Hi,
Thanks for replying and taking the time to help me with my problem. I ran gmer but mid-way through the scan it went to the blue screen of death, I tried it again and the same thing happened. I have included here the two OTL logs.
OTL logfile created on: 11/10/2010 17:50:54 - Run 1
OTL by OldTimer - Version 3.2.15.0 Folder = C:\Users\Andrew\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 450.70 Gb Total Space | 170.31 Gb Free Space | 37.79% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.22 Gb Free Space | 54.83% Space Free | Partition Type: NTFS
Computer Name: ANDREW-PC | User Name: Andrew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Andrew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
PRC - C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\Andrew\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\System32\pmxscrll.dll (Primax Electronics Ltd.)
MOD - C:\Windows\System32\pmxcomm.dll (Primax Electronics Ltd.)
MOD - C:\Windows\System32\pmxhooks.dll (Primax Electronics Ltd.)
========== Win32 Services (SafeList) ==========
SRV - (SessionLauncher) – C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe File not found
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MOBKbackup) – C:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (MSSQLServerADHelper100) – c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)
SRV - (SMServer) – C:\Windows\System32\snmvtsvc.exe (SMServer)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (RoxLiveShare10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (Sonic Solutions)
SRV - (RoxWatch10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe (Sonic Solutions)
SRV - (RoxMediaDB10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (STacSV) – C:\Windows\System32\stacsv.exe (SigmaTel, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (amdkmdap) – C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (AtiHDAudioService) – C:\Windows\System32\drivers\AtihdLH3.sys (ATI Technologies, Inc.)
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – C:\Windows\System32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (vmm) – C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (DrmRAudio) – C:\Windows\System32\drivers\DrmRAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (RsFx0103) – C:\Windows\System32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (VPCNetS2) – C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (btwrchid) – C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (btwavdt) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://uk.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 174.142.104.57:3128
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/10/01 19:28:11 | 000,000,000 | —D | M]
[2010/10/09 22:39:16 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Mozilla\Extensions
[2010/10/09 22:39:16 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Mozilla\Extensions\[removed]
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - Reg Error: Value error. File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATICustomerCare] c:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Bluetooth HCI Monitor] C:\Windows\System32\HCIMNTR.DLL (Logitech Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Andrew\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\DrmRemoval\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\DrmRemoval\YouTubeRipper.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.virginmedia.com/CST/ver1/vistainstaller.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Andrew\Pictures\sarah_connor_chronicles16.jpg
O24 - Desktop BackupWallPaper: C:\Users\Andrew\Pictures\sarah_connor_chronicles16.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{2708447a-d3ec-11df-9bf9-001e4ce63776}\Shell\AutoRun\command - "" = K:\InstallTomTomHOME.exe – File not found
O33 - MountPoints2\{3bc19a55-180d-11dd-be1f-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{3bc19a55-180d-11dd-be1f-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AUTORUN.EXE – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/10/11 17:48:42 | 000,576,512 | —- | C] (OldTimer Tools) – C:\Users\Andrew\Desktop\OTL.exe
[2010/10/11 17:30:56 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\gmer
[2010/10/11 07:30:17 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\Apple Computer
[2010/10/10 20:55:56 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\tdsskiller
[2010/10/10 20:49:49 | 000,000,000 | —D | C] – C:\Users\Andrew\Desktop\GooredFix Backups
[2010/10/10 20:49:22 | 000,071,398 | —- | C] (jpshortstuff) – C:\Users\Andrew\Desktop\GooredFix.exe
[2010/10/10 20:48:37 | 000,071,398 | —- | C] (jpshortstuff) – C:\Users\Andrew\Documents\GooredFix.exe
[2010/10/10 20:46:15 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Andrew\Documents\ATF_Cleaner.exe
[2010/10/10 18:27:55 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\Temporary Projects
[2010/10/10 14:06:41 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Andrew\Documents\HiJackThis.exe
[2010/10/10 13:49:35 | 000,000,000 | —D | C] – C:\Users\Andrew\Documents\SysinternalsSuite
[2010/10/09 22:39:34 | 000,000,000 | —D | C] – C:\Users\Andrew\Documents\TomTom
[2010/10/09 22:39:31 | 000,000,000 | —D | C] – C:\ProgramData\TomTom
[2010/10/09 22:39:14 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\TomTom
[2010/10/09 22:39:14 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\TomTom
[2010/10/09 22:39:14 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\Mozilla
[2010/10/09 22:39:10 | 000,000,000 | —D | C] – C:\Program Files\TomTom International B.V
[2010/10/09 22:38:55 | 000,000,000 | —D | C] – C:\Program Files\TomTom HOME 2
[2010/10/09 22:38:17 | 000,000,000 | —D | C] – C:\Program Files\TomTom DesktopSuite
[2010/10/09 16:39:16 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\SUPERAntiSpyware.com
[2010/10/09 16:39:16 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/10/09 16:39:12 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/10/09 16:15:42 | 000,000,000 | —D | C] – C:\ProgramData\FrontLine Registry Cleaner
[2010/10/09 16:15:37 | 000,000,000 | —D | C] – C:\Program Files\Frontline Registry Cleaner
[2010/10/08 21:02:24 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\McAfee
[2010/10/08 17:21:01 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\{F163ECC0-AAAA-4527-B25D-5B2E8950D067}
[2010/10/08 17:19:01 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\Server
[2010/10/02 17:21:15 | 000,043,520 | —- | C] (ATI Technologies, Inc.) – C:\Windows\System32\ati2edxx.dll
[2010/10/02 17:21:12 | 000,380,928 | —- | C] (AMD) – C:\Windows\System32\atieclxx.exe
[2010/10/02 17:21:09 | 000,278,528 | —- | C] (ATI Technologies, Inc.) – C:\Windows\System32\Oemdspif.dll
[2010/10/02 17:21:09 | 000,241,664 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atiadlxx.dll
[2010/10/02 17:21:04 | 000,012,800 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiglpxx.dll
[2010/10/02 17:21:02 | 015,830,016 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atioglxx.dll
[2010/10/02 17:20:54 | 000,053,248 | —- | C] (ATI Technologies Inc.) – C:\Windows\System32\drivers\ati2erec.dll
[2010/10/02 17:20:54 | 000,019,968 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atigktxx.dll
[2010/10/02 17:20:52 | 000,052,736 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atimpc32.dll
[2010/10/02 17:20:52 | 000,052,736 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\amdpcom32.dll
[2010/10/02 17:20:52 | 000,011,776 | —- | C] (AMD) – C:\Windows\System32\atimuixx.dll
[2010/10/02 17:20:49 | 003,914,240 | —- | C] (ATI Technologies Inc. ) – C:\Windows\System32\atidxx32.dll
[2010/10/02 17:20:43 | 004,375,552 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticaldd.dll
[2010/10/02 17:20:43 | 000,221,696 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\System32\drivers\atikmpag.sys
[2010/10/02 17:20:39 | 000,356,352 | —- | C] (ATI Technologies, Inc.) – C:\Windows\System32\atipdlxx.dll
[2010/10/02 17:20:26 | 000,030,208 | —- | C] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiuxpag.dll
[2010/10/02 17:20:25 | 000,176,128 | —- | C] (AMD) – C:\Windows\System32\atiesrxx.exe
[2010/10/02 17:20:24 | 000,159,744 | —- | C] (AMD) – C:\Windows\System32\atitmmxx.dll
[2010/10/02 17:20:24 | 000,143,360 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atiapfxx.exe
[2010/10/02 17:20:24 | 000,044,032 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticalcl.dll
[2010/10/02 17:20:19 | 000,099,344 | —- | C] (ATI Technologies, Inc.) – C:\Windows\System32\drivers\AtihdLH3.sys
[2010/10/02 17:20:14 | 000,046,080 | —- | C] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticalrt.dll
[2010/10/02 17:20:10 | 000,450,560 | —- | C] (Advanced Micro Devices, Inc.) – C:\Windows\System32\ATIDEMGX.dll
[2010/10/02 17:20:09 | 006,380,032 | —- | C] (ATI Technologies Inc.) – C:\Windows\System32\drivers\atikmdag.sys
[2010/10/01 17:57:11 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\Microsoft Corporation
[2010/09/29 07:33:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/28 18:38:27 | 000,050,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
[2010/09/28 18:38:13 | 000,079,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
[2010/09/28 18:37:12 | 000,000,000 | —D | C] – C:\Windows\System32\RsFx
[2010/09/28 18:36:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 9.0
[2010/09/28 18:36:04 | 000,000,000 | —D | C] – C:\Windows\System32\1033
[2010/09/28 18:32:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server
[2010/09/28 18:32:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2010/09/28 18:32:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2010/09/28 18:32:11 | 000,000,000 | —D | C] – C:\Users\Andrew\Documents\Visual Studio 2010
[2010/09/28 18:30:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Help Viewer
[2010/09/28 18:30:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 10.0
[2010/09/28 18:30:42 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SDKs
[2010/09/28 18:13:03 | 003,252,048 | —- | C] (Microsoft Corporation) – C:\Users\Andrew\Documents\vcs_web.exe
[2010/09/26 18:30:54 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/09/26 18:28:23 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/09/24 18:31:18 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/09/22 07:58:54 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\dvdcss
[2010/09/20 18:45:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Press Training Kit Exam Prep
[2010/09/19 18:04:31 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/09/19 10:45:18 | 000,000,000 | —D | C] – C:\Program Files\YouTube Downloader
[2010/09/18 22:17:32 | 000,000,000 | —D | C] – C:\YouTubeDownload
[2010/09/18 22:09:31 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/09/18 22:03:13 | 000,000,000 | —D | C] – C:\Users\Andrew\Documents\Cucusoft
[2010/09/18 22:03:02 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\Cucusoft
[2010/09/18 20:57:45 | 009,575,606 | —- | C] (Cucusoft, Inc. ) – C:\Users\Andrew\Documents\ipodconv.exe
[2010/09/15 09:53:35 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2010/09/14 20:49:24 | 000,000,000 | —D | C] – C:\Users\Andrew\AppData\Local\Dell
[2009/06/07 21:19:02 | 000,106,496 | —- | C] ( ) – C:\Windows\System32\VM_1.dll
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/11 17:51:53 | 004,456,448 | -HS- | M] () – C:\Users\Andrew\ntuser.dat
[2010/10/11 17:48:47 | 000,576,512 | —- | M] (OldTimer Tools) – C:\Users\Andrew\Desktop\OTL.exe
[2010/10/11 17:44:13 | 000,001,737 | —- | M] () – C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2010/10/11 17:42:26 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/11 17:42:26 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/11 17:42:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/10/11 17:42:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/11 17:42:11 | 3485,425,664 | -HS- | M] () – C:\hiberfil.sys
[2010/10/11 17:42:09 | 248,385,300 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/10/11 17:29:53 | 000,284,915 | —- | M] () – C:\Users\Andrew\Desktop\gmer.zip
[2010/10/11 17:24:15 | 000,002,568 | —- | M] () – C:\Windows\MOBK.blk
[2010/10/11 17:24:15 | 000,000,762 | —- | M] () – C:\Windows\MOBK.flt
[2010/10/11 07:45:55 | 000,524,288 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TMContainer00000000000000000001.regtrans-ms
[2010/10/11 07:45:55 | 000,065,536 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TM.blf
[2010/10/11 07:45:52 | 003,497,820 | -H– | M] () – C:\Users\Andrew\AppData\Local\IconCache.db
[2010/10/11 07:30:09 | 000,002,231 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/10/10 20:52:18 | 001,211,285 | —- | M] () – C:\Users\Andrew\Desktop\tdsskiller.zip
[2010/10/10 20:49:22 | 000,071,398 | —- | M] (jpshortstuff) – C:\Users\Andrew\Desktop\GooredFix.exe
[2010/10/10 20:48:37 | 000,071,398 | —- | M] (jpshortstuff) – C:\Users\Andrew\Documents\GooredFix.exe
[2010/10/10 20:46:15 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Andrew\Documents\ATF_Cleaner.exe
[2010/10/10 19:56:07 | 000,000,799 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/10/10 14:06:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Andrew\Documents\HiJackThis.exe
[2010/10/10 13:48:26 | 013,072,572 | —- | M] () – C:\Users\Andrew\Documents\SysinternalsSuite.zip
[2010/10/10 13:16:58 | 000,131,066 | —- | M] () – C:\Windows\System32\DellPM.ini
[2010/10/10 12:38:47 | 000,327,576 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/09 22:39:56 | 000,720,830 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/10/09 22:39:55 | 000,860,342 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/10/09 22:39:55 | 000,152,278 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/10/09 19:59:17 | 000,017,920 | —- | M] () – C:\Users\Andrew\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 19:38:22 | 000,014,777 | —- | M] () – C:\Users\Andrew\Documents\Battlestar Galactica The Plan 2009
[2010/10/09 18:52:38 | 003,046,400 | —- | M] () – C:\Users\Andrew\Documents\mvt_en-gb.msi
[2010/10/09 17:32:59 | 000,524,288 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TMContainer00000000000000000002.regtrans-ms
[2010/10/09 17:13:09 | 000,524,288 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TMContainer00000000000000000001.regtrans-ms
[2010/10/09 17:13:09 | 000,065,536 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TM.blf
[2010/10/09 02:02:06 | 000,524,288 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TMContainer00000000000000000002.regtrans-ms
[2010/10/08 20:36:45 | 000,524,288 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{42f052a4-bcfa-11df-88f5-001e4ce63776}.TMContainer00000000000000000001.regtrans-ms
[2010/10/08 20:36:45 | 000,065,536 | -HS- | M] () – C:\Users\Andrew\ntuser.dat{42f052a4-bcfa-11df-88f5-001e4ce63776}.TM.blf
[2010/10/08 17:21:02 | 000,000,120 | —- | M] () – C:\Users\Andrew\AppData\Local\Bhiveqodadujodiv.dat
[2010/10/08 17:21:02 | 000,000,000 | —- | M] () – C:\Users\Andrew\AppData\Local\Sqosefixipugofor.bin
[2010/10/04 21:06:35 | 001,722,772 | —- | M] () – C:\Users\Andrew\Documents\MCPDigitalCertPDF.zip
[2010/10/03 14:04:55 | 000,000,921 | —- | M] () – C:\Users\Public\Desktop\YouTube Downloader.lnk
[2010/10/03 14:04:09 | 004,295,761 | —- | M] () – C:\Users\Andrew\Documents\YouTubeDownloaderSetup262.exe
[2010/10/02 17:21:24 | 015,830,016 | —- | M] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atioglxx.dll
[2010/10/02 17:21:18 | 000,043,520 | —- | M] (ATI Technologies, Inc.) – C:\Windows\System32\ati2edxx.dll
[2010/10/02 17:21:15 | 000,380,928 | —- | M] (AMD) – C:\Windows\System32\atieclxx.exe
[2010/10/02 17:21:12 | 000,278,528 | —- | M] (ATI Technologies, Inc.) – C:\Windows\System32\Oemdspif.dll
[2010/10/02 17:21:12 | 000,241,664 | —- | M] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atiadlxx.dll
[2010/10/02 17:21:09 | 000,583,888 | —- | M] () – C:\Windows\System32\atiumdva.cap
[2010/10/02 17:21:08 | 000,012,800 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiglpxx.dll
[2010/10/02 17:21:02 | 000,021,866 | —- | M] () – C:\Windows\atiogl.xml
[2010/10/02 17:21:01 | 004,032,512 | —- | M] (ATI Technologies Inc. ) – C:\Windows\System32\atiumdag.dll
[2010/10/02 17:20:59 | 003,392,000 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiumdva.dll
[2010/10/02 17:20:57 | 000,065,536 | —- | M] (AMD) – C:\Windows\System32\coinst.dll
[2010/10/02 17:20:54 | 003,914,240 | —- | M] (ATI Technologies Inc. ) – C:\Windows\System32\atidxx32.dll
[2010/10/02 17:20:54 | 000,053,248 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\drivers\ati2erec.dll
[2010/10/02 17:20:54 | 000,019,968 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atigktxx.dll
[2010/10/02 17:20:53 | 000,052,736 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atimpc32.dll
[2010/10/02 17:20:53 | 000,052,736 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\amdpcom32.dll
[2010/10/02 17:20:52 | 000,011,776 | —- | M] (AMD) – C:\Windows\System32\atimuixx.dll
[2010/10/02 17:20:50 | 004,375,552 | —- | M] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticaldd.dll
[2010/10/02 17:20:45 | 000,528,384 | —- | M] (ATI Technologies Inc. ) – C:\Windows\System32\aticfx32.dll
[2010/10/02 17:20:44 | 000,221,696 | —- | M] (Advanced Micro Devices, Inc.) – C:\Windows\System32\drivers\atikmpag.sys
[2010/10/02 17:20:40 | 000,356,352 | —- | M] (ATI Technologies, Inc.) – C:\Windows\System32\atipdlxx.dll
[2010/10/02 17:20:26 | 000,044,032 | —- | M] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticalcl.dll
[2010/10/02 17:20:26 | 000,030,208 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiuxpag.dll
[2010/10/02 17:20:26 | 000,028,160 | —- | M] (Advanced Micro Devices, Inc. ) – C:\Windows\System32\atiu9pag.dll
[2010/10/02 17:20:25 | 000,176,128 | —- | M] (AMD) – C:\Windows\System32\atiesrxx.exe
[2010/10/02 17:20:25 | 000,143,360 | —- | M] (Advanced Micro Devices, Inc.) – C:\Windows\System32\atiapfxx.exe
[2010/10/02 17:20:25 | 000,076,216 | —- | M] () – C:\Windows\System32\atiapfxx.blb
[2010/10/02 17:20:24 | 006,380,032 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\drivers\atikmdag.sys
[2010/10/02 17:20:24 | 000,159,744 | —- | M] (AMD) – C:\Windows\System32\atitmmxx.dll
[2010/10/02 17:20:19 | 000,099,344 | —- | M] (ATI Technologies, Inc.) – C:\Windows\System32\drivers\AtihdLH3.sys
[2010/10/02 17:20:16 | 000,046,080 | —- | M] (Advanced Micro Devices Inc.) – C:\Windows\System32\aticalrt.dll
[2010/10/02 17:20:11 | 000,450,560 | —- | M] (Advanced Micro Devices, Inc.) – C:\Windows\System32\ATIDEMGX.dll
[2010/10/02 17:20:10 | 000,023,040 | —- | M] () – C:\Windows\System32\atitmpxx.dll
[2010/09/28 18:13:04 | 003,252,048 | —- | M] (Microsoft Corporation) – C:\Users\Andrew\Documents\vcs_web.exe
[2010/09/26 09:43:12 | 000,001,523 | —- | M] () – C:\Users\Public\Desktop\Half-Life 2.lnk
[2010/09/24 19:03:38 | 1693,896,703 | —- | M] () – C:\Users\Andrew\Documents\IE8 on XP SP3.vhd
[2010/09/23 18:31:45 | 000,016,695 | —- | M] () – C:\Users\Andrew\Documents\alivetorrents_com The Curious Case of Benjamin Button
[2010/09/22 08:03:30 | 000,033,827 | —- | M] () – C:\Users\Andrew\Documents\Microsoft Visual Studio 2008
[2010/09/20 20:01:42 | 000,215,633 | —- | M] () – C:\Users\Andrew\Documents\583251-14.09.10_1409201010505700.pdf
[2010/09/19 10:44:33 | 004,295,189 | —- | M] () – C:\Users\Andrew\Documents\YouTubeDownloaderSetup261.exe
[2010/09/18 22:09:29 | 000,001,034 | —- | M] () – C:\Users\Andrew\Desktop\DVDVideoSoft Free Studio.lnk
[2010/09/18 22:07:58 | 018,095,568 | —- | M] (DVDVideoSoft Limited. ) – C:\Users\Andrew\Documents\FreeYouTubeToMp3Converter.exe
[2010/09/18 22:03:03 | 000,001,911 | —- | M] () – C:\Users\Andrew\Desktop\Cucusoft iPod Movie & Video Converter.lnk
[2010/09/18 20:57:45 | 009,575,606 | —- | M] (Cucusoft, Inc. ) – C:\Users\Andrew\Documents\ipodconv.exe
[2010/09/12 19:25:40 | 000,015,872 | —- | M] () – C:\Users\Andrew\Documents\ranking.xls
[2010/09/12 17:47:37 | 000,056,517 | —- | M] () – C:\Users\Andrew\Documents\torrentdownloads net Cannibal Holocaust Uncut 1980
[2010/09/12 15:47:02 | 000,829,162 | —- | M] () – C:\Users\Andrew\Documents\TK_70-272_v13_221_Q___A.pdf
[2010/09/12 14:08:43 | 000,829,162 | —- | M] () – C:\Users\Andrew\Documents\TestKing_70-272_v13a.pdf
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/11 17:35:38 | 248,385,300 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/10/11 17:29:50 | 000,284,915 | —- | C] () – C:\Users\Andrew\Desktop\gmer.zip
[2010/10/10 20:52:16 | 001,211,285 | —- | C] () – C:\Users\Andrew\Desktop\tdsskiller.zip
[2010/10/10 13:48:26 | 013,072,572 | —- | C] () – C:\Users\Andrew\Documents\SysinternalsSuite.zip
[2010/10/09 19:38:22 | 000,014,777 | —- | C] () – C:\Users\Andrew\Documents\Battlestar Galactica The Plan 2009
[2010/10/09 18:52:35 | 003,046,400 | —- | C] () – C:\Users\Andrew\Documents\mvt_en-gb.msi
[2010/10/09 17:22:33 | 000,524,288 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TMContainer00000000000000000002.regtrans-ms
[2010/10/09 17:22:33 | 000,524,288 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TMContainer00000000000000000001.regtrans-ms
[2010/10/09 17:22:32 | 000,065,536 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{3bd006c0-d3be-11df-9f61-001e4ce63776}.TM.blf
[2010/10/08 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TMContainer00000000000000000002.regtrans-ms
[2010/10/08 20:42:54 | 000,524,288 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TMContainer00000000000000000001.regtrans-ms
[2010/10/08 20:42:54 | 000,065,536 | -HS- | C] () – C:\Users\Andrew\ntuser.dat{6b27168c-d312-11df-9275-c36babd50834}.TM.blf
[2010/10/08 20:42:44 | 3485,425,664 | -HS- | C] () – C:\hiberfil.sys
[2010/10/08 17:21:02 | 000,000,120 | —- | C] () – C:\Users\Andrew\AppData\Local\Bhiveqodadujodiv.dat
[2010/10/08 17:21:02 | 000,000,000 | —- | C] () – C:\Users\Andrew\AppData\Local\Sqosefixipugofor.bin
[2010/10/04 21:06:28 | 001,722,772 | —- | C] () – C:\Users\Andrew\Documents\MCPDigitalCertPDF.zip
[2010/10/03 14:03:58 | 004,295,761 | —- | C] () – C:\Users\Andrew\Documents\YouTubeDownloaderSetup262.exe
[2010/10/02 17:21:04 | 000,583,888 | —- | C] () – C:\Windows\System32\atiumdva.cap
[2010/10/02 17:21:01 | 000,021,866 | —- | C] () – C:\Windows\atiogl.xml
[2010/10/02 17:20:24 | 000,076,216 | —- | C] () – C:\Windows\System32\atiapfxx.blb
[2010/09/26 18:31:39 | 000,002,231 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/09/26 09:43:12 | 000,001,523 | —- | C] () – C:\Users\Public\Desktop\Half-Life 2.lnk
[2010/09/23 18:31:45 | 000,016,695 | —- | C] () – C:\Users\Andrew\Documents\alivetorrents_com The Curious Case of Benjamin Button [2008]
[2010/09/22 08:03:30 | 000,033,827 | —- | C] () – C:\Users\Andrew\Documents\Microsoft Visual Studio 2008
[2010/09/20 20:01:42 | 000,215,633 | —- | C] () – C:\Users\Andrew\Documents\583251-14.09.10_1409201010505700.pdf
[2010/09/19 10:45:19 | 000,000,921 | —- | C] () – C:\Users\Public\Desktop\YouTube Downloader.lnk
[2010/09/19 10:44:28 | 004,295,189 | —- | C] () – C:\Users\Andrew\Documents\YouTubeDownloaderSetup261.exe
[2010/09/18 22:09:27 | 000,001,034 | —- | C] () – C:\Users\Andrew\Desktop\DVDVideoSoft Free Studio.lnk
[2010/09/18 22:03:03 | 000,001,911 | —- | C] () – C:\Users\Andrew\Desktop\Cucusoft iPod Movie & Video Converter.lnk
[2010/09/12 17:47:36 | 000,056,517 | —- | C] () – C:\Users\Andrew\Documents\torrentdownloads net Cannibal Holocaust Uncut 1980
[2010/09/12 15:47:00 | 000,829,162 | —- | C] () – C:\Users\Andrew\Documents\TK_70-272_v13_221_Q___A.pdf
[2010/09/12 14:08:38 | 000,829,162 | —- | C] () – C:\Users\Andrew\Documents\TestKing_70-272_v13a.pdf
[2010/08/24 21:30:44 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/24 21:30:42 | 000,304,640 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/08/23 18:15:02 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2010/08/23 18:15:01 | 000,022,328 | —- | C] () – C:\Users\Andrew\AppData\Roaming\PnkBstrK.sys
[2010/08/04 01:14:28 | 000,023,040 | —- | C] () – C:\Windows\System32\atitmpxx.dll
[2010/06/19 18:31:42 | 000,000,680 | —- | C] () – C:\Users\Andrew\AppData\Local\d3d9caps.dat
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2010/03/27 01:13:26 | 000,024,064 | —- | C] () – C:\Users\Andrew\AppData\Roaming\UserTile.png
[2009/09/11 19:00:22 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/12/25 18:59:27 | 000,000,319 | —- | C] () – C:\Windows\game.ini
[2008/10/19 20:25:56 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/19 20:25:56 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2008/08/31 17:42:48 | 000,017,920 | —- | C] () – C:\Users\Andrew\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/18 12:32:55 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/06/15 17:41:09 | 000,069,632 | —- | C] () – C:\Windows\System32\xmltok.dll
[2008/06/15 17:41:09 | 000,036,864 | —- | C] () – C:\Windows\System32\xmlparse.dll
[2008/05/18 19:48:40 | 000,003,682 | —- | C] () – C:\Users\Andrew\AppData\Roaming\wklnhst.dat
[2008/05/02 14:59:30 | 000,876,544 | —- | C] () – C:\Windows\System32\TEACico2.dll
[2008/05/02 07:14:49 | 000,131,066 | —- | C] () – C:\Windows\System32\DellPM.ini
[2007/02/13 11:14:18 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/11/14 12:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2010/10/09 17:20:54 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\085AFDEEE2B825F5E29B5F69ED328277
[2008/12/06 14:09:14 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Amazon
[2009/08/31 16:51:51 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/10/09 19:58:46 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\BitTorrent
[2010/03/14 22:10:06 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\DNA
[2010/09/18 22:09:31 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/03/27 14:11:25 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Foxit
[2009/02/25 15:41:00 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\My Games
[2010/03/26 19:18:30 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Opera
[2010/03/27 01:13:26 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\PeerNetworking
[2008/06/04 18:30:36 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\Template
[2010/10/09 22:39:14 | 000,000,000 | —D | M] – C:\Users\Andrew\AppData\Roaming\TomTom
[2010/10/11 07:45:56 | 000,032,622 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2008/05/02 14:47:51 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\drivers\AGP440.sys
[2008/05/02 14:47:51 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2008/05/02 14:47:51 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2008/05/02 14:47:51 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2006/11/02 10:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/04/11 07:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/05/02 14:48:10 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2008/05/02 14:59:08 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=61CA2C1E145809813C28752298CF9843 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5da5d093\atapi.sys
[2008/05/02 14:59:08 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=61CA2C1E145809813C28752298CF9843 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20580_none_db8503133dc1c2af\atapi.sys
[2008/05/02 14:59:08 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=7EB55F6BEFB392BD312CD0CD5263305D – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_6c3af7d3\atapi.sys
[2008/05/02 14:59:08 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=7EB55F6BEFB392BD312CD0CD5263305D – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16470_none_db063634249c06f4\atapi.sys
[2008/05/02 14:47:49 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys
[2008/05/02 14:47:49 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys
[2008/05/02 14:48:10 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2008/05/02 14:48:10 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008/05/02 14:55:33 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/05/02 14:55:33 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/05/02 14:55:33 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\System32\drivers\atapi.sys
[2008/05/02 14:55:33 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2008/05/02 14:55:33 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 10:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTOR.SYS >
[2007/09/29 23:03:32 | 000,384,024 | —- | M] (Intel Corporation) MD5=16A4671255CFB842225F0FDB6DBDB414 – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys
[2007/12/11 09:43:48 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Drivers\storage\R173412\IaStor.sys
[2007/09/29 23:03:12 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys
[2007/12/11 09:43:48 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Windows\System32\drivers\iaStor.sys
[2007/12/11 09:43:48 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_7baf6192\iaStor.sys
[2007/12/11 09:43:48 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_41af7b1f\iaStor.sys
< MD5 for: IASTORV.SYS >
[2008/01/19 08:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 08:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2006/11/02 10:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 08:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2006/11/02 10:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 10:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/19 08:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 10:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 07:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 07:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 784 bytes -> C:\Users\Andrew\Documents\F_A_O_ Melville Thomson.eml:OECustomProperty
@Alternate Data Stream - 498 bytes -> C:\ProgramData\TEMP:05EE1EEF
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 11/10/2010 17:50:54 - Run 1
OTL by OldTimer - Version 3.2.15.0 Folder = C:\Users\Andrew\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 450.70 Gb Total Space | 170.31 Gb Free Space | 37.79% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.22 Gb Free Space | 54.83% Space Free | Partition Type: NTFS
Computer Name: ANDREW-PC | User Name: Andrew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" File not found
https [open] – "C:\Program Files\Opera\opera.exe" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0DC37154-BE38-4F05-BF11-78AC7AF1878E}" = rport=139 | protocol=6 | dir=out | app=system |
"{1998247F-EC85-48BB-8D1B-F151EE7CBAF8}" = rport=137 | protocol=17 | dir=out | app=system |
"{250FE4A8-AA1E-4A6E-AAE9-9BB37783FE47}" = rport=445 | protocol=6 | dir=out | app=system |
"{473D83A9-E944-4467-BDB2-E41A79D0773C}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{72AF3E2B-1287-4650-A588-4C2DD1DC600F}" = lport=138 | protocol=17 | dir=in | app=system |
"{81072528-8B9F-4BC0-B74E-D0283B4185C6}" = lport=445 | protocol=6 | dir=in | app=system |
"{8DABEE6D-C7A8-4B98-84CA-877CF24F0E40}" = lport=139 | protocol=6 | dir=in | app=system |
"{9F7A7461-1CB1-46BD-9C16-065A12A4C77C}" = lport=137 | protocol=17 | dir=in | app=system |
"{CDADC99B-A808-40F3-BFB0-01094FE76E16}" = rport=138 | protocol=17 | dir=out | app=system |
"{D5208D41-6066-4194-895E-5086DF8148A3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FC760A1E-D553-481E-836D-F4F8C32F2B3F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03FB67E4-C7A1-41C9-A996-D15D6BF9846C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{0E2C1CD9-5E04-4A7B-BC5E-005E6D5A1B8F}" = protocol=6 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{0F0A57CE-C601-4BC5-BE0D-EFEF87B3E4FD}" = protocol=6 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{11580DD8-4054-4AE9-ABA0-E5BA9A4E717C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{1699DA8D-D623-42DA-97AC-9586BCA88480}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{1ED02E5A-B275-4F02-B023-503B0BF25D7D}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{2292BDB7-835C-4FF8-93E0-A5B687FB19BD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{243B405A-EC5C-4FD8-B58F-6358856EE19A}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{265CDB80-0A37-4DB9-99B5-05687D0CBFB7}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{320E7400-B647-48F0-B675-C34CB3C4247C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{354669BF-A57A-4590-8BC2-8565555F9028}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{3B3B3510-8239-47ED-951B-05670D21A9E7}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{4190F331-511B-419C-AC54-F0AF255EF913}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4901275F-1B14-4524-9493-CE32911B85A8}" = protocol=6 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{4D44F26E-F93F-4E1B-A36D-2545F92477CF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5461FED0-EB50-4D5B-8694-0B7B77C3BD50}" = protocol=17 | dir=in | app=c:\program files\firaxis games\sid meier's civilization 4\civilization4.exe |
"{587E9192-9CF1-4219-9ABB-A0185A3B65F5}" = protocol=17 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{5C971C94-3B1D-44F0-9FF5-944D75EE9372}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5D8743D3-C928-460E-81D5-8029FE6C39E2}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{5E67EAD5-99AC-4BF6-9A06-00EDE0AF3F1C}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{5FA09F15-A7AD-4DD4-966C-37A0224F8AAD}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{6424E78D-D883-44FE-ACF7-0C40032DF540}" = protocol=6 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{6738221E-4287-4998-BC54-5268D7713F14}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{681954D0-FCC6-4DED-A2BB-5963FA08DE45}" = protocol=17 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"{6CCF299F-EC17-455B-8C3D-5CC6033090B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\amd driver updater, vista and 7, 32 bit\setup.exe |
"{70AC884F-C74D-4E55-8A24-215587CB9D52}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{80766CB3-A5A5-4B6D-9E37-5F1E8A2E5A52}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{811218E9-BB0F-41D2-9049-0E5ADE68B095}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{82DA877C-3490-4A50-AEBB-9DB2A1F3450E}" = protocol=17 | dir=in | app=c:\program files\mass effect 2\binaries\masseffect2.exe |
"{87F11600-275E-4F64-8C4B-342CC01F26CF}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{89788096-F811-48A0-AF23-3FA05BDE9290}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{89C28BAD-3C26-44E3-96AC-FB6493D7E327}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{8B36D457-A92C-4556-9DD6-45F1CEB18F00}" = protocol=17 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{8DFC4127-0EED-42F8-9A4E-E81C2E08E627}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{8E9D866F-51B3-45BC-8A8E-635D197CE174}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{8EB567C5-B265-4866-AB78-C89E9B11AE52}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{9B75DA49-FC81-4B20-826F-9B7F902B3F94}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9CE005BD-86A0-41A1-A62E-D24E0B05A577}" = protocol=17 | dir=in | app=c:\program files\mass effect 2\masseffect2launcher.exe |
"{9FF5BDB5-3604-41D4-8AAB-E73E6CA51CC4}" = protocol=6 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"{A150352B-F566-4A80-87A2-DFC3DB1C3B69}" = protocol=17 | dir=in | app=c:\program files\kontiki\kservice.exe |
"{A1DF3A43-36C3-4673-B115-6141C56CEE13}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2D77795-DBE0-4B73-9CBF-EC185C4E8F4C}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{A3A21DAE-0222-4A0B-A408-8B4B65459E97}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{B5BBEDB0-A3CB-4F10-BC10-DCCE3FC475D9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{B904F3BA-2930-4BB9-9665-295A9EDBD841}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{BB186C50-BEA5-4A13-B49E-390D4437C6F0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{BBE15461-CD25-4334-AC8A-555956AF22B8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{C5CC8DA4-1962-4B99-BE47-AA30875ABCB6}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{C9A18AA9-1F7A-4527-8D2D-8E6E21D9D6E8}" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{CA4F48DA-1C07-4B91-8E56-8C771ED05F82}" = protocol=6 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
"{CE0347F0-669D-41F7-BAB7-A851D4F9938D}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{CF1E9A2C-A78E-4870-A2C2-1DD4B66A7080}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D05CF9FE-F5D7-449D-8398-20C1298C1707}" = protocol=17 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
"{E18EE75A-BDC3-4E71-BC1C-31AD74BE3F0C}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{E9D2A9C6-C36F-4B7A-B157-12F9FEDF0730}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\amd driver updater, vista and 7, 32 bit\setup.exe |
"{EC85AEE2-BF2F-4DCE-93BD-E737E4397DD2}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{F3F03356-3998-4916-A615-4ECE9EF1A0B0}" = protocol=6 | dir=in | app=c:\program files\mass effect 2\masseffect2launcher.exe |
"{F522A572-262F-403F-B768-89F737E0F45D}" = protocol=6 | dir=in | app=c:\program files\mass effect 2\binaries\masseffect2.exe |
"{FB0AB679-D1E6-4AC6-9007-75984A18AAEC}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"TCP Query User{2CF4F5ED-BB1C-4E4F-B83F-5CBD6C3937FB}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{457AE1A0-C5FE-4BC5-9D52-E8EBF14D4AE8}C:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-engb-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-engb-downloader.exe |
"UDP Query User{385851DA-4C82-4792-8A08-25D41664D46D}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{B8A839A0-8FD3-44EA-BABB-6C2904F94B14}C:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-engb-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-engb-downloader.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{01D51B09-8C96-66F8-92BF-33A7E164C55C}" = Catalyst Control Center Localization Portuguese
"{0280F0D8-1542-4DAA-913C-8529E2A3835D}" = The Longest Journey
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.4300
"{043D8259-3CAA-6F8C-6E2D-E38283FC0D4D}" = CCC Help Chinese Standard
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07183287-CF06-9557-D0A0-4DF5A237CD05}" = CCC Help Spanish
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0C9F2F87-6FA3-488C-F489-3501F178C480}" = Catalyst Control Center Localization Chinese Standard
"{0CA675F4-84C5-43EF-870F-93D68D55554A}" = Microsoft Press Readiness Review Suite 70-271
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.6.2
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{1E01E143-E78C-A324-FF2F-16EAA0C6CB1E}" = CCC Help Hungarian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1FB3C00D-E214-F383-0D86-47211D4472EC}" = CCC Help Chinese Traditional
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 18
"{27C467F8-F8EF-4f68-BD72-D63632B2096C}" = McAfee Online Backup
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{30EE5A21-1E57-1DFF-3D59-E6B5EE5C274E}" = CCC Help English
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FB3647F-B6A6-46B4-8613-A09BCFAB80F0}" = Roxio Creator Premier 10
"{40C801DC-E428-E41B-C4BC-8AD9C07C4336}" = Catalyst Control Center Graphics Full New
"{419D6CBB-322C-4EE2-0866-FB582514BF62}" = Catalyst Control Center Localization Korean
"{41F09D47-DBF4-1497-ACAF-534AED2AD7F4}" = Catalyst Control Center Graphics Full Existing
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{43934147-4A8B-EFEF-BD42-CFE52CF5663B}" = Catalyst Control Center Localization Polish
"{44415FD8-A554-AA16-00E7-B1DF43F49CB0}" = Catalyst Control Center Graphics Previews Common
"{448E2D77-E504-4221-B2C2-93646B344729}" = Mouse Suite for Desktop Computers
"{4498C780-9A00-105B-80CE-AB458C680888}" = Catalyst Control Center Localization Spanish
"{469EF13B-4AD0-48D7-AF89-6B92278293E2}" = Roxio Creator Premier
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{493909E8-83A7-E4D5-C7E8-E75E5E53FB07}" = Catalyst Control Center Localization Japanese
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4AB9C5C3-B890-97EC-26ED-ECD96645B5FF}" = Catalyst Control Center Localization Chinese Traditional
"{4CA09BF7-1CFC-44B8-80EA-7B4D15D12DC5}" = Catalyst Control Center - Branding
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{51DC7E02-3EEE-D01E-60D1-103A0DA2C3BF}" = Catalyst Control Center Graphics Previews Common
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{59ADFE8C-AD8C-2B04-6940-2D417FBAD111}" = CCC Help English
"{59F24743-2EA1-3A45-B8C2-6E0E1E078FA8}" = Microsoft Visual C# 2010 Express - ENU
"{5C82FB90-FD74-BB07-AA83-A6B683E407E8}" = Skins
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5E14A164-4DC8-7686-DFF9-1B0DC0E9C22E}" = Catalyst Control Center Graphics Light
"{616BF52A-6B5C-E98A-D320-F7CB396289B4}" = CCC Help German
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6863264D-A026-74F9-B6B9-6432CD83E8D0}" = Catalyst Control Center Localization Thai
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B7CEA10-4694-4FC3-B761-9DBFD50B8F2A}" = Client Settings Tool
"{7160D728-3A2B-5E11-CF1C-F0F46790C1C5}" = ccc-core-static
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{75736F55-9518-4D33-8CD9-8183C71EEA89}" = Microsoft Press Training Kit Exam Prep Suite 70-536
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections [removed]
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7C503E58-B2BC-11D5-978A-0050BA84F5F7}" = Neverwinter Nights
"{7CB2A775-9537-F0B3-B12C-39935FC406BE}" = CCC Help Portuguese
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack
"{8F1A20DC-251D-47B0-91B7-DCA2523EE6C9}" = McAfee Virtual Technician
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{93DD0407-71F9-CC33-DFEB-6A972D9A0D6C}" = CCC Help Italian
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96FB529E-634D-48EF-91CB-A1A06243E25C}" = CCC Help Korean
"{99CD4458-A1E7-BDCF-2838-B2FEC4D7F3BD}" = Catalyst Control Center Localization Hungarian
"{9B63540D-D942-4C38-B42E-A48AE0145970}" = Virtua Tennis 3
"{9E327786-6078-3A3D-B161-34C57105B183}" = CCC Help Polish
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A43494A1-A4D4-A75B-EE06-5DD390DE9D6F}" = ccc-utility
"{AB5EC8FC-C7D5-797E-A33C-79695264E0E7}" = CCC Help French
"{AC16252B-B731-8133-A10F-E4F8066945B4}" = CCC Help Turkish
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.4
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{AF2E5BA0-759C-926D-6C3F-11A3751C286E}" = Catalyst Control Center Graphics Previews Vista
"{B1AE9D28-DA40-4C5E-94BC-5A6C7FA7A43B}" = Catalyst Control Center Graphics Previews Vista
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes
"{BAD890B2-D495-E30F-48A7-95ADB7A7C811}" = CCC Help Thai
"{BEA18030-8B42-1286-EF64-CDA6BD083888}" = BBC iPlayer Desktop
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C5F776B4-B76E-43CF-8A66-BF847BC12B09}" = Microsoft Press Readiness Review Suite 70-272
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C81A17EF-B3FA-3F03-DEF9-DC6E24F12D5A}" = CCC Help Japanese
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{C969744F-EB74-5868-719E-D4B1F3D0792F}" = ccc-utility
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE03D1DC-FD8D-2F5C-5FAD-02570BA0383B}" = Catalyst Control Center InstallProxy
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFF4500E-C5D6-695D-A027-B3D4DDED2CC3}" = McAfee Online Backup
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{D45EC259-4A19-4656-B588-C2C360DD18EA}" = Half-Life® 2
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DDB74B95-2169-9869-B4DA-7CC881C0AC59}" = Catalyst Control Center Core Implementation
"{DE44E86C-6339-394D-DD8A-D8BD499EB287}" = Catalyst Control Center Localization Turkish
"{E1E8CEE9-9A46-819C-2490-10B12E5A40EE}" = Catalyst Control Center Localization German
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator Premier
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{EFBBCE37-DE8C-CC16-48E8-DBBFB51B6FC4}" = Catalyst Control Center Localization French
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F34D6DAE-7777-5C40-E143-8A0D6A048F75}" = ATI Catalyst Install Manager
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FAA2E296-811E-4636-9B27-110423F321DF}_is1" = The Lost Crown Uninstaller
"{FD28B75E-10A2-63A9-6EBA-D4494220F903}" = Catalyst Control Center Localization Italian
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.4
"AudioConverter Studio_is1" = AudioConverter Studio 6.0
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"BitTorrent" = BitTorrent
"Crysis WARHEAD®" = Crysis WARHEAD®
"Cucusoft iPod Video Converter_is1" = Cucusoft iPod Video Converter 8.06
"Deus Ex" = Deus Ex
"Download Manager" = Download Manager 2.3.10
"DrmRemoval_is1" = DrmRemoval 3.8.7
"ffdshow_is1" = ffdshow
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual C# 2010 Express - ENU" = Microsoft Visual C# 2010 Express - ENU
"MSC" = McAfee Internet Security
"PROSetDX" = Intel® PRO Network Connections [removed]
"PunkBusterSvc" = PunkBuster Services
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"TomTom HOME" = TomTom HOME 2.7.6.2056
"Uninstall_is1" = Uninstall 1.0.0.1
"Unreal" = Unreal
"VLC media player" = VLC media player 1.0.1
"WinRAR archiver" = WinRAR archiver
"WinUAE" = WinUAE 1.5.3
"World of Warcraft" = World of Warcraft
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/10/2010 12:40:04 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:40:04 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:40:04 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:40:04 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:47:47 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:47:47 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:47:47 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:47:47 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:48:00 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
Error - 11/10/2010 12:48:00 | Computer Name = Andrew-PC | Source = Windows Search Service | ID = 3013
Description =
[ System Events ]
Error - 10/10/2010 03:52:33 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 10/10/2010 06:42:12 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 10/10/2010 07:40:24 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 10/10/2010 13:17:48 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/10/2010 02:19:54 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/10/2010 11:28:40 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/10/2010 12:35:55 | Computer Name = Andrew-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 17:33:47 on 11/10/2010 was unexpected.
Error - 11/10/2010 12:37:28 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 11/10/2010 12:42:18 | Computer Name = Andrew-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 17:40:38 on 11/10/2010 was unexpected.
Error - 11/10/2010 12:43:59 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >