup: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ntuser_mssec.exe ()
O8 - Extra context menu item: &AIM Search - c:\Program Files\AOL\AIM Toolbar 5.0\resources\en-us\local\search.html ()
O8 - Extra context menu item: Add to Evernote - C:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - Reg Error: Value error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll (Evernote Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/27 03:45:25 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{26f3e461-8f17-11dd-a6e5-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{26f3e461-8f17-11dd-a6e5-001eec77546b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{346e13ce-7d84-11df-835b-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{346e13ce-7d84-11df-835b-001eec77546b}\Shell\AutoRun\command - "" = F:\Autorun.exe – File not found
O33 - MountPoints2\{346e1433-7d84-11df-835b-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{346e1433-7d84-11df-835b-001eec77546b}\Shell\AutoRun\command - "" = F:\Autorun.exe – File not found
O33 - MountPoints2\{350fb917-00ba-11de-abee-001eec77546b}\Shell\1\Command - "" = Recycled.exe
O33 - MountPoints2\{350fb917-00ba-11de-abee-001eec77546b}\Shell\2\Command - "" = Recycled.exe
O33 - MountPoints2\{65b3048d-da0c-11dd-abdd-001eec77546b}\Shell\AutoRun\command - "" = F:\m9ma.exe – File not found
O33 - MountPoints2\{65b3048d-da0c-11dd-abdd-001eec77546b}\Shell\explore\Command - "" = F:\m9ma.exe – File not found
O33 - MountPoints2\{65b3048d-da0c-11dd-abdd-001eec77546b}\Shell\open\Command - "" = F:\m9ma.exe – File not found
O33 - MountPoints2\{65b3098c-da0c-11dd-abdd-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{65b3098c-da0c-11dd-abdd-001eec77546b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{6e8a092e-20e5-11de-b8f5-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{6e8a092e-20e5-11de-b8f5-001eec77546b}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{bc9afbcf-7580-11dd-942d-001eec77546b}\Shell\AutoRun\command - "" = qquq.bat
O33 - MountPoints2\{bc9afbcf-7580-11dd-942d-001eec77546b}\Shell\explore\Command - "" = qquq.bat
O33 - MountPoints2\{bc9afbcf-7580-11dd-942d-001eec77546b}\Shell\open\Command - "" = qquq.bat
O33 - MountPoints2\{e7fb9b4d-a45b-11dd-922f-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{e7fb9b4d-a45b-11dd-922f-001eec77546b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{fe5f756a-cf78-11dd-ac06-001eec77546b}\Shell - "" = AutoRun
O33 - MountPoints2\{fe5f756a-cf78-11dd-ac06-001eec77546b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.VaAcelpNet - C:\Program Files\VoiceAge\Common\VaAcelpNet.acm (VoiceAge Corporation)
Drivers32: msacm.VaAmrNbF - C:\Program Files\VoiceAge\Common\VaAmrNbF.acm (VoiceAge Corporation)
Drivers32: msacm.VaAmrNbV - C:\Program Files\VoiceAge\Common\VaAmrNbV.acm (VoiceAge Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/09/03 22:31:07 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Kirby\Desktop\OTL.exe
[2010/09/03 22:04:22 | 000,000,000 | —D | C] – C:\Users\Kirby\Documents\CIS-262
[2010/09/03 21:56:39 | 000,000,000 | —D | C] – C:\Users\Kirby\AppData\Local\TSVNCache
[2010/09/03 21:50:21 | 000,000,000 | —D | C] – C:\Users\Kirby\AppData\Local\{57ECB6B5-A28C-4E00-92D6-90C74D942452}
[2010/09/02 17:54:01 | 000,000,000 | -HSD | C] – C:\Users\Kirby\.COMMgr
[2010/08/30 11:07:58 | 000,000,000 | —D | C] – C:\Program Files\Penn Apps 2010
[2010/08/23 16:09:21 | 000,000,000 | —D | C] – C:\Users\Kirby\Documents\Share
[2010/08/05 03:51:43 | 000,000,000 | —D | C] – C:\Users\Kirby\AppData\Local\Windows
[2010/08/05 03:51:38 | 000,000,000 | —D | C] – C:\Users\Kirby\AppData\Local\Windows Server
[2009/05/14 22:02:10 | 003,392,872 | —- | C] (Acresso Software Inc.) – C:\Program Files\Common Files\adlmint_libFNP.dll
[2009/05/14 22:02:10 | 003,298,152 | —- | C] (Autodesk) – C:\Program Files\Common Files\adlmint.dll
[2008/01/20 22:24:21 | 000,192,512 | —- | C] ( ) – C:\Users\Kirby\AppData\Local\inarafoxosivolup.dll

========== Files - Modified Within 30 Days ==========

[2010/09/03 22:37:21 | 005,505,024 | -HS- | M] () – C:\Users\Kirby\NTUSER.DAT
[2010/09/03 22:35:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{51C3E0A0-2767-4AD4-BB53-0E98157CE560}.job
[2010/09/03 22:31:14 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Kirby\Desktop\OTL.exe
[2010/09/03 21:52:15 | 000,663,900 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/03 21:52:14 | 000,786,800 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/03 21:52:14 | 000,126,596 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/03 21:51:12 | 000,000,279 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/09/03 21:45:01 | 218,069,460 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/09/03 21:45:01 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/03 21:45:00 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/03 21:44:56 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/03 21:44:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/03 21:44:06 | 2134,953,984 | -HS- | M] () – C:\hiberfil.sys
[2010/09/03 21:40:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599389596-1674606367-349658144-1000UA.job
[2010/09/03 17:40:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599389596-1674606367-349658144-1000Core.job
[2010/09/03 02:38:53 | 000,003,584 | —- | M] () – C:\Users\Kirby\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/02 18:49:22 | 009,826,400 | —- | M] () – C:\Users\Kirby\Documents\Documents.rar
[2010/09/01 15:13:51 | 000,524,288 | -HS- | M] () – C:\Users\Kirby\NTUSER.DAT{32ccb1ed-a34a-11de-a98b-001eec77546b}.TMContainer00000000000000000001.regtrans-ms
[2010/09/01 15:13:51 | 000,065,536 | -HS- | M] () – C:\Users\Kirby\NTUSER.DAT{32ccb1ed-a34a-11de-a98b-001eec77546b}.TM.blf
[2010/09/01 15:13:46 | 003,299,421 | -H– | M] () – C:\Users\Kirby\AppData\Local\IconCache.db
[2010/09/01 13:46:31 | 000,034,304 | —- | M] () – C:\Users\Kirby\Documents\resumemodern-new.doc
[2010/08/26 20:45:50 | 000,000,680 | —- | M] () – C:\Users\Kirby\AppData\Local\d3d9caps.dat
[2010/08/25 11:13:20 | 000,218,544 | —- | M] () – C:\Users\Kirby\Documents\Default-4.fpl
[2010/08/23 21:38:42 | 000,014,379 | —- | M] () – C:\Users\Kirby\Documents\Phineas and Ferb.fpl
[2010/08/20 15:53:34 | 000,000,943 | —- | M] () – C:\Users\Kirby\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/19 04:27:33 | 000,000,852 | —- | M] () – C:\Users\Kirby\Application Data\Microsoft\Internet Explorer\Quick Launch\foobar2000.lnk
[2010/08/19 04:27:33 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\foobar2000.lnk
[2010/08/19 03:43:22 | 000,001,882 | —- | M] () – C:\Users\Kirby\Documents\Old Default.fth
[2010/08/19 03:38:11 | 000,008,566 | —- | M] () – C:\Users\Kirby\Documents\Scott Pilgrim vs. The World OST.fpl
[2010/08/19 03:00:49 | 000,014,419 | —- | M] () – C:\Users\Kirby\Documents\Super Mario 64 OST.fpl
[2010/08/18 13:19:06 | 000,002,437 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/08/18 13:19:06 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\Adobe Acrobat 7.0 Professional.lnk
[2010/08/18 13:10:34 | 000,054,272 | —- | M] () – C:\Users\Kirby\Documents\library_student_application.doc
[2010/08/17 03:09:47 | 000,333,824 | —- | M] () – C:\Users\Kirby\Documents\Wages In VFX, Animation, And Games.xls
[2010/08/07 10:01:30 | 000,632,832 | —- | M] () – C:\Users\Kirby\Desktop\card.doc

========== Files Created - No Company Name ==========

[2010/09/03 21:44:11 | 218,069,460 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/09/03 02:38:53 | 000,003,584 | —- | C] () – C:\Users\Kirby\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/02 18:47:39 | 009,826,400 | —- | C] () – C:\Users\Kirby\Documents\Documents.rar
[2010/08/31 10:14:30 | 000,034,304 | —- | C] () – C:\Users\Kirby\Documents\resumemodern-new.doc
[2010/08/23 21:38:19 | 000,014,379 | —- | C] () – C:\Users\Kirby\Documents\Phineas and Ferb.fpl
[2010/08/20 15:53:34 | 000,000,943 | —- | C] () – C:\Users\Kirby\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/19 04:27:33 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\foobar2000.lnk
[2010/08/19 03:43:22 | 000,001,882 | —- | C] () – C:\Users\Kirby\Documents\Old Default.fth
[2010/08/19 03:38:11 | 000,008,566 | —- | C] () – C:\Users\Kirby\Documents\Scott Pilgrim vs. The World OST.fpl
[2010/08/18 13:19:06 | 000,002,437 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/08/18 13:10:33 | 000,054,272 | —- | C] () – C:\Users\Kirby\Documents\library_student_application.doc
[2010/08/17 03:09:20 | 000,333,824 | —- | C] () – C:\Users\Kirby\Documents\Wages In VFX, Animation, And Games.xls
[2010/08/13 17:55:18 | 000,014,419 | —- | C] () – C:\Users\Kirby\Documents\Super Mario 64 OST.fpl
[2010/08/07 10:01:24 | 000,632,832 | —- | C] () – C:\Users\Kirby\Desktop\card.doc
[2010/06/08 01:05:01 | 000,000,000 | —- | C] () – C:\Users\Kirby\AppData\Local\FnF4.txt
[2010/04/09 18:03:49 | 000,000,600 | —- | C] () – C:\Users\Kirby\AppData\Local\PUTTY.RND
[2010/01/24 20:56:18 | 000,000,172 | —- | C] () – C:\Windows\ODBC.INI
[2009/10/03 21:42:47 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/24 20:37:47 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2009/08/24 20:37:47 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2009/08/24 20:36:10 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2009/08/24 20:36:10 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2009/08/24 20:33:14 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2009/08/24 20:33:12 | 000,106,496 | —- | C] () – C:\Windows\System32\BrMuSNMP.dll
[2009/08/24 20:28:59 | 000,031,567 | —- | C] () – C:\Windows\maxlink.ini
[2009/08/06 10:24:05 | 002,463,976 | —- | C] () – C:\Windows\System32\NPSWF32.dll
[2009/06/07 01:40:26 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/05/31 22:33:01 | 000,041,324 | —- | C] () – C:\Windows\System32\winio.sys
[2009/05/31 22:32:33 | 000,000,157 | —- | C] () – C:\Windows\matlab.ini
[2009/05/31 13:12:28 | 000,716,272 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/04/22 00:19:06 | 000,172,173 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/03/29 23:36:43 | 000,000,080 | RHS- | C] () – C:\Windows\System32\7F3CB44FCF.dll
[2009/02/15 15:55:06 | 000,011,168 | -H– | C] () – C:\ProgramData\gerofunu
[2009/01/27 02:13:55 | 000,000,622 | —- | C] () – C:\Users\Kirby\AppData\Roaming\wklnhst.dat
[2008/12/30 21:01:20 | 000,005,091 | —- | C] () – C:\ProgramData\idwyfyfc.dba
[2008/09/07 16:14:21 | 000,061,678 | —- | C] () – C:\Users\Kirby\AppData\Roaming\PFP100JPR.{PB
[2008/09/07 16:14:21 | 000,012,358 | —- | C] () – C:\Users\Kirby\AppData\Roaming\PFP100JCM.{PB
[2008/09/04 19:05:18 | 000,000,680 | —- | C] () – C:\Users\Kirby\AppData\Local\d3d9caps.dat
[2008/08/29 11:34:49 | 000,000,000 | —- | C] () – C:\Users\Kirby\AppData\Local\QSwitch.txt
[2008/08/29 11:34:49 | 000,000,000 | —- | C] () – C:\Users\Kirby\AppData\Local\DSwitch.txt
[2008/08/29 11:34:48 | 000,000,000 | —- | C] () – C:\Users\Kirby\AppData\Local\AtStart.txt
[2008/06/18 00:39:22 | 000,155,648 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2008/02/27 03:59:45 | 000,001,501 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/12/03 12:46:16 | 000,000,000 | —- | C] () – C:\ProgramData\f7129022-a000-4847-db07-470265a73c4f
[2007/08/23 20:30:00 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2007/08/20 08:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 08:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/08/20 08:10:18 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/06/10 10:00:00 | 000,102,400 | —- | C] () – C:\Windows\System32\cviUSI.dll
[2005/06/10 10:00:00 | 000,007,140 | —- | C] () – C:\Windows\System32\drivers\cvintdrv.sys
[2002/06/06 02:01:58 | 000,029,696 | —- | C] () – C:\Windows\System32\asutl8.dll

========== LOP Check ==========

[2010/07/22 17:08:26 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\.anki
[2008/09/13 22:58:54 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\acccore
[2008/09/19 21:17:44 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Anvil Studio
[2010/01/12 14:50:53 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Autodesk
[2009/04/01 10:29:25 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\DJJava
[2010/06/28 00:48:24 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\EpiValley
[2010/01/14 22:49:35 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\fltk.org
[2010/09/01 15:20:59 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\foobar2000
[2009/06/16 23:04:33 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Maple
[2010/07/06 15:53:03 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\mplayer
[2008/11/08 00:45:46 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\NoteCable
[2009/12/10 01:15:50 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Notepad++
[2009/05/05 21:59:54 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Opera
[2010/05/14 01:34:58 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Red Kawa
[2010/07/05 00:27:50 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Regensoft
[2009/08/24 19:39:16 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Ruckus Network
[2008/11/18 18:21:04 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\SecondLife
[2008/12/25 12:24:33 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Sony
[2009/02/14 06:32:18 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\SpaceMonger
[2010/04/09 17:59:46 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Subversion
[2009/01/27 02:14:02 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Template
[2009/04/04 20:58:08 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Toon Boom Animation
[2008/11/27 04:29:00 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Tunebite
[2008/12/14 07:10:35 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\Unity
[2010/09/02 18:46:47 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\uTorrent
[2009/07/25 18:03:39 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\WildTangent
[2009/12/08 18:24:00 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\WTouch
[2010/02/24 01:33:03 | 000,000,000 | —D | M] – C:\Users\Kirby\AppData\Roaming\XMind
[2010/09/01 15:14:02 | 000,032,554 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/09/03 22:35:00 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{51C3E0A0-2767-4AD4-BB53-0E98157CE560}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/27 03:45:25 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2008/01/20 22:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/09/03 21:44:06 | 2134,953,984 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/09/13 22:58:35 | 000,000,749 | -H– | M] () – C:\IPH.PH
[2002/01/05 05:48:16 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\mfc70.dll
[2002/01/05 05:36:38 | 000,964,608 | —- | M] (Microsoft Corporation) – C:\mfc70u.dll
[2002/01/05 04:40:20 | 000,487,424 | —- | M] (Microsoft Corporation) – C:\msvcp70.dll
[2002/01/05 04:37:28 | 000,344,064 | —- | M] (Microsoft Corporation) – C:\msvcr70.dll
[2010/09/03 21:44:03 | 2450,804,736 | -HS- | M] () – C:\pagefile.sys
[2008/12/28 13:30:06 | 000,000,594 | —- | M] () – C:\updatedatfix.log
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/12/17 18:05:32 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/01/20 22:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/09/25 17:49:27 | 000,000,332 | -HS- | M] () – C:\Users\Kirby\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/03 22:44:10 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Kirby\Desktop\HiJackThis.exe
[2010/09/03 22:31:14 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Kirby\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >
[2009/05/14 22:02:10 | 003,298,152 | —- | M] (Autodesk) – C:\Program Files\Common Files\adlmint.dll
[2009/05/14 22:02:10 | 003,392,872 | —- | M] (Acresso Software Inc.) – C:\Program Files\Common Files\adlmint_libFNP.dll

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-11-13 16:59:35
< End of report >




Posting Extras.txt log from OTL:
OTL Extras logfile created on: 9/3/2010 10:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Kirby\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 30.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.52 Gb Total Space | 22.36 Gb Free Space | 16.26% Space Free | Partition Type: NTFS
Drive D: | 11.53 Gb Total Space | 2.03 Gb Free Space | 17.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KIRBY-PC
Current User Name: Kirby
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [SpaceMonger] – "C:\Program Files\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{749B76B8-1C97-4257-904D-59A4169C3A79}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{890E3347-B02D-4F15-925C-4B5544816B80}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B1FB99E0-2AE2-442C-AC33-7864B6F74D90}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{B7D5E0F0-4D6B-4B5E-9F52-0830EAAA920B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01CA4C70-B84A-412A-A500-A0FEE55BAFDA}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{0496BC4C-8A34-49A0-ACCF-59242569C37B}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{0508FFC1-CEC1-41DC-AF96-59C9B31D3D75}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{0536CFEC-905E-456B-98BE-FF3D1A6AB17D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{07F0ED00-9FD9-4691-ACF1-14513B50A265}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{09EF94DC-ACB8-4E2D-B74E-8A2BD7C9154D}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{0BBFA798-238F-4BF9-BDFB-6CC2EF198ACB}" = protocol=6 | dir=in | app=c:\program files\avira\antivir desktop\update.exe |
"{0DF69E0D-3992-47A1-9AC3-D86C09A137F6}" = protocol=17 | dir=in | app=c:\program files\brother\brmfl08b\faxrx.exe |
"{139FA1B3-DA70-4459-A53A-365B7F459540}" = protocol=6 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{152A25A7-DCB2-4DE9-8C34-5C9FCC4F3497}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{284863F2-E03D-4E2B-830F-1FF14A26A8B5}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{2A1A24FA-B14A-4329-987E-390D55A05FCC}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{31FFE361-8B75-4428-B9C5-AA64307B29FE}" = protocol=6 | dir=in | app=c:\program files\symantec endpoint protection\smc.exe |
"{34D81761-5ED4-469C-A1FA-B8985DFA37FA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{36688D66-8C5E-4669-A653-46FF4D9F43CB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{3E924F19-676E-48C5-9FD6-547EA7A03A07}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{436EC39F-27A1-46B8-9276-B1166DA9D443}" = protocol=17 | dir=in | app=c:\program files\rapidsolution\tunebite\tunebitehelper.exe |
"{458A28F5-3CC0-43AC-932B-DF8344F65B83}" = protocol=6 | dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4FC21042-F0A0-4777-A430-5720F547829E}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{509DC7D0-4536-4186-BC54-04C73D3A80A4}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{57EF4EFD-CE18-488B-92C8-5F370B64E4DF}" = protocol=6 | dir=in | app=c:\program files\adobe\adobe version cue cs2\bin\versioncuecs2.exe |
"{5E66FD85-E4DD-4282-A960-63A599574477}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5EC206B6-D5B5-4BA4-90F2-B45C89E4FDD3}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{6311876C-59EA-456C-A5A7-D4641CB41346}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{6EDC0092-8469-45DA-B270-AC141AF1DF30}" = protocol=6 | dir=in | app=c:\program files\brother\brmfl08b\faxrx.exe |
"{70C37D40-BB13-4C3F-9637-F9C08D8EBAED}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{729CCED0-17CE-4F57-9A0A-4375AB2461A5}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\mathematica.exe |
"{76C3D245-E599-4BA8-BDDD-AD2FE537C456}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{7E8CF99A-931A-44A4-B8F3-AFC66D3245A2}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{84E30C19-8E5E-4C33-96BE-4699BB7B16C6}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\math.exe |
"{87C4F44D-00BC-48EC-B069-4FEB7F8235B7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{91004571-84D0-4D57-A854-78BE5CF0AB5B}" = protocol=17 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\mathkernel.exe |
"{923521E6-FE8F-4AF5-AED2-C38FD971F2E9}" = protocol=17 | dir=in | app=c:\program files\adobe\adobe version cue cs2\bin\versioncuecs2.exe |
"{93E70215-1B48-4555-953A-4F77CCEB8453}" = protocol=17 | dir=in | app=c:\program files\avira\antivir desktop\update.exe |
"{9C7B351E-3DB2-4D06-8889-0100E3920B4C}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{9D6B7519-1520-48FB-AF26-18D4E4DDEB8C}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{9E9B8A56-15CD-44A0-B15E-26FD04F44D9C}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{9FA7CA49-49F5-4051-AEB9-C4D22C33F826}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\math.exe |
"{A1BD4ABD-6F1E-4AC3-85C7-32243678D748}" = protocol=17 | dir=in | app=c:\program files\symantec endpoint protection\snac.exe |
"{AD4DA11F-760C-40FA-A8E9-559D8046EA5F}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{AE9404CA-1DC2-4F45-9CA7-809B3898F9E3}" = protocol=17 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{AEF6B45A-261A-46D8-9182-537EF6FB8D05}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\sony ericsson media manager\mediamanager.exe |
"{B0709BCA-7466-43F0-AF0D-A45B7ABE500B}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\mathematica.exe |
"{B29BAF77-6E00-46FF-80A5-BDEC43909C49}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B3CF36D9-405C-4A85-A083-EAD92E2B16C1}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B90FCEBC-D4ED-4398-866F-5B6C777F706E}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{CA806DDB-EEC1-4DAD-BF7F-E88AEE89419F}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{CB8E5433-1536-41EA-9D39-63612E2C6842}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D8C6961D-D1D0-47A7-ACED-21613656F2F7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D9D007F0-DE45-45F7-B87D-A1A472131B42}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DBE15820-8196-4106-81F3-7393E2EEB2A6}" = protocol=17 | dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{DC8556BE-7202-420F-B169-40E21FAF90A1}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{DDC5D2BF-1470-4EDA-B369-C092FF6E5653}" = protocol=17 | dir=in | app=c:\program files\symantec endpoint protection\smc.exe |
"{E06900F2-9CF0-4933-8C33-E3F1D476A44B}" = protocol=6 | dir=in | app=c:\program files\wolfram research\mathematica\7.0\mathkernel.exe |
"{EA8CD5D3-88D4-46FD-A6F1-C31E4FA19923}" = protocol=6 | dir=in | app=c:\program files\symantec endpoint protection\snac.exe |
"{F128BBA6-C25B-4FB0-8DB2-BFB606581498}" = protocol=6 | dir=in | app=c:\program files\rapidsolution\tunebite\tunebitehelper.exe |
"TCP Query User{0060C9AA-20A0-4100-8D46-3C20459E90BF}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{141369E8-7B7F-455D-8220-628ECF3200BD}C:\users\kirby\documents\share\share.exe" = protocol=6 | dir=in | app=c:\users\kirby\documents\share\share.exe |
"TCP Query User{1AF95D03-93FE-454A-9030-7C93807DDF7E}C:\program files\eclipse\eclipse.exe" = protocol=6 | dir=in | app=c:\program files\eclipse\eclipse.exe |
"TCP Query User{20851050-2906-48D9-B3CE-C2EC7A03D520}C:\program files\autodesk\maya2010\bin\maya.exe" = protocol=6 | dir=in | app=c:\program files\autodesk\maya2010\bin\maya.exe |
"TCP Query User{379DDCDA-5AD3-4752-928F-1CF221BFD377}C:\program files\foobar2000\foobar2000.exe" = protocol=6 | dir=in | app=c:\program files\foobar2000\foobar2000.exe |
"TCP Query User{39D4DE2E-7716-4E9E-9048-138C627B9EEA}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{3A7B9E98-F407-43A2-AA27-7DB6498CA3B3}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe |
"TCP Query User{41480854-71D1-4D9C-AF76-BF75C2EE771D}C:\users\kirby\desktop\eclipse\eclipse.exe" = protocol=6 | dir=in | app=c:\users\kirby\desktop\eclipse\eclipse.exe |
"TCP Query User{65D1FC5F-6319-48B8-BEE0-05C73A04EABB}C:\program files\maple 12\jre\bin\maple.exe" = protocol=6 | dir=in | app=c:\program files\maple 12\jre\bin\maple.exe |
"TCP Query User{70EA218E-653D-4BAB-9EA2-0A50B6007573}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{736799E7-4E3F-42CC-B22F-5FD464E21783}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{76D9AC61-A9DC-4008-AE90-6CC9A050A1AC}C:\program files\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlife\slvoice.exe |
"TCP Query User{7D0C75DF-4D47-4F90-A640-58C5226FC3F5}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{814568DA-3714-4EBD-BDDC-6A6C84D2F6AC}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe |
"TCP Query User{82705FC1-14FB-4C05-B87A-7BCF6A7B85ED}C:\program files\anki\anki.exe" = protocol=6 | dir=in | app=c:\program files\anki\anki.exe |
"TCP Query User{8BD1AEB9-3317-4487-8E49-FF483EC0EE94}C:\users\kirby\documents\programs\utorrent.exe" = protocol=6 | dir=in | app=c:\users\kirby\documents\programs\utorrent.exe |
"TCP Query User{961543CF-6E66-40D5-9F4D-307D679CFFAF}C:\sonyericsson\javame_sdk_cldc\ondevicedebug\bin\serialproxy.exe" = protocol=6 | dir=in | app=c:\sonyericsson\javame_sdk_cldc\ondevicedebug\bin\serialproxy.exe |
"TCP Query User{9AF383E6-1FF8-441D-B3EC-CF5E75C882D6}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{A69CBABF-EBED-432A-B3A4-FED0429AD9C0}C:\users\kirby\appdata\local\temp\rar$ex00.259\eclipse\eclipsec.exe" = protocol=6 | dir=in | app=c:\users\kirby\appdata\local\temp\rar$ex00.259\eclipse\eclipsec.exe |
"TCP Query User{A74BC4EA-8281-45FF-834F-F08D06578970}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{BA2753D7-9228-4C64-9154-7123313D235A}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{D50C38A0-BDAC-4168-8053-250D63553E18}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{D7678770-A625-4293-84E4-5E2AAA052F10}C:\users\kirby\documents\share\share.exe" = protocol=6 | dir=in | app=c:\users\kirby\documents\share\share.exe |
"TCP Query User{D886631D-6576-43B7-86CF-70DEC62F9E64}C:\users\kirby\desktop\eclipse\eclipse.exe" = protocol=6 | dir=in | app=c:\users\kirby\desktop\eclipse\eclipse.exe |
"TCP Query User{DEEB395F-ABA3-4469-83EA-C7B8B76525E4}C:\program files\ruckus player\ruckus.exe" = protocol=6 | dir=in | app=c:\program files\ruckus player\ruckus.exe |
"TCP Query User{FC30C3E7-F0A3-4AB1-BFE9-DDAA7C28D8E8}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{FE69EFCC-34E0-431C-9F31-D4FD98792306}C:\program files\foobar2000\foobar2000.exe" = protocol=6 | dir=in | app=c:\program files\foobar2000\foobar2000.exe |
"UDP Query User{0A57BC42-DEC6-481B-8B29-95FE99F04C6C}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{11FAB4B2-4455-4D14-B239-FC81AD8BD97B}C:\users\kirby\documents\programs\utorrent.exe" = protocol=17 | dir=in | app=c:\users\kirby\documents\programs\utorrent.exe |
"UDP Query User{1BAE3EB9-1D8B-4B43-9526-8523693C3D22}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{1F361ED2-4B4A-4BE5-994A-327DF128ABD0}C:\program files\foobar2000\foobar2000.exe" = protocol=17 | dir=in | app=c:\program files\foobar2000\foobar2000.exe |
"UDP Query User{2E032213-D608-4784-853C-E842A9FF4281}C:\users\kirby\desktop\eclipse\eclipse.exe" = protocol=17 | dir=in | app=c:\users\kirby\desktop\eclipse\eclipse.exe |
"UDP Query User{2FD69024-77FF-489D-8414-281BA2A50D8B}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{38BFBFE9-0105-402D-AFFC-BDF95AC54C6A}C:\program files\ruckus player\ruckus.exe" = protocol=17 | dir=in | app=c:\program files\ruckus player\ruckus.exe |
"UDP Query User{3F831184-CC2A-4B9D-9E75-9F589302088C}C:\program files\autodesk\maya2010\bin\maya.exe" = protocol=17 | dir=in | app=c:\program files\autodesk\maya2010\bin\maya.exe |
"UDP Query User{491F733E-8ECE-43CC-85D9-5D0BECD4C035}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{563B7490-16CA-404B-851C-E2F3FF882756}C:\program files\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlife\slvoice.exe |
"UDP Query User{58668B9C-C678-4942-852E-E7A63AB36656}C:\users\kirby\documents\share\share.exe" = protocol=17 | dir=in | app=c:\users\kirby\documents\share\share.exe |
"UDP Query User{6308FF15-1B37-44C8-AEFA-8A1DE6BE94B2}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{6457C816-1D67-4485-A143-F8F010EC5E40}C:\users\kirby\appdata\local\temp\rar$ex00.259\eclipse\eclipsec.exe" = protocol=17 | dir=in | app=c:\users\kirby\appdata\local\temp\rar$ex00.259\eclipse\eclipsec.exe |
"UDP Query User{6CF2C783-B574-4894-8DF4-2C8A648372B9}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{6EEA9D25-2B1F-4976-A93E-A9CFE2C2E1E4}C:\users\kirby\documents\share\share.exe" = protocol=17 | dir=in | app=c:\users\kirby\documents\share\share.exe |
"UDP Query User{71F358C1-E2CE-43C5-A1F4-FDE1A9FC9D1E}C:\users\kirby\desktop\eclipse\eclipse.exe" = protocol=17 | dir=in | app=c:\users\kirby\desktop\eclipse\eclipse.exe |
"UDP Query User{7293F550-07A9-4E17-8A39-3AAA92614672}C:\program files\eclipse\eclipse.exe" = protocol=17 | dir=in | app=c:\program files\eclipse\eclipse.exe |
"UDP Query User{92F2299B-017C-488C-8860-79063298BEDA}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{A326E1DF-2696-4028-BC6A-AF7E1900C407}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{A4BC26F0-64B1-4011-9991-1FF3E25020FC}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe |
"UDP Query User{B5AADD97-BFEA-41B9-8D2D-88C78B9E6730}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{CA8EB681-E095-4BBF-92A3-B8E528702EF0}C:\program files\anki\anki.exe" = protocol=17 | dir=in | app=c:\program files\anki\anki.exe |
"UDP Query User{D2FE10A8-41DC-4238-BF0A-57318B78765E}C:\sonyericsson\javame_sdk_cldc\ondevicedebug\bin\serialproxy.exe" = protocol=17 | dir=in | app=c:\sonyericsson\javame_sdk_cldc\ondevicedebug\bin\serialproxy.exe |
"UDP Query User{F6A6061B-5D25-4A25-8809-3CF218CC6275}C:\program files\maple 12\jre\bin\maple.exe" = protocol=17 | dir=in | app=c:\program files\maple 12\jre\bin\maple.exe |
"UDP Query User{FC0C1EDF-8681-4F5D-9A76-8557C96828FD}C:\program files\java\jre1.6.0_07\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.6.0_07\bin\javaw.exe |
"UDP Query User{FE303247-B0D2-427D-AF39-C9483CE3BB07}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{FEE87AD7-95D0-4F2E-A426-193DA9A8A466}C:\program files\foobar2000\foobar2000.exe" = protocol=17 | dir=in | app=c:\program files\foobar2000\foobar2000.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{0134A1A1-C283-4A47-91A1-92F19F960372}" = Adobe Creative Suite 2
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{07FB1A47-5D14-47A2-BC3C-A3481ABBB957}" = EWB Shared Components
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0B0BEF37-B327-48ED-A2E0-BF6974676294}" = NI Logos 4.6
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0D025345-1033-4F35-A5CE-68CDCDE6CC03}" = Evernote
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{110EB5C4-E995-4CFB-AB80-A5F315BEA9E8}" = Python 2.6
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1BD1BBE0-95F7-4273-ABDE-2077EC84E35B}" = SPOT xde® Player DLL
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{255D87CE-1E45-4795-9731-454EF5371B02}" = NI USI 1.2.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28C59BDD-55F3-4454-BF17-37AC537F894B}" = NI MDF Support
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A856E11-228D-459F-A196-6F4F7E104FFC}" = ZBrush 3.5 R3
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 3.209.00
"{310AFA6B-094D-45DA-8389-4712074B6A22}" = Maya 2010
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0150000}" = J2SE Development Kit 5.0
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java™ SE Development Kit 6 Update 7
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{378E6AB4-C604-4D67-83D5-E973F0DE7EC9}" = ExpressPCB
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3BA37E38-B53D-4520-B8DA-1DD62AD3A74E}" = Microsoft XNA Game Studio 3.1 (VCSExpress)
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.6
"{46548E80-0409-0000-7E8A-45000F855001}" = Adobe GoLive CS2
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{56DF5C9E-6392-46D3-B366-297B14E1DAAF}" = Bonjour Core for Windows
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5DC6B387-DCD5-4B66-B866-434020FF2ECC}" = TortoiseSVN 1.6.7.18415 (32 bit)
"{60FC2242-9CF5-4264-B02A-A4A86447F560}" = NI EULA Depot
"{621FCD24-4498-4324-A81E-07D331376EDF}" = PixiePack Codec Pack
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{679EC478-3FF9-4987-B2FF-C2C2B27532A2}" = DocProc
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B407945-AE16-4A2A-BAAF-497FE62EDED3}" = PS_AIO_03_C4400_Software_Min
"{6B437F94-056F-4791-AF2C-0D10E2706AF0}" = PanoStandAlone
"{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7A8FF745-BBC5-482B-88E4-18D3178249A9}" = ScanSoft PaperPort 11
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
"{7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8F014E72-8456-431B-A985-EBBBFEAE85ED}" = Game Creators Dark GDK
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{954B7F64-D1D4-476F-8919-99585D0A6ABF}" = PS_AIO_03_C4400_Software
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.2
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9E0AE153-88DC-428B-99EB-6A3D984230B8}" = NI LabWindows/CVI 7.1.1 Run Time Engine
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A4418082-E601-3954-805B-D56A2B50EC8B}" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A5D1EA23-CEE5-4B72-A0C3-8BCEDFC6F94C}" = NI LabVIEW Run-Time Engine 8.0
"{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADBE46EE-54E0-4610-B436-D7E93D829100}" = Adobe Version Cue CS2
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}" = Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B1F27A23-B6D1-4397-BA2F-25F348DF135F}" = NI Uninstaller
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{BED4CEEC-863F-4AB3-BA23-541764E2D2CE}" = Microsoft XNA Game Studio Platform Tools
"{C0750A0D-35F4-47FF-B8E1-730F3938D0D5}" = Toon Boom Animate
"{C260343B-6282-42A2-939F-1FF7E503F608}" = Wolfram Notebook Indexer 2.0
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C49DAA9C-5BA8-459A-8244-E57B69DF0F04}" = Suite Specific
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C73A0FC7-FFDC-4BAD-912A-C5791FF9EAC6}" = NI Service Locator
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{C9CE9393-B568-428D-AD5B-55452B9748DB}" = PS_AIO_03_C4400_ProductContext
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 Tools
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D5844C35-2870-4BFB-8128-BC14A4F73FF8}" = AnkhSVN 2.1.7819.411
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{D7358B07-4F10-4014-9869-7999578BE8ED}" = HP User Guides 0093
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{D9461574-5FC0-4641-BBDC-D1038B196F55}" = Brother MFL-Pro Suite MFC-790CW
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}" = NI Math Kernel Libraries
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DF81B441-BBE3-4A1E-AB7A-A430F806E682}" = Tunebite
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5FCED12-3E77-4C0E-A305-5AEB38A52A70}" = AdobeColorCommonSetCMYK
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
"{EBBE2FB2-FBED-44F6-B95F-230AB5A65B28}" = Goombah Partner COM Server
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{EE217F71-2546-4E9C-825F-DBBCAA9E9777}" = Sony Ericsson Media Manager 1.1
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7646923-2B1C-493E-A38E-D4AD6408E854}" = DJ Java Decompiler v.[removed]
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF1F4E8E-A833-4c4b-A14A-45D5B841B5D8}" = HP Photosmart C4400 All-In-One Driver Software 10.0 Rel .3
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFC1ADE3-944B-4231-894E-3903C37271D2}" = Adobe Setup
"7-Zip" = 7-Zip 4.65
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
"Adobe_c3c7fe8b09d497ab2b3fd91c9353390" = Adobe Flash CS3 Professional
"AIM Toolbar" = AIM Toolbar 5.0
"AIM_6" = AIM 6
"Anki" = Anki
"AsUninst.exe" = Anvil Studio
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AviSynth" = AviSynth 2.5
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner (remove only)
"CDisplay_is1" = CDisplay 1.8
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Emma" = Emma
"eMule" = eMule
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPIVALLEY Data Modem" = EPIVALLEY Data Modem Software
"Fanfiction Downloader_is1" = Fanfiction Downloader v4.0.5
"foobar2000" = foobar2000 v1.0.3
"Game Maker 7.0" = Game Maker 7.0
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{2A856E11-228D-459F-A196-6F4F7E104FFC}" = ZBrush 3.5 R3
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"iZAP@Star" = iZAP@Star 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MatlabR2007b" = MATLAB R2007b
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual C# 2008 Express Edition with SP1 - ENU" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"mIRC" = mIRC
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"M-WIN-L 7.0.0 1148351_is1" = Wolfram Mathematica 7 (M-WIN-L 7.0.0 1148351)
"nbi-nb-base-[removed].200811100001" = NetBeans IDE 6.5
"NI Uninstaller" = National Instruments Software
"Notepad++" = Notepad++
"PE Builder_is1" = PE Builder 3.1.10a
"Pen Tablet Driver" = Pen Tablet
"PowerISO" = PowerISO
"Qt OpenSource 4.6.1 - C:_Qt_4.6.1" = Qt OpenSource 4.6.1
"Qt4 Visual Studio Add-in 1.1.3 - C:_Program Files_Nokia_Qt4VSAddin" = Qt4 Visual Studio Add-in 1.1.3
"Ruckus Player" = Ruckus Player
"SDK for the Java™ ME Platform" = Sony Ericsson SDK 2.2.4 for the Java™ ME Platform
"SecureW2 EAP Suite" = SecureW2 EAP Suite 1.0.6 for Windows
"SecureW2 Enterprise Client" = SecureW2 Enterprise Client 3.4.5
"Shop for HP Supplies" = Shop for HP Supplies
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"SpaceMonger" = SpaceMonger 2.1.1
"SurfOffline Professional 2" = SurfOffline Professional 2
"The KMPlayer" = The KMPlayer (remove only)
"TVWiz" = Intel® TV Wizard
"UnityWebPlayer" = Unity Web Player
"Videora iPod touch Converter" = Videora iPod touch Converter 5.04
"ViewpointMediaPlayer" = Viewpoint Media Player
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"Wacom Tablet Driver" = Wacom Tablet
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR" = WinRAR
"WordPerfect Office 2002" = WordPerfect Office 2002
"WordWeb" = WordWeb
"XMind" = XMind
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YouTube Downloader App" = YouTube Downloader App 2.03

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EasyToon 1.9.7 EN" = EasyToon 1.9.7 EN
"Google Chrome" = Google Chrome
"Tile-based game" = Tile-based game
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/18/2009 11:06:18 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711731
Description =

Error - 2/18/2009 11:06:20 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711726
Description =

Error - 2/18/2009 11:06:26 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711731
Description =

Error - 2/18/2009 11:06:29 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711726
Description =

Error - 2/18/2009 11:06:34 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711731
Description =

Error - 2/18/2009 11:06:36 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711726
Description =

Error - 2/18/2009 11:06:42 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711731
Description =

Error - 2/18/2009 11:06:44 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711726
Description =

Error - 2/18/2009 11:06:49 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711685
Description =

Error - 2/18/2009 11:06:49 AM | Computer Name = Kirby-PC | Source = Symantec AntiVirus | ID = 16711731
Description =

[ OSession Events ]
Error - 10/16/2008 8:48:45 AM | Computer Name = Kirby-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 19647
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/21/2009 3:56:20 AM | Computer Name = Kirby-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 187699
seconds with 4980 seconds of active time. This session ended with a crash.

Error - 6/6/2010 12:05:01 AM | Computer Name = Kirby-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 187562
seconds with 20520 seconds of active time. This session ended with a crash.

Error - 6/14/2010 2:58:21 PM | Computer Name = Kirby-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 425603
seconds with 35220 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2/16/2009 12:06:11 PM | Computer Name = Kirby-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:04:13 AM on 2/16/2009 was unexpected.

Error - 2/16/2009 12:07:07 PM | Computer Name = Kirby-PC | Source = HTTP | ID = 15016
Description =

Error - 2/16/2009 12:09:29 PM | Computer Name = Kirby-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 2/16/2009 1:56:05 PM | Computer Name = Kirby-PC | Source = DCOM | ID = 10010
Description =

Error - 2/16/2009 1:56:05 PM | Computer Name = Kirby-PC | Source = DCOM | ID = 10010
Description =

Error - 2/16/2009 1:59:40 PM | Computer Name = Kirby-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:56:05 PM on 2/16/2009 was unexpected.

Error - 2/16/2009 1:59:59 PM | Computer Name = Kirby-PC | Source = HTTP | ID = 15016
Description =

Error - 2/16/2009 2:02:06 PM | Computer Name = Kirby-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 2/17/2009 7:29:57 PM | Computer Name = Kirby-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 2/18/2009 10:42:05 AM | Computer Name = Kirby-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed]
on the Network Card with network address 001FE16C8B98.


< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hey, thanks for helping me out! My computer is behaving normally. Windows Defender blocked MBAM on startup, though, but it allowed me to activate it afterward. Windows Defender also claimed that AntiVir Desktop is offline, too, when it's supposed to start up automatically. When I tried to turn it on from the Windows Defender main window, it asked me to activate C:\Program Files\Avira\AntiVir Desktop\wsctool.exe. However, the main program (Avira Antivirus Personal) seemed to be up and running on my taskbar, and said that the AntiVir Guard was running fine. After a while, without me activating wsctool.exe, Windows Defender finally reported that AntiVir Desktop had turned on. This might just be the program lagging in startup, though? It's happened once or twice before, even before I got that whole influx of trojans. I followed the instructions, and here's the MBAM log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4544 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 9/4/2010 2:02:34 PM mbam-log-2010-09-04 (14-02-34).txt Scan type: Quick scan Objects scanned: 147215 Time elapsed: 17 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 24 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\DigiFast (Trojan.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> No action taken. HKEY_CURRENT_USER\Software\WinServers (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ahcopces (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ahloyduv (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bhbnoxgi (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cgolcmul (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\com+ manager (Trojan.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dgglslei (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kqsbokuq (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\popaomhk (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tjwindon (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uieutkuo (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ujnudmlr (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vdhhuqdx (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vicgrqln (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vikfyoeg (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vilgbscq (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wibfpmnd (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wirfglxa (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xhgdtald (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xixemdsk (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xiyrnsec (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yhecsvnt (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yheprgcc (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yhfptlal (Trojan.FakeAlert.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yhvpkjji (Trojan.FakeAlert.Gen) -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Users\Kirby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ntuser_mssec.exe (Trojan.VirTool) -> No action taken. C:\Users\Kirby\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> No action taken. C:\Windows\Temp\TMP00000001D9D95BEFF21F39FA (Trojan.Dropper) -> No action taken.
Sweet. I think it's been cleared up? :) Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4544 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 9/5/2010 12:58:52 AM mbam-log-2010-09-05 (00-58-52).txt Scan type: Quick scan Objects scanned: 147823 Time elapsed: 14 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI