elliebungo
Topic Starter
Hi
My internet is going really really slow and typing is really delayed. I've run malwarebytes, superantispyware, avira antivirus, wise disk cleaner, spywareblaster and temporary file cleaner. There were lots of things removed or quarantined through these programs. I've tried defragmenting and resetting internet explorer settings. I've installed the most recent windows update and updated the virus scanner and superantispyware. This all seemed to happen after a box appeared just after startup asking for permission to run an exe file and I stupidly clicked on run by accident. The virus scanners, malwarebytes, superantispyware, etc are no longer finding anything but the delay in internet browsing, typing delay is driving me mad!!
I should probably also say that I deleted 3 profiles from the pc but it looks like the one I left is shown as 'console' so not sure if I've deleted the wrong one or if I should have deleted any at all! Hope you can help. Many thanks, Ellie
This is the OTL extras log:
OTL Extras logfile created on: 21/10/2010 22:45:14 - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\elliebungo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 3000 3067 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 49.92 Gb Free Space | 10.95% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.37 Gb Free Space | 63.66% Space Free | Partition Type: NTFS
Drive E: | 641.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ESMITH | User Name: elliebungo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{024BCF26-F89B-4AE9-BE6C-844ADE001C25}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{03A34442-0A3F-437F-9512-A0BFD87D528B}" = lport=3390 | protocol=6 | dir=in | app=system |
"{0F6CB223-E6DE-407F-95D7-FE29F2366CE0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{154E7800-94D8-45EA-B436-7BE60168A8DC}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{20DBD095-FD49-4810-B973-84A64971D436}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{26B6F653-9A75-446A-8810-9190777AF2D8}" = lport=139 | protocol=6 | dir=in | app=system |
"{2C999786-EF4A-4836-9B41-FCA10A8A4193}" = lport=10244 | protocol=6 | dir=in | app=system |
"{36AF7472-2D1D-4D86-8205-6AE7C24060AD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3B67C64C-4446-44FC-99E6-140DB71C5BF9}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{3DA6791A-27AA-49F3-8103-7B59559EDD52}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{411C7462-507F-4362-BAA3-B3945263B765}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5833B060-6504-44A9-8D45-95BE95557909}" = lport=137 | protocol=17 | dir=in | app=system |
"{5B09635B-AB2A-47DC-BF60-1480757DD4D1}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{647026D4-345A-42B7-A11E-3B2A5FE2A365}" = lport=10244 | protocol=6 | dir=in | app=system |
"{6630E419-E6BE-48D7-86C4-33E1762DB872}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{6F16AA65-38C7-4D39-B075-9E1A3A3E574E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{708A2253-39E2-4CB2-8E77-5E6553C79E44}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{75E22B42-B5EA-4B7A-9BCF-D00346014C88}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{7B0B9152-D10F-49E8-99ED-B0E7F6EE5541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7CA2718A-4FC4-4A09-A2FC-2CE84AB2EFE8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93178B0D-0EBC-43B9-88E9-6859219C5170}" = rport=10244 | protocol=6 | dir=out | app=system |
"{9A4DCB91-27D3-44D8-B1A3-228639839011}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{9B47F3C0-9078-4C55-99D2-F3B8421471EF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9BF5A5F2-D866-48AF-B02C-8CA1DA26E42B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9C000FAE-FC2A-4C69-8FF8-72974DB67250}" = rport=445 | protocol=6 | dir=out | app=system |
"{9DB06E1B-80C4-4907-8695-27CDEF043612}" = lport=3390 | protocol=6 | dir=in | app=system |
"{9DCF91F2-FB4A-4947-9739-A1B1FBDFB8B8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9F41CD0D-50E2-4A91-9F44-1EDE2A778CE4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A05BB8CB-74E8-4E5F-B0E4-B9106E6E7968}" = rport=138 | protocol=17 | dir=out | app=system |
"{A897E64C-8142-44A1-BD53-556005E78A7A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AF3D597D-0B4B-4BA3-A2A7-FDF5D1AFFD94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B2E5EC88-4B47-426A-8E78-F9658A49AA2A}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B5570A67-EFC3-4FCB-B781-459CA1410C5D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BB8C8367-8256-4532-9E61-DD3E628DE2BF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BC179D42-5E1B-41BC-BB52-7DCDA1B0AF90}" = lport=445 | protocol=6 | dir=in | app=system |
"{BD49CCB9-B990-4659-9117-7CC3C2E0B2B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C086079B-FECD-4D55-B5FE-63B9534F1010}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
"{C8E11358-8A69-42EA-8D23-3CAD1009C531}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{CABED932-773F-4BA5-8143-4E09A0E29E49}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D38E6563-DAB7-45E6-A7E1-8A344C62DC5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D4EEBCA8-E4F3-4002-BD92-003BE5332705}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D8AF961B-5AAD-48CF-A943-E2E50EC64DB4}" = rport=139 | protocol=6 | dir=out | app=system |
"{DC22C94F-F181-47B0-869A-19B3632A77B4}" = lport=138 | protocol=17 | dir=in | app=system |
"{E8847FA2-0209-4369-A160-BC5374DD4808}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EC4A5D79-6F88-4EFE-9DDF-B7CB75E12A93}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ECCF1DA7-899A-4C52-8703-1D97470C3D2E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EF69750D-99B6-4135-8E31-F9778795EE89}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F02B1727-D535-44BB-AE41-E61EDE982343}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F15AA9AD-FCCC-4098-AB98-30A8ADA6E8FC}" = rport=10244 | protocol=6 | dir=out | app=system |
"{F26E36F0-5DB9-45D8-BA30-01A1FBB4CAED}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE5A7583-2890-4DD8-8E6F-27A478CF2A94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{014B6FC6-2E30-487A-9A27-D5F681D6570E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{03520D48-B2B0-4DFA-8B7F-1A2D6572EE23}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{04214DFE-2049-4D33-877A-4F2CA45FEBFD}" = protocol=6 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{0529050D-4292-4A87-B4C3-DE0DB77804E6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{088EF0E5-2AE2-481F-B9A9-BCD45393226D}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{09FC73A6-42E1-4885-8BAE-FDD86D8C92FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0FD6EFB9-CAD5-489A-8B12-D110AEACA7AF}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{104F04BA-25B2-415B-9813-40B1BE17F148}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{108D432B-8D15-4FB1-9FC1-92BED39F0839}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{14485AD1-110D-4733-8C43-3FB1A52B22A3}" = protocol=6 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{14F0C042-6FC4-40C0-A721-43860FD3F2F1}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{16243067-6B4F-4B34-9835-23F0422B47AD}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{19D402EA-6A95-4511-B123-5521D26E6DCB}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{1C459696-DEFB-452D-94A4-705BD9BD4714}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2270A841-7CCC-411E-B936-79BD3D031BE9}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{246F31FF-EB09-42BC-B848-E2E22E584CF5}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{2CD8EF25-191B-4557-B23A-A1732B48CFF2}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{329E2FA5-393F-4887-B278-5123E3B1C85B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4074E4D6-28BE-478A-AC48-BAE08F8D988D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{4170A50E-D900-4FCF-A14F-9A42C891E6FB}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{4472E7D3-5C0F-4F47-A84C-4D3604C4170A}" = protocol=17 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{4562D3C2-B6B9-4025-AD0E-06853A7E48A7}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{4C2A7A48-1660-43BE-826F-EC491C1943BB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4D5F42BD-DC14-4956-A44F-DE634339AC5A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4EADF9D0-0F13-4EE6-B5B0-15515B9DC9E6}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{53E79BF6-E295-4338-86EC-885DE5F78228}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{57D84B66-1D95-4662-BA9E-5A436B00B989}" = protocol=17 | dir=in | app=c:\program files\namco bandai games\warhammer mark of chaos\warhammer.exe |
"{5D075E90-D8C9-435A-AD22-FD6FE297C361}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{607C8AAE-1EA2-4722-A75B-A786001946EB}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{60EDD7A3-137C-492E-8DEF-C1704D254093}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{734E9815-2CC3-4A92-9E56-82DF70421867}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{74C3304C-02C0-4D09-962C-606D0B4AD9B0}" = protocol=17 | dir=in | app=c:\users\elliebungo\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{75BC53FA-5DB8-4455-9367-22A1863EF208}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{7AA2D7DC-9003-421E-AE42-9AE5D46AD00D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7BB7C06B-B74F-4518-B5BE-5E27FFF5D4C4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7E0621F7-6669-446F-95C6-673F48379C66}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{812EC45F-990D-4EA8-99A5-B2CCA6C3A861}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{81BE5D7A-5A4E-4C85-A0EC-C7527728A56D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{831331B3-B70D-4AE4-B0C2-AACD3926EF8E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8ACE092F-F0C2-4F51-8C34-13470A41B414}" = protocol=17 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{981BCE77-DD93-4BFB-99D7-7787A038DBF1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9FB1B147-71D1-4791-8C08-1AB5441F5276}" = protocol=6 | dir=out | app=system |
"{A508001C-FE35-4143-A71F-6D714420B1FF}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{AA0C8DC4-405C-4E5D-A19B-64409165D3BE}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{B49CB1F9-ADFD-4888-B0EA-3D02885A6980}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B6F49797-3559-4F9F-9B82-314EBD4C5B49}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{B8267931-B4C3-4F92-AF59-4208F085D27C}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{B8B46DB4-794D-45B0-97D8-63698E099083}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BF5F58F0-D31A-4BC1-A595-2EC9D35F5FBD}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{BFBB35D5-E005-4A95-B85A-386111FC85CA}" = protocol=6 | dir=in | app=c:\users\elliebungo\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{C2BB9188-2990-45FA-A739-208BB49B51D7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C333327C-8EE3-45CD-ADC0-DBB52A6A45CB}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{C82EC96E-929A-428E-9796-CCEE171D7EB1}" = protocol=6 | dir=in | app=c:\program files\namco bandai games\warhammer mark of chaos\warhammer.exe |
"{CA62FD22-7449-4141-84E9-55975E0654C5}" = protocol=6 | dir=in | app=c:\program files\gamespy arcade\aphex.exe |
"{CC876A2C-3FC9-47E5-930C-A5CC0C6AE848}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{CEB969FD-73E2-4101-9A01-5DB3FE8F5C77}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{DBED3766-A31C-4EF5-9D7D-6C210017D31A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E3ED1B41-E6C6-4698-A761-44B8A91E5C55}" = protocol=17 | dir=in | app=c:\program files\gamespy arcade\aphex.exe |
"{EC404350-FF42-4E58-B0DF-BC5487539C73}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{EEAE8840-95D0-4678-B65C-8469AE694CA5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F0378877-0142-49EE-AF48-DD15E2F51208}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{F314822E-BFA3-46D5-B586-BB9A35EEBEB2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{0AFB72A3-0C1E-4C38-9A50-2568FC0CEA17}C:\program files\sony\station\launchpad\launchpad.exe" = protocol=6 | dir=in | app=c:\program files\sony\station\launchpad\launchpad.exe |
"TCP Query User{144E54A5-35CB-47EA-819D-EA8CBA577150}C:\program files\black isle\baldur's gate\bgmain.exe" = protocol=6 | dir=in | app=c:\program files\black isle\baldur's gate\bgmain.exe |
"TCP Query User{37599B9B-DEDC-4AA7-A340-CA815B9B705F}C:\program files\winamp remote\bin\orbir.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"TCP Query User{3A817D38-C6B2-4A43-AFBE-4CD33D8C2137}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{63377455-AA25-4661-860A-7E9C07F63418}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{88EC5ED2-5A12-4A4C-80C0-4D6D8514D51F}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{8953A09C-B5E5-49DF-9BDD-7C08D3099AA6}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{8D313979-7720-4349-B6C7-63C9CACF36C4}C:\program files\winamp remote\bin\orb.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"TCP Query User{8FBAB0E0-77C4-435D-B7F1-2205FF1815EE}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{BB658558-F3CE-47CD-AA2B-464229998ABB}C:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=6 | dir=in | app=c:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe |
"TCP Query User{C20B4375-4FD5-460A-8EAE-7E807800EE13}C:\program files\winamp remote\bin\orbtray.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"TCP Query User{D1F5B2C9-F573-40DB-A34C-BD092D5FFD5F}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{FD19AC0B-3A35-4EC6-A5EA-9E9F83C62515}C:\codemasters\severance\bin\blade.exe" = protocol=6 | dir=in | app=c:\codemasters\severance\bin\blade.exe |
"UDP Query User{00F1F687-8965-4360-A012-5AD021F169C8}C:\program files\sony\station\launchpad\launchpad.exe" = protocol=17 | dir=in | app=c:\program files\sony\station\launchpad\launchpad.exe |
"UDP Query User{1C706850-8751-4D0F-ABE2-42C46F3042A6}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{34FECB87-8405-4525-A54A-A73A15B42CB9}C:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=17 | dir=in | app=c:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe |
"UDP Query User{58CF3E23-6395-4AA4-8FB4-964CCE7667CD}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{5DB863D4-ABC0-4110-AFDA-4F3272212E1A}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{78A237FA-D9AA-4437-BC97-36E0FA4335DD}C:\program files\winamp remote\bin\orbir.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"UDP Query User{8477DCAD-77D1-440B-82F2-410BA2674CA2}C:\codemasters\severance\bin\blade.exe" = protocol=17 | dir=in | app=c:\codemasters\severance\bin\blade.exe |
"UDP Query User{8B90CBFB-431D-47AC-B1D0-7782A475EFBD}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{9E2053BF-DCEF-4493-B5F9-3C19A3810353}C:\program files\winamp remote\bin\orbtray.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"UDP Query User{9E97DB29-C12C-438F-A033-C091CBE7823D}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{A1073D39-F4A7-471D-848F-DC08E94E5176}C:\program files\winamp remote\bin\orb.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"UDP Query User{CF599730-5E31-4427-8D59-E5CC07DCB2FB}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{FE9DA7B0-4BE4-490D-AF4A-D7DEE281E9CD}C:\program files\black isle\baldur's gate\bgmain.exe" = protocol=17 | dir=in | app=c:\program files\black isle\baldur's gate\bgmain.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DE20748-45A5-6CD9-610E-F881A34E7342}" = Catalyst Control Center Localization Arabic
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{15CC10AB-4266-210D-E2D2-03089C25A028}" = CCC Help English
"{1603C7DC-358B-97AF-B451-B2DDAC734117}" = Catalyst Control Center Localization French
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{214030BC-490D-57D4-2547-D0D4ECC851A5}" = Catalyst Control Center Localization Japanese
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2B98E4C3-AABC-9594-3219-A6EB60006C2C}" = Catalyst Control Center Graphics Full Existing
"{2C698DB8-0D99-5A27-DA3D-A3414FC5DBA7}" = Catalyst Control Center Graphics Light
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{31DBBB49-CAC2-984A-64CA-A88102056E10}" = CCC Help German
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{412FECA2-836F-3DF6-A302-924CEC5B4DE2}" = CCC Help Spanish
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46ACAEB5-365A-74BB-D405-980EA4FE3545}" = CCC Help Japanese
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AAB7E8F-1C71-E364-458F-5A6797670157}" = Catalyst Control Center Graphics Full New
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65E6362A-B878-4A7B-86DA-D16F8DBD75C7}" = ccc-core-static
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6DD45BD7-DB28-E59F-8239-CF6816AE1FA4}" = Skins
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{76C73966-AED3-5ACB-B438-B47E9B1FB2E3}" = CCC Help Chinese Standard
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{794F49F0-2A44-EE74-62FE-22FD68953A25}" = ccc-utility
"{7CD5F286-FF0A-E638-8143-0E258E3C17E2}" = CCC Help Thai
"{7CE979C6-E5FF-41C5-B6CC-4EE18071563B}" = SierraAddressBook 3.0
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98698CC8-F4C4-A0A7-F521-8547DDD1BB6B}" = Catalyst Control Center Localization Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBB19C0-1FE1-4A4E-B25F-C9E1B0497EC5}" = Shaiya(US)
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B651AD20-D522-2D6F-3AC7-A5F625FCB283}" = Catalyst Control Center Core Implementation
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{C3E2D64C-1B8E-D142-A76F-DEAC02AFF4FA}" = CCC Help Polish
"{C5145CD4-4F74-C986-F86B-F57F3995C59B}" = Catalyst Control Center Localization Arabic
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8D524C0-FBD2-C4F0-2446-912EABA681E0}" = CCC Help Portuguese
"{CCF7F09E-A1C5-7D81-437D-B2DC347CC52E}" = Catalyst Control Center Localization Spanish
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEEE47BB-4AB7-9AEB-2212-ECC6D05DDC74}" = Catalyst Control Center Localization Italian
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D71B45B0-70B5-12BA-4ACF-2CEC94FE8A06}" = CCC Help Korean
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = COWON Media Center - jetAudio Plus VX
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7744050-4D6F-1280-5331-2EA048B51E94}" = Catalyst Control Center Localization Arabic
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECA80341-4BFB-172D-EC5D-64FD8DD41F5A}" = Catalyst Control Center Localization German
"{ECBEB9C6-CC47-70F7-E939-1E20E3BEEC8F}" = Catalyst Control Center Localization Korean
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{F038C836-BE82-4AE4-9326-A90A43D6431D}" = MAME32 Plus
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4FA8AC4-6B6A-CAA6-8E44-FC64227CC4F7}" = CCC Help Italian
"{F6412237-45F7-B34B-0803-4D77E2D39D0C}" = Catalyst Control Center Localization Chinese Traditional
"{FD01FEBF-376F-F125-09F8-E94B04D21E77}" = CCC Help French
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF001690-A829-9DFD-9EF6-DA285783C49C}" = CCC Help Chinese Traditional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALSong_is1" = ALSong
"ALUpdate_is1" = ALTools Update
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner (remove only)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GameSpy Arcade" = GameSpy Arcade
"Google Updater" = Google Updater
"Guild Wars" = Guild Wars
"Hardware Helper_is1" = Hardware Helper
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"KaraFun_is1" = KaraFun 1.18
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (2.0.0.2)" = Mozilla Firefox (2.0.0.2)
"NCH Toolbar" = NCH Toolbar
"Revo Uninstaller" = Revo Uninstaller 1.83
"SpywareBlaster_is1" = SpywareBlaster 4.4
"Surprise Attack Jigsaw Puzzle_is1" = He-man Jigsaw Puzzles: Surprise Attack
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar for Internet Explorer
"Winamp Toolbar for Firefox" = Winamp Toolbar for Firefox
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.62
"wyigk" = Favorit
"x26 (z26 Front End)_is1" = x26 v1.1.12
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
This is the OTL txt log:
OTL logfile created on: 21/10/2010 22:45:14 - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\elliebungo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 3000 3067 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 49.92 Gb Free Space | 10.95% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.37 Gb Free Space | 63.66% Space Free | Partition Type: NTFS
Drive E: | 641.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ESMITH | User Name: elliebungo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\elliebungo\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
========== Modules (SafeList) ==========
MOD - C:\Users\elliebungo\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_062a651.dll ()
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (USBAAPL) – C:\Windows\System32\Drivers\usbaapl.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (UMPass) – C:\Windows\System32\drivers\umpass.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ZSMC301b) – C:\Windows\System32\drivers\usbVM31b.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {c2db4fe6-8409-45ce-8010-189a7b5cce86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ie/ig/dell?hl=en&cli…amp;ibd=1070715
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:29775
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={6E5E3D95-8BD1-EE8A-97A5-AACA2A231918}&q="
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/19 20:51:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/19 20:51:44 | 000,000,000 | —D | M]
[2010/10/19 23:28:02 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions
[2009/03/24 20:06:58 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009/09/04 12:37:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/14 23:30:33 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/20 19:39:03 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/15 23:07:35 | 000,000,000 | —D | M] (NCH Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2009/12/10 20:10:54 | 000,000,000 | —D | M] (Fast Browser Search (My Face LOL)) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2009/12/09 00:03:15 | 000,005,407 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\fast-browser-search.xml
[2009/07/27 17:10:25 | 000,009,949 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\mywebsearch.xml
[2009/03/24 20:07:16 | 000,001,196 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\winamp-search.xml
[2010/10/21 21:15:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 08:25:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/21 21:15:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2007/10/22 22:27:33 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/28 03:49:53 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/28 03:49:43 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2009/03/28 03:49:43 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2009/03/28 03:49:43 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2009/03/28 03:49:45 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2009/03/28 03:49:45 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2010/10/21 21:15:02 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (NCH Toolbar) - {c2db4fe6-8409-45ce-8010-189a7b5cce86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (NCH Toolbar) - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe/accounttracking.cab (Egg Money Manager Digital Safe)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\biosserv: DllName - biosserv.dll - File not found
O24 - Desktop WallPaper: C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [1999/10/01 19:30:46 | 000,000,041 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{6d6ed688-3234-11dc-9ac9-806e6f6e6963}\Shell\AutoRun\command - "" = E:\RAL.EXE – [2000/01/27 19:09:36 | 005,676,544 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.XVID - xvidvfw.dll File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/10/21 22:35:57 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/10/21 21:16:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/10/21 21:15:15 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/21 21:15:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/21 21:15:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/21 21:14:56 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/10/21 20:36:35 | 016,074,528 | —- | C] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/21 19:35:41 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_5.dll
[2010/10/21 19:35:40 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_43.dll
[2010/10/21 19:35:40 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_43.dll
[2010/10/21 19:35:40 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_43.dll
[2010/10/21 19:35:40 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_7.dll
[2010/10/21 19:35:40 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_43.dll
[2010/10/21 19:35:40 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_43.dll
[2010/10/21 19:35:40 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_7.dll
[2010/10/21 19:35:39 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_6.dll
[2010/10/21 19:35:39 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2010/10/21 19:35:39 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_6.dll
[2010/10/21 19:35:39 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_4.dll
[2010/10/21 19:35:39 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_7.dll
[2010/10/21 19:35:38 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_42.dll
[2010/10/21 19:35:38 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_41.dll
[2010/10/21 19:35:38 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_42.dll
[2010/10/21 19:35:38 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_42.dll
[2010/10/21 19:35:38 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2010/10/21 19:35:38 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_5.dll
[2010/10/21 19:35:38 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_42.dll
[2010/10/21 19:35:37 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2010/10/21 19:35:37 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_40.dll
[2010/10/21 19:35:37 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2010/10/21 19:35:37 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_40.dll
[2010/10/21 19:35:37 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2010/10/21 19:35:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/10/21 19:35:37 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2010/10/21 19:35:36 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_3.dll
[2010/10/21 19:35:36 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2010/10/21 19:35:36 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2010/10/21 19:35:36 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_3.dll
[2010/10/21 19:35:36 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_2.dll
[2010/10/21 19:35:36 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2010/10/21 19:35:36 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_5.dll
[2010/10/21 19:35:35 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2010/10/21 19:35:35 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2010/10/21 19:35:35 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2010/10/21 19:35:35 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2010/10/21 19:35:35 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2010/10/21 19:35:34 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2010/10/21 19:35:34 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2010/10/21 19:35:34 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2010/10/21 19:35:34 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2010/10/21 19:35:33 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_38.dll
[2010/10/21 19:35:33 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2010/10/21 19:35:33 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2010/10/21 19:35:33 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2010/10/21 19:35:33 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2010/10/21 19:35:33 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2010/10/21 19:35:33 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2010/10/21 19:35:32 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2010/10/21 19:35:32 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2010/10/21 19:35:32 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2010/10/21 19:35:32 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2010/10/21 19:35:31 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2010/10/21 19:35:31 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2010/10/21 19:35:31 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2010/10/21 19:35:31 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2010/10/21 19:35:31 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2010/10/21 19:35:31 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2010/10/21 19:35:31 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2010/10/21 19:35:30 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2010/10/21 19:35:30 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2010/10/21 19:33:54 | 000,000,000 | -H-D | C] – C:\Windows\msdownld.tmp
[2010/10/21 19:33:51 | 000,000,000 | —D | C] – C:\Windows\System32\directx
[2010/10/19 23:37:18 | 000,000,000 | —D | C] – C:\Users\elliebungo\AppData\Roaming\Malwarebytes
[2010/10/19 23:37:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/19 23:37:08 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/10/19 23:37:08 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/19 23:37:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/19 22:52:25 | 000,000,000 | —D | C] – C:\rc
[2010/10/19 22:06:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2010/10/19 21:56:46 | 000,000,000 | —D | C] – C:\Users\elliebungo\AppData\Local\Windows Live
[2010/10/19 21:54:43 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/10/19 21:44:46 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/10/19 20:47:54 | 000,000,000 | —D | C] – C:\Windows\Temp
[2010/10/19 20:46:17 | 001,079,296 | —- | C] (ADDPCs) – C:\Users\elliebungo\Desktop\tempCleaner.exe
[2010/10/19 20:07:39 | 000,000,000 | —D | C] – C:\Program Files\Wise Disk Cleaner
[2010/10/19 19:48:16 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2010/10/14 22:18:39 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/14 22:18:25 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/14 22:18:01 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/14 22:17:44 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/14 22:17:39 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/14 22:17:39 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/14 22:17:39 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/14 22:17:38 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/14 22:17:38 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/14 22:17:38 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/14 22:17:38 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/14 22:17:38 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/14 22:17:38 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/14 22:17:38 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/14 22:17:38 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/14 22:17:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/14 22:17:38 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/14 22:17:38 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/14 22:17:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/14 22:17:38 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/14 22:17:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/14 22:17:33 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/14 22:17:33 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/14 22:17:27 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/14 22:17:23 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/01 20:19:17 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/10/01 20:19:15 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/09/29 15:05:22 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/23 08:44:27 | 000,000,000 | —D | C] – C:\Program Files\MAME
[2010/09/23 00:47:28 | 000,049,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/21 22:48:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/21 22:45:00 | 000,000,416 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D5EB8124-DDB4-422A-A76F-CC3E68FA35AD}.job
[2010/10/21 22:36:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/10/21 22:16:20 | 000,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/10/21 21:15:01 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/10/21 21:15:01 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/21 21:15:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/21 21:15:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/21 21:10:15 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/21 21:09:19 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/21 21:09:19 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/21 21:09:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/21 21:09:11 | 2145,902,592 | -HS- | M] () – C:\hiberfil.sys
[2010/10/21 20:36:47 | 016,074,528 | —- | M] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/19 23:37:12 | 000,000,780 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/19 23:12:28 | 000,461,376 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/19 20:46:01 | 000,976,273 | —- | M] () – C:\Users\elliebungo\Desktop\tempCleaner_3.0.4.exe.zip
[2010/10/19 20:07:41 | 000,001,802 | —- | M] () – C:\Users\elliebungo\Desktop\Wise Disk Cleaner Free.lnk
[2010/10/19 20:07:41 | 000,001,788 | —- | M] () – C:\Users\elliebungo\Desktop\Clean disk with 1 click.lnk
[2010/10/19 20:07:41 | 000,000,928 | —- | M] () – C:\Users\elliebungo\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Disk Cleaner.lnk
[2010/10/19 19:48:17 | 000,000,814 | —- | M] () – C:\Users\elliebungo\Desktop\SpywareBlaster.lnk
[2010/10/17 15:59:00 | 000,001,356 | —- | M] () – C:\Users\elliebungo\AppData\Local\d3d9caps.dat
[2010/10/16 20:32:59 | 000,000,008 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/10/16 14:06:00 | 000,241,152 | —- | M] () – C:\Users\elliebungo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 22:28:41 | 000,104,581 | —- | M] () – C:\Users\elliebungo\Desktop\paint - revengance 2.jpg
[2010/10/01 20:20:35 | 000,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/09/23 00:47:28 | 000,049,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/19 23:37:12 | 000,000,780 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/19 20:46:00 | 000,976,273 | —- | C] () – C:\Users\elliebungo\Desktop\tempCleaner_3.0.4.exe.zip
[2010/10/19 20:07:41 | 000,001,802 | —- | C] () – C:\Users\elliebungo\Desktop\Wise Disk Cleaner Free.lnk
[2010/10/19 20:07:41 | 000,001,788 | —- | C] () – C:\Users\elliebungo\Desktop\Clean disk with 1 click.lnk
[2010/10/19 20:07:41 | 000,000,928 | —- | C] () – C:\Users\elliebungo\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Disk Cleaner.lnk
[2010/10/19 19:48:17 | 000,000,814 | —- | C] () – C:\Users\elliebungo\Desktop\SpywareBlaster.lnk
[2010/10/17 20:06:15 | 2145,902,592 | -HS- | C] () – C:\hiberfil.sys
[2010/10/01 20:20:35 | 000,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/08/17 18:25:11 | 000,000,157 | —- | C] () – C:\Windows\SIERRA.INI
[2010/07/01 18:52:19 | 000,000,178 | —- | C] () – C:\ProgramData\lxdx.log
[2010/06/21 16:33:50 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2010/06/21 16:33:50 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2010/06/21 16:33:50 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2010/04/11 23:08:17 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/01/10 01:04:35 | 000,000,050 | —- | C] () – C:\Windows\Progs_.ini
[2010/01/05 18:23:26 | 000,000,960 | —- | C] () – C:\ProgramData\ss.ini
[2009/12/29 23:48:10 | 002,044,851 | —- | C] () – C:\Windows\System32\servxp.dll
[2009/12/29 23:48:10 | 001,457,003 | —- | C] () – C:\Windows\System32\netusb.dll
[2009/12/29 23:48:10 | 000,428,142 | —- | C] () – C:\Windows\System32\perfbot.dll
[2009/12/29 23:48:10 | 000,381,236 | —- | C] () – C:\Windows\System32\vbadisk.dll
[2009/12/29 23:48:10 | 000,377,874 | —- | C] () – C:\Windows\System32\actmap.dll
[2009/12/29 23:48:10 | 000,339,786 | —- | C] () – C:\Windows\System32\utilmidi.dll
[2009/12/29 23:47:54 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/20 15:15:25 | 000,000,008 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/11/04 20:46:36 | 000,000,016 | -H– | C] () – C:\Users\elliebungo\AppData\Local\art.udk
[2009/11/04 20:46:35 | 000,000,017 | -H– | C] () – C:\Users\elliebungo\AppData\Local\19720201.dat
[2009/11/04 16:15:38 | 000,000,018 | —- | C] () – C:\Windows\gfact.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/05/30 13:33:54 | 000,027,648 | —- | C] () – C:\Windows\System32\AVSredirect.dll
[2009/04/27 10:44:25 | 000,000,093 | —- | C] () – C:\Users\elliebungo\AppData\Local\wyigk.bat
[2009/03/01 11:27:05 | 000,001,356 | —- | C] () – C:\Users\elliebungo\AppData\Local\d3d9caps.dat
[2009/01/19 21:28:20 | 001,228,854 | —- | C] () – C:\ProgramData\OrbError.bmp
[2007/08/05 14:56:37 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2007/07/26 22:37:56 | 000,008,992 | —- | C] () – C:\Users\elliebungo\AppData\Roaming\wklnhst.dat
[2007/07/21 12:22:54 | 000,241,152 | —- | C] () – C:\Users\elliebungo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/15 03:00:07 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:33:50 | 000,297,857 | —- | C] () – C:\Windows\System32\xmlodbc.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/10/14 11:56:50 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2005/10/14 11:56:50 | 000,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2005/10/14 11:56:50 | 000,344,064 | —- | C] () – C:\Windows\System32\xvid.dll
[2005/10/14 11:56:50 | 000,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2005/10/14 11:56:50 | 000,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2005/10/14 11:56:50 | 000,155,136 | —- | C] () – C:\Windows\System32\unrar.dll
[2005/10/14 11:56:50 | 000,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[2001/03/06 20:47:48 | 000,077,560 | —- | C] () – C:\Windows\System32\libungif.dll
========== LOP Check ==========
[2009/04/06 21:26:51 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\COWON
[2009/11/11 00:44:45 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\FOG Downloader
[2009/01/24 23:30:20 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Leadertech
[2010/07/16 18:29:09 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Lexmark Productivity Studio
[2008/05/26 09:53:51 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\LimeWire
[2010/02/19 00:03:01 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\ScummVM
[2009/03/24 16:38:27 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Serif
[2009/07/21 11:37:31 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Spectaculator
[2009/10/23 12:22:02 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\SpinTop
[2009/08/18 17:33:15 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Stella
[2007/07/26 22:37:58 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Template
[2010/01/03 17:50:44 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Texthelp Systems
[2010/03/10 23:58:58 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Trusteer
[2010/10/03 23:33:21 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\uTorrent
[2009/06/03 23:10:25 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\WindSolutions
[2009/11/04 20:46:44 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\www.My-Software.co.uk
[2010/10/21 20:57:26 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/10/21 22:45:00 | 000,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D5EB8124-DDB4-422A-A76F-CC3E68FA35AD}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 14:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/07/15 03:00:15 | 000,004,354 | RH– | M] () – C:\dell.sdr
[2010/10/21 21:09:11 | 2145,902,592 | -HS- | M] () – C:\hiberfil.sys
[2009/06/07 00:56:42 | 000,052,253 | —- | M] () – C:\lma_log.html
[2010/10/19 20:57:31 | 000,000,078 | —- | M] () – C:\lxdx.log
[2010/10/21 21:09:10 | 3145,728,000 | -HS- | M] () – C:\pagefile.sys
[2009/07/11 13:58:24 | 000,000,150 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/01/05 17:24:49 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/11 01:52:58 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/19 13:08:35 | 000,000,286 | -HS- | M] () – C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/04/10 19:01:59 | 000,000,179 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\YouTube - Broadcast Yourself..url
< %USERPROFILE%\Desktop\*.exe >
[2001/06/06 16:54:54 | 000,036,864 | —- | M] () – C:\Users\elliebungo\Desktop\Autorun.exe
[2010/08/14 10:39:01 | 054,822,952 | —- | M] (Online Media Technologies Ltd. ) – C:\Users\elliebungo\Desktop\AVSVideoConverter.exe
[2010/08/15 23:05:32 | 000,456,800 | —- | M] (NCH Software) – C:\Users\elliebungo\Desktop\disketchsetup.exe
[2010/05/11 17:41:13 | 001,180,952 | —- | M] (DivX, Inc. ) – C:\Users\elliebungo\Desktop\DivXWebPlayerInstaller.exe
[2010/09/05 14:16:51 | 000,343,696 | —- | M] (Gameforge 4D ) – C:\Users\elliebungo\Desktop\Downloader_4Story_uk_3.3.26.exe
[2010/07/10 17:58:45 | 128,891,648 | —- | M] () – C:\Users\elliebungo\Desktop\dx7sdk.exe
[2010/08/16 20:56:34 | 001,609,432 | —- | M] () – C:\Users\elliebungo\Desktop\ezcdsetup.exe
[2010/03/30 22:12:23 | 000,000,000 | —- | M] () – C:\Users\elliebungo\Desktop\Firefox Setup 3.6.2.exe
[2010/10/21 20:36:47 | 016,074,528 | —- | M] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/21 22:36:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/04/22 18:30:43 | 000,634,344 | —- | M] () – C:\Users\elliebungo\Desktop\radiobar_toolbar.exe
[2010/06/22 14:33:03 | 002,347,946 | —- | M] (Codemasters ) – C:\Users\elliebungo\Desktop\sevpatch.exe
[2010/07/22 16:24:20 | 000,138,176 | —- | M] () – C:\Users\elliebungo\Desktop\Shaiya_Install_US_20090508_csd.exe
[2009/04/21 23:02:24 | 001,079,296 | —- | M] (ADDPCs) – C:\Users\elliebungo\Desktop\tempCleaner.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-20 02:02:53
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:52B72A7C
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Warhammer Battle March:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Northern Ireland 3-2 Spain Euro 2008 Qualifier.avi:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Ibiza 2007.m3u:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\HardwareHelper:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\Revengance recordings:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\messin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\l_e945df51aa2a427196979d332ba6fa5b.png:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\Incomplete:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\connally-assassination-2.jpg:Roxio EMC Stream
@Alternate Data Stream - 64 bytes -> C:\Users\elliebungo\Documents\Northern Ireland 3-2 Spain Euro 2008 Qualifier.avi:TOC.WMV
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E7833B2E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:3B360415
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CD30FA91
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AFFC859A
< End of report >
My internet is going really really slow and typing is really delayed. I've run malwarebytes, superantispyware, avira antivirus, wise disk cleaner, spywareblaster and temporary file cleaner. There were lots of things removed or quarantined through these programs. I've tried defragmenting and resetting internet explorer settings. I've installed the most recent windows update and updated the virus scanner and superantispyware. This all seemed to happen after a box appeared just after startup asking for permission to run an exe file and I stupidly clicked on run by accident. The virus scanners, malwarebytes, superantispyware, etc are no longer finding anything but the delay in internet browsing, typing delay is driving me mad!!
I should probably also say that I deleted 3 profiles from the pc but it looks like the one I left is shown as 'console' so not sure if I've deleted the wrong one or if I should have deleted any at all! Hope you can help. Many thanks, Ellie
This is the OTL extras log:
OTL Extras logfile created on: 21/10/2010 22:45:14 - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\elliebungo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 3000 3067 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 49.92 Gb Free Space | 10.95% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.37 Gb Free Space | 63.66% Space Free | Partition Type: NTFS
Drive E: | 641.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ESMITH | User Name: elliebungo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{024BCF26-F89B-4AE9-BE6C-844ADE001C25}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{03A34442-0A3F-437F-9512-A0BFD87D528B}" = lport=3390 | protocol=6 | dir=in | app=system |
"{0F6CB223-E6DE-407F-95D7-FE29F2366CE0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{154E7800-94D8-45EA-B436-7BE60168A8DC}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{20DBD095-FD49-4810-B973-84A64971D436}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{26B6F653-9A75-446A-8810-9190777AF2D8}" = lport=139 | protocol=6 | dir=in | app=system |
"{2C999786-EF4A-4836-9B41-FCA10A8A4193}" = lport=10244 | protocol=6 | dir=in | app=system |
"{36AF7472-2D1D-4D86-8205-6AE7C24060AD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3B67C64C-4446-44FC-99E6-140DB71C5BF9}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{3DA6791A-27AA-49F3-8103-7B59559EDD52}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{411C7462-507F-4362-BAA3-B3945263B765}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5833B060-6504-44A9-8D45-95BE95557909}" = lport=137 | protocol=17 | dir=in | app=system |
"{5B09635B-AB2A-47DC-BF60-1480757DD4D1}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{647026D4-345A-42B7-A11E-3B2A5FE2A365}" = lport=10244 | protocol=6 | dir=in | app=system |
"{6630E419-E6BE-48D7-86C4-33E1762DB872}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{6F16AA65-38C7-4D39-B075-9E1A3A3E574E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{708A2253-39E2-4CB2-8E77-5E6553C79E44}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{75E22B42-B5EA-4B7A-9BCF-D00346014C88}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{7B0B9152-D10F-49E8-99ED-B0E7F6EE5541}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7CA2718A-4FC4-4A09-A2FC-2CE84AB2EFE8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{93178B0D-0EBC-43B9-88E9-6859219C5170}" = rport=10244 | protocol=6 | dir=out | app=system |
"{9A4DCB91-27D3-44D8-B1A3-228639839011}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{9B47F3C0-9078-4C55-99D2-F3B8421471EF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9BF5A5F2-D866-48AF-B02C-8CA1DA26E42B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9C000FAE-FC2A-4C69-8FF8-72974DB67250}" = rport=445 | protocol=6 | dir=out | app=system |
"{9DB06E1B-80C4-4907-8695-27CDEF043612}" = lport=3390 | protocol=6 | dir=in | app=system |
"{9DCF91F2-FB4A-4947-9739-A1B1FBDFB8B8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9F41CD0D-50E2-4A91-9F44-1EDE2A778CE4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A05BB8CB-74E8-4E5F-B0E4-B9106E6E7968}" = rport=138 | protocol=17 | dir=out | app=system |
"{A897E64C-8142-44A1-BD53-556005E78A7A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AF3D597D-0B4B-4BA3-A2A7-FDF5D1AFFD94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B2E5EC88-4B47-426A-8E78-F9658A49AA2A}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B5570A67-EFC3-4FCB-B781-459CA1410C5D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BB8C8367-8256-4532-9E61-DD3E628DE2BF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BC179D42-5E1B-41BC-BB52-7DCDA1B0AF90}" = lport=445 | protocol=6 | dir=in | app=system |
"{BD49CCB9-B990-4659-9117-7CC3C2E0B2B5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C086079B-FECD-4D55-B5FE-63B9534F1010}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
"{C8E11358-8A69-42EA-8D23-3CAD1009C531}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{CABED932-773F-4BA5-8143-4E09A0E29E49}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D38E6563-DAB7-45E6-A7E1-8A344C62DC5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D4EEBCA8-E4F3-4002-BD92-003BE5332705}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D8AF961B-5AAD-48CF-A943-E2E50EC64DB4}" = rport=139 | protocol=6 | dir=out | app=system |
"{DC22C94F-F181-47B0-869A-19B3632A77B4}" = lport=138 | protocol=17 | dir=in | app=system |
"{E8847FA2-0209-4369-A160-BC5374DD4808}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EC4A5D79-6F88-4EFE-9DDF-B7CB75E12A93}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ECCF1DA7-899A-4C52-8703-1D97470C3D2E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EF69750D-99B6-4135-8E31-F9778795EE89}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F02B1727-D535-44BB-AE41-E61EDE982343}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{F15AA9AD-FCCC-4098-AB98-30A8ADA6E8FC}" = rport=10244 | protocol=6 | dir=out | app=system |
"{F26E36F0-5DB9-45D8-BA30-01A1FBB4CAED}" = rport=137 | protocol=17 | dir=out | app=system |
"{FE5A7583-2890-4DD8-8E6F-27A478CF2A94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{014B6FC6-2E30-487A-9A27-D5F681D6570E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{03520D48-B2B0-4DFA-8B7F-1A2D6572EE23}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{04214DFE-2049-4D33-877A-4F2CA45FEBFD}" = protocol=6 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{0529050D-4292-4A87-B4C3-DE0DB77804E6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{088EF0E5-2AE2-481F-B9A9-BCD45393226D}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{09FC73A6-42E1-4885-8BAE-FDD86D8C92FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0FD6EFB9-CAD5-489A-8B12-D110AEACA7AF}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{104F04BA-25B2-415B-9813-40B1BE17F148}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{108D432B-8D15-4FB1-9FC1-92BED39F0839}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{14485AD1-110D-4733-8C43-3FB1A52B22A3}" = protocol=6 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{14F0C042-6FC4-40C0-A721-43860FD3F2F1}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{16243067-6B4F-4B34-9835-23F0422B47AD}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{19D402EA-6A95-4511-B123-5521D26E6DCB}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{1C459696-DEFB-452D-94A4-705BD9BD4714}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2270A841-7CCC-411E-B936-79BD3D031BE9}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{246F31FF-EB09-42BC-B848-E2E22E584CF5}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{2CD8EF25-191B-4557-B23A-A1732B48CFF2}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"{329E2FA5-393F-4887-B278-5123E3B1C85B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4074E4D6-28BE-478A-AC48-BAE08F8D988D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{4170A50E-D900-4FCF-A14F-9A42C891E6FB}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{4472E7D3-5C0F-4F47-A84C-4D3604C4170A}" = protocol=17 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{4562D3C2-B6B9-4025-AD0E-06853A7E48A7}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{4C2A7A48-1660-43BE-826F-EC491C1943BB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4D5F42BD-DC14-4956-A44F-DE634339AC5A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4EADF9D0-0F13-4EE6-B5B0-15515B9DC9E6}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{53E79BF6-E295-4338-86EC-885DE5F78228}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{57D84B66-1D95-4662-BA9E-5A436B00B989}" = protocol=17 | dir=in | app=c:\program files\namco bandai games\warhammer mark of chaos\warhammer.exe |
"{5D075E90-D8C9-435A-AD22-FD6FE297C361}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{607C8AAE-1EA2-4722-A75B-A786001946EB}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{60EDD7A3-137C-492E-8DEF-C1704D254093}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{734E9815-2CC3-4A92-9E56-82DF70421867}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"{74C3304C-02C0-4D09-962C-606D0B4AD9B0}" = protocol=17 | dir=in | app=c:\users\elliebungo\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{75BC53FA-5DB8-4455-9367-22A1863EF208}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{7AA2D7DC-9003-421E-AE42-9AE5D46AD00D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7BB7C06B-B74F-4518-B5BE-5E27FFF5D4C4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7E0621F7-6669-446F-95C6-673F48379C66}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{812EC45F-990D-4EA8-99A5-B2CCA6C3A861}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{81BE5D7A-5A4E-4C85-A0EC-C7527728A56D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{831331B3-B70D-4AE4-B0C2-AACD3926EF8E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8ACE092F-F0C2-4F51-8C34-13470A41B414}" = protocol=17 | dir=in | app=c:\program files\minions of mirth\bin\minionsofmirth.exe |
"{981BCE77-DD93-4BFB-99D7-7787A038DBF1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9FB1B147-71D1-4791-8C08-1AB5441F5276}" = protocol=6 | dir=out | app=system |
"{A508001C-FE35-4143-A71F-6D714420B1FF}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{AA0C8DC4-405C-4E5D-A19B-64409165D3BE}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{B49CB1F9-ADFD-4888-B0EA-3D02885A6980}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B6F49797-3559-4F9F-9B82-314EBD4C5B49}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{B8267931-B4C3-4F92-AF59-4208F085D27C}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{B8B46DB4-794D-45B0-97D8-63698E099083}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BF5F58F0-D31A-4BC1-A595-2EC9D35F5FBD}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{BFBB35D5-E005-4A95-B85A-386111FC85CA}" = protocol=6 | dir=in | app=c:\users\elliebungo\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{C2BB9188-2990-45FA-A739-208BB49B51D7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C333327C-8EE3-45CD-ADC0-DBB52A6A45CB}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{C82EC96E-929A-428E-9796-CCEE171D7EB1}" = protocol=6 | dir=in | app=c:\program files\namco bandai games\warhammer mark of chaos\warhammer.exe |
"{CA62FD22-7449-4141-84E9-55975E0654C5}" = protocol=6 | dir=in | app=c:\program files\gamespy arcade\aphex.exe |
"{CC876A2C-3FC9-47E5-930C-A5CC0C6AE848}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{CEB969FD-73E2-4101-9A01-5DB3FE8F5C77}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbstreamerclient.exe |
"{DBED3766-A31C-4EF5-9D7D-6C210017D31A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E3ED1B41-E6C6-4698-A761-44B8A91E5C55}" = protocol=17 | dir=in | app=c:\program files\gamespy arcade\aphex.exe |
"{EC404350-FF42-4E58-B0DF-BC5487539C73}" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{EEAE8840-95D0-4678-B65C-8469AE694CA5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F0378877-0142-49EE-AF48-DD15E2F51208}" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"{F314822E-BFA3-46D5-B586-BB9A35EEBEB2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{0AFB72A3-0C1E-4C38-9A50-2568FC0CEA17}C:\program files\sony\station\launchpad\launchpad.exe" = protocol=6 | dir=in | app=c:\program files\sony\station\launchpad\launchpad.exe |
"TCP Query User{144E54A5-35CB-47EA-819D-EA8CBA577150}C:\program files\black isle\baldur's gate\bgmain.exe" = protocol=6 | dir=in | app=c:\program files\black isle\baldur's gate\bgmain.exe |
"TCP Query User{37599B9B-DEDC-4AA7-A340-CA815B9B705F}C:\program files\winamp remote\bin\orbir.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"TCP Query User{3A817D38-C6B2-4A43-AFBE-4CD33D8C2137}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{63377455-AA25-4661-860A-7E9C07F63418}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{88EC5ED2-5A12-4A4C-80C0-4D6D8514D51F}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{8953A09C-B5E5-49DF-9BDD-7C08D3099AA6}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{8D313979-7720-4349-B6C7-63C9CACF36C4}C:\program files\winamp remote\bin\orb.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"TCP Query User{8FBAB0E0-77C4-435D-B7F1-2205FF1815EE}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{BB658558-F3CE-47CD-AA2B-464229998ABB}C:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=6 | dir=in | app=c:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe |
"TCP Query User{C20B4375-4FD5-460A-8EAE-7E807800EE13}C:\program files\winamp remote\bin\orbtray.exe" = protocol=6 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"TCP Query User{D1F5B2C9-F573-40DB-A34C-BD092D5FFD5F}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{FD19AC0B-3A35-4EC6-A5EA-9E9F83C62515}C:\codemasters\severance\bin\blade.exe" = protocol=6 | dir=in | app=c:\codemasters\severance\bin\blade.exe |
"UDP Query User{00F1F687-8965-4360-A012-5AD021F169C8}C:\program files\sony\station\launchpad\launchpad.exe" = protocol=17 | dir=in | app=c:\program files\sony\station\launchpad\launchpad.exe |
"UDP Query User{1C706850-8751-4D0F-ABE2-42C46F3042A6}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{34FECB87-8405-4525-A54A-A73A15B42CB9}C:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe" = protocol=17 | dir=in | app=c:\users\elliebungo\desktop\fogdownloader-rom_2_1_0_1871.exe |
"UDP Query User{58CF3E23-6395-4AA4-8FB4-964CCE7667CD}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{5DB863D4-ABC0-4110-AFDA-4F3272212E1A}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{78A237FA-D9AA-4437-BC97-36E0FA4335DD}C:\program files\winamp remote\bin\orbir.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbir.exe |
"UDP Query User{8477DCAD-77D1-440B-82F2-410BA2674CA2}C:\codemasters\severance\bin\blade.exe" = protocol=17 | dir=in | app=c:\codemasters\severance\bin\blade.exe |
"UDP Query User{8B90CBFB-431D-47AC-B1D0-7782A475EFBD}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{9E2053BF-DCEF-4493-B5F9-3C19A3810353}C:\program files\winamp remote\bin\orbtray.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orbtray.exe |
"UDP Query User{9E97DB29-C12C-438F-A033-C091CBE7823D}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{A1073D39-F4A7-471D-848F-DC08E94E5176}C:\program files\winamp remote\bin\orb.exe" = protocol=17 | dir=in | app=c:\program files\winamp remote\bin\orb.exe |
"UDP Query User{CF599730-5E31-4427-8D59-E5CC07DCB2FB}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{FE9DA7B0-4BE4-490D-AF4A-D7DEE281E9CD}C:\program files\black isle\baldur's gate\bgmain.exe" = protocol=17 | dir=in | app=c:\program files\black isle\baldur's gate\bgmain.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DE20748-45A5-6CD9-610E-F881A34E7342}" = Catalyst Control Center Localization Arabic
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{15CC10AB-4266-210D-E2D2-03089C25A028}" = CCC Help English
"{1603C7DC-358B-97AF-B451-B2DDAC734117}" = Catalyst Control Center Localization French
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{214030BC-490D-57D4-2547-D0D4ECC851A5}" = Catalyst Control Center Localization Japanese
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2B98E4C3-AABC-9594-3219-A6EB60006C2C}" = Catalyst Control Center Graphics Full Existing
"{2C698DB8-0D99-5A27-DA3D-A3414FC5DBA7}" = Catalyst Control Center Graphics Light
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{31DBBB49-CAC2-984A-64CA-A88102056E10}" = CCC Help German
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{412FECA2-836F-3DF6-A302-924CEC5B4DE2}" = CCC Help Spanish
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46ACAEB5-365A-74BB-D405-980EA4FE3545}" = CCC Help Japanese
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AAB7E8F-1C71-E364-458F-5A6797670157}" = Catalyst Control Center Graphics Full New
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65E6362A-B878-4A7B-86DA-D16F8DBD75C7}" = ccc-core-static
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6DD45BD7-DB28-E59F-8239-CF6816AE1FA4}" = Skins
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{76C73966-AED3-5ACB-B438-B47E9B1FB2E3}" = CCC Help Chinese Standard
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{794F49F0-2A44-EE74-62FE-22FD68953A25}" = ccc-utility
"{7CD5F286-FF0A-E638-8143-0E258E3C17E2}" = CCC Help Thai
"{7CE979C6-E5FF-41C5-B6CC-4EE18071563B}" = SierraAddressBook 3.0
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98698CC8-F4C4-A0A7-F521-8547DDD1BB6B}" = Catalyst Control Center Localization Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBB19C0-1FE1-4A4E-B25F-C9E1B0497EC5}" = Shaiya(US)
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B651AD20-D522-2D6F-3AC7-A5F625FCB283}" = Catalyst Control Center Core Implementation
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{C3E2D64C-1B8E-D142-A76F-DEAC02AFF4FA}" = CCC Help Polish
"{C5145CD4-4F74-C986-F86B-F57F3995C59B}" = Catalyst Control Center Localization Arabic
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8D524C0-FBD2-C4F0-2446-912EABA681E0}" = CCC Help Portuguese
"{CCF7F09E-A1C5-7D81-437D-B2DC347CC52E}" = Catalyst Control Center Localization Spanish
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEEE47BB-4AB7-9AEB-2212-ECC6D05DDC74}" = Catalyst Control Center Localization Italian
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D71B45B0-70B5-12BA-4ACF-2CEC94FE8A06}" = CCC Help Korean
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = COWON Media Center - jetAudio Plus VX
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7744050-4D6F-1280-5331-2EA048B51E94}" = Catalyst Control Center Localization Arabic
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECA80341-4BFB-172D-EC5D-64FD8DD41F5A}" = Catalyst Control Center Localization German
"{ECBEB9C6-CC47-70F7-E939-1E20E3BEEC8F}" = Catalyst Control Center Localization Korean
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{F038C836-BE82-4AE4-9326-A90A43D6431D}" = MAME32 Plus
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4FA8AC4-6B6A-CAA6-8E44-FC64227CC4F7}" = CCC Help Italian
"{F6412237-45F7-B34B-0803-4D77E2D39D0C}" = Catalyst Control Center Localization Chinese Traditional
"{FD01FEBF-376F-F125-09F8-E94B04D21E77}" = CCC Help French
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF001690-A829-9DFD-9EF6-DA285783C49C}" = CCC Help Chinese Traditional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALSong_is1" = ALSong
"ALUpdate_is1" = ALTools Update
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner (remove only)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GameSpy Arcade" = GameSpy Arcade
"Google Updater" = Google Updater
"Guild Wars" = Guild Wars
"Hardware Helper_is1" = Hardware Helper
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"KaraFun_is1" = KaraFun 1.18
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (2.0.0.2)" = Mozilla Firefox (2.0.0.2)
"NCH Toolbar" = NCH Toolbar
"Revo Uninstaller" = Revo Uninstaller 1.83
"SpywareBlaster_is1" = SpywareBlaster 4.4
"Surprise Attack Jigsaw Puzzle_is1" = He-man Jigsaw Puzzles: Surprise Attack
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar for Internet Explorer
"Winamp Toolbar for Firefox" = Winamp Toolbar for Firefox
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.62
"wyigk" = Favorit
"x26 (z26 Front End)_is1" = x26 v1.1.12
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
This is the OTL txt log:
OTL logfile created on: 21/10/2010 22:45:14 - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\elliebungo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 3000 3067 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.70 Gb Total Space | 49.92 Gb Free Space | 10.95% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.37 Gb Free Space | 63.66% Space Free | Partition Type: NTFS
Drive E: | 641.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ESMITH | User Name: elliebungo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\elliebungo\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
========== Modules (SafeList) ==========
MOD - C:\Users\elliebungo\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_062a651.dll ()
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (USBAAPL) – C:\Windows\System32\Drivers\usbaapl.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (UMPass) – C:\Windows\System32\drivers\umpass.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ZSMC301b) – C:\Windows\System32\drivers\usbVM31b.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {c2db4fe6-8409-45ce-8010-189a7b5cce86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ie/ig/dell?hl=en&cli…amp;ibd=1070715
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:29775
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={6E5E3D95-8BD1-EE8A-97A5-AACA2A231918}&q="
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/19 20:51:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/19 20:51:44 | 000,000,000 | —D | M]
[2010/10/19 23:28:02 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions
[2009/03/24 20:06:58 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009/09/04 12:37:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/14 23:30:33 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/20 19:39:03 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/15 23:07:35 | 000,000,000 | —D | M] (NCH Toolbar) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2009/12/10 20:10:54 | 000,000,000 | —D | M] (Fast Browser Search (My Face LOL)) – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2009/12/09 00:03:15 | 000,005,407 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\fast-browser-search.xml
[2009/07/27 17:10:25 | 000,009,949 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\mywebsearch.xml
[2009/03/24 20:07:16 | 000,001,196 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Mozilla\Firefox\Profiles\pf7szhq2.default\searchplugins\winamp-search.xml
[2010/10/21 21:15:17 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 08:25:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/21 21:15:17 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2007/10/22 22:27:33 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/28 03:49:53 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/28 03:49:43 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2009/03/28 03:49:43 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2009/03/28 03:49:43 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2009/03/28 03:49:45 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2009/03/28 03:49:45 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2010/10/21 21:15:02 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (NCH Toolbar) - {c2db4fe6-8409-45ce-8010-189a7b5cce86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (NCH Toolbar) - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - C:\Program Files\NCH\tbNCH.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe/accounttracking.cab (Egg Money Manager Digital Safe)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\biosserv: DllName - biosserv.dll - File not found
O24 - Desktop WallPaper: C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [1999/10/01 19:30:46 | 000,000,041 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{6d6ed688-3234-11dc-9ac9-806e6f6e6963}\Shell\AutoRun\command - "" = E:\RAL.EXE – [2000/01/27 19:09:36 | 005,676,544 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.XVID - xvidvfw.dll File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/10/21 22:35:57 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/10/21 21:16:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/10/21 21:15:15 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/21 21:15:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/21 21:15:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/21 21:14:56 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/10/21 20:36:35 | 016,074,528 | —- | C] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/21 19:35:41 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_5.dll
[2010/10/21 19:35:40 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_43.dll
[2010/10/21 19:35:40 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_43.dll
[2010/10/21 19:35:40 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_43.dll
[2010/10/21 19:35:40 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_7.dll
[2010/10/21 19:35:40 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_43.dll
[2010/10/21 19:35:40 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_43.dll
[2010/10/21 19:35:40 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_7.dll
[2010/10/21 19:35:39 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_6.dll
[2010/10/21 19:35:39 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2010/10/21 19:35:39 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_6.dll
[2010/10/21 19:35:39 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_4.dll
[2010/10/21 19:35:39 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_7.dll
[2010/10/21 19:35:38 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_42.dll
[2010/10/21 19:35:38 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_41.dll
[2010/10/21 19:35:38 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_42.dll
[2010/10/21 19:35:38 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_42.dll
[2010/10/21 19:35:38 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2010/10/21 19:35:38 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_5.dll
[2010/10/21 19:35:38 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_42.dll
[2010/10/21 19:35:37 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2010/10/21 19:35:37 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_40.dll
[2010/10/21 19:35:37 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2010/10/21 19:35:37 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_40.dll
[2010/10/21 19:35:37 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2010/10/21 19:35:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/10/21 19:35:37 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2010/10/21 19:35:36 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_3.dll
[2010/10/21 19:35:36 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2010/10/21 19:35:36 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2010/10/21 19:35:36 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_3.dll
[2010/10/21 19:35:36 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_2.dll
[2010/10/21 19:35:36 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2010/10/21 19:35:36 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_5.dll
[2010/10/21 19:35:35 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2010/10/21 19:35:35 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2010/10/21 19:35:35 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2010/10/21 19:35:35 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2010/10/21 19:35:35 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2010/10/21 19:35:34 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2010/10/21 19:35:34 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2010/10/21 19:35:34 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2010/10/21 19:35:34 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2010/10/21 19:35:33 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_38.dll
[2010/10/21 19:35:33 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2010/10/21 19:35:33 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2010/10/21 19:35:33 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2010/10/21 19:35:33 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2010/10/21 19:35:33 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2010/10/21 19:35:33 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2010/10/21 19:35:32 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2010/10/21 19:35:32 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2010/10/21 19:35:32 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2010/10/21 19:35:32 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2010/10/21 19:35:31 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2010/10/21 19:35:31 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2010/10/21 19:35:31 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2010/10/21 19:35:31 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2010/10/21 19:35:31 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2010/10/21 19:35:31 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2010/10/21 19:35:31 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2010/10/21 19:35:30 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2010/10/21 19:35:30 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2010/10/21 19:33:54 | 000,000,000 | -H-D | C] – C:\Windows\msdownld.tmp
[2010/10/21 19:33:51 | 000,000,000 | —D | C] – C:\Windows\System32\directx
[2010/10/19 23:37:18 | 000,000,000 | —D | C] – C:\Users\elliebungo\AppData\Roaming\Malwarebytes
[2010/10/19 23:37:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/19 23:37:08 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/10/19 23:37:08 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/19 23:37:08 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/19 22:52:25 | 000,000,000 | —D | C] – C:\rc
[2010/10/19 22:06:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2010/10/19 21:56:46 | 000,000,000 | —D | C] – C:\Users\elliebungo\AppData\Local\Windows Live
[2010/10/19 21:54:43 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/10/19 21:44:46 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/10/19 20:47:54 | 000,000,000 | —D | C] – C:\Windows\Temp
[2010/10/19 20:46:17 | 001,079,296 | —- | C] (ADDPCs) – C:\Users\elliebungo\Desktop\tempCleaner.exe
[2010/10/19 20:07:39 | 000,000,000 | —D | C] – C:\Program Files\Wise Disk Cleaner
[2010/10/19 19:48:16 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2010/10/14 22:18:39 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/14 22:18:25 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/14 22:18:01 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/14 22:17:44 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/14 22:17:39 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/14 22:17:39 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/14 22:17:39 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/14 22:17:38 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/14 22:17:38 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/14 22:17:38 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/14 22:17:38 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/14 22:17:38 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/14 22:17:38 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/14 22:17:38 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/14 22:17:38 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/14 22:17:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/14 22:17:38 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/14 22:17:38 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/14 22:17:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/14 22:17:38 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/14 22:17:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/14 22:17:33 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/14 22:17:33 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/14 22:17:27 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/14 22:17:23 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/01 20:19:17 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/10/01 20:19:15 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/09/29 15:05:22 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/23 08:44:27 | 000,000,000 | —D | C] – C:\Program Files\MAME
[2010/09/23 00:47:28 | 000,049,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/21 22:48:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/21 22:45:00 | 000,000,416 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D5EB8124-DDB4-422A-A76F-CC3E68FA35AD}.job
[2010/10/21 22:36:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/10/21 22:16:20 | 000,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/10/21 21:15:01 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/10/21 21:15:01 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/21 21:15:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/21 21:15:01 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/10/21 21:10:15 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/21 21:09:19 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/21 21:09:19 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/21 21:09:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/21 21:09:11 | 2145,902,592 | -HS- | M] () – C:\hiberfil.sys
[2010/10/21 20:36:47 | 016,074,528 | —- | M] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/19 23:37:12 | 000,000,780 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/19 23:12:28 | 000,461,376 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/19 20:46:01 | 000,976,273 | —- | M] () – C:\Users\elliebungo\Desktop\tempCleaner_3.0.4.exe.zip
[2010/10/19 20:07:41 | 000,001,802 | —- | M] () – C:\Users\elliebungo\Desktop\Wise Disk Cleaner Free.lnk
[2010/10/19 20:07:41 | 000,001,788 | —- | M] () – C:\Users\elliebungo\Desktop\Clean disk with 1 click.lnk
[2010/10/19 20:07:41 | 000,000,928 | —- | M] () – C:\Users\elliebungo\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Disk Cleaner.lnk
[2010/10/19 19:48:17 | 000,000,814 | —- | M] () – C:\Users\elliebungo\Desktop\SpywareBlaster.lnk
[2010/10/17 15:59:00 | 000,001,356 | —- | M] () – C:\Users\elliebungo\AppData\Local\d3d9caps.dat
[2010/10/16 20:32:59 | 000,000,008 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/10/16 14:06:00 | 000,241,152 | —- | M] () – C:\Users\elliebungo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 22:28:41 | 000,104,581 | —- | M] () – C:\Users\elliebungo\Desktop\paint - revengance 2.jpg
[2010/10/01 20:20:35 | 000,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/09/23 00:47:28 | 000,049,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sirenacm.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/19 23:37:12 | 000,000,780 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/19 20:46:00 | 000,976,273 | —- | C] () – C:\Users\elliebungo\Desktop\tempCleaner_3.0.4.exe.zip
[2010/10/19 20:07:41 | 000,001,802 | —- | C] () – C:\Users\elliebungo\Desktop\Wise Disk Cleaner Free.lnk
[2010/10/19 20:07:41 | 000,001,788 | —- | C] () – C:\Users\elliebungo\Desktop\Clean disk with 1 click.lnk
[2010/10/19 20:07:41 | 000,000,928 | —- | C] () – C:\Users\elliebungo\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise Disk Cleaner.lnk
[2010/10/19 19:48:17 | 000,000,814 | —- | C] () – C:\Users\elliebungo\Desktop\SpywareBlaster.lnk
[2010/10/17 20:06:15 | 2145,902,592 | -HS- | C] () – C:\hiberfil.sys
[2010/10/01 20:20:35 | 000,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/08/17 18:25:11 | 000,000,157 | —- | C] () – C:\Windows\SIERRA.INI
[2010/07/01 18:52:19 | 000,000,178 | —- | C] () – C:\ProgramData\lxdx.log
[2010/06/21 16:33:50 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2010/06/21 16:33:50 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2010/06/21 16:33:50 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2010/04/11 23:08:17 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/01/10 01:04:35 | 000,000,050 | —- | C] () – C:\Windows\Progs_.ini
[2010/01/05 18:23:26 | 000,000,960 | —- | C] () – C:\ProgramData\ss.ini
[2009/12/29 23:48:10 | 002,044,851 | —- | C] () – C:\Windows\System32\servxp.dll
[2009/12/29 23:48:10 | 001,457,003 | —- | C] () – C:\Windows\System32\netusb.dll
[2009/12/29 23:48:10 | 000,428,142 | —- | C] () – C:\Windows\System32\perfbot.dll
[2009/12/29 23:48:10 | 000,381,236 | —- | C] () – C:\Windows\System32\vbadisk.dll
[2009/12/29 23:48:10 | 000,377,874 | —- | C] () – C:\Windows\System32\actmap.dll
[2009/12/29 23:48:10 | 000,339,786 | —- | C] () – C:\Windows\System32\utilmidi.dll
[2009/12/29 23:47:54 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/12/20 15:15:25 | 000,000,008 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/11/04 20:46:36 | 000,000,016 | -H– | C] () – C:\Users\elliebungo\AppData\Local\art.udk
[2009/11/04 20:46:35 | 000,000,017 | -H– | C] () – C:\Users\elliebungo\AppData\Local\19720201.dat
[2009/11/04 16:15:38 | 000,000,018 | —- | C] () – C:\Windows\gfact.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/05/30 13:33:54 | 000,027,648 | —- | C] () – C:\Windows\System32\AVSredirect.dll
[2009/04/27 10:44:25 | 000,000,093 | —- | C] () – C:\Users\elliebungo\AppData\Local\wyigk.bat
[2009/03/01 11:27:05 | 000,001,356 | —- | C] () – C:\Users\elliebungo\AppData\Local\d3d9caps.dat
[2009/01/19 21:28:20 | 001,228,854 | —- | C] () – C:\ProgramData\OrbError.bmp
[2007/08/05 14:56:37 | 000,000,120 | —- | C] () – C:\Windows\wininit.ini
[2007/07/26 22:37:56 | 000,008,992 | —- | C] () – C:\Users\elliebungo\AppData\Roaming\wklnhst.dat
[2007/07/21 12:22:54 | 000,241,152 | —- | C] () – C:\Users\elliebungo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/15 03:00:07 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:33:50 | 000,297,857 | —- | C] () – C:\Windows\System32\xmlodbc.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/10/14 11:56:50 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2005/10/14 11:56:50 | 000,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2005/10/14 11:56:50 | 000,344,064 | —- | C] () – C:\Windows\System32\xvid.dll
[2005/10/14 11:56:50 | 000,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2005/10/14 11:56:50 | 000,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2005/10/14 11:56:50 | 000,155,136 | —- | C] () – C:\Windows\System32\unrar.dll
[2005/10/14 11:56:50 | 000,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[2001/03/06 20:47:48 | 000,077,560 | —- | C] () – C:\Windows\System32\libungif.dll
========== LOP Check ==========
[2009/04/06 21:26:51 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\COWON
[2009/11/11 00:44:45 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\FOG Downloader
[2009/01/24 23:30:20 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Leadertech
[2010/07/16 18:29:09 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Lexmark Productivity Studio
[2008/05/26 09:53:51 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\LimeWire
[2010/02/19 00:03:01 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\ScummVM
[2009/03/24 16:38:27 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Serif
[2009/07/21 11:37:31 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Spectaculator
[2009/10/23 12:22:02 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\SpinTop
[2009/08/18 17:33:15 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Stella
[2007/07/26 22:37:58 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Template
[2010/01/03 17:50:44 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Texthelp Systems
[2010/03/10 23:58:58 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\Trusteer
[2010/10/03 23:33:21 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\uTorrent
[2009/06/03 23:10:25 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\WindSolutions
[2009/11/04 20:46:44 | 000,000,000 | —D | M] – C:\Users\elliebungo\AppData\Roaming\www.My-Software.co.uk
[2010/10/21 20:57:26 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/10/21 22:45:00 | 000,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D5EB8124-DDB4-422A-A76F-CC3E68FA35AD}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 22:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 14:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/07/15 03:00:15 | 000,004,354 | RH– | M] () – C:\dell.sdr
[2010/10/21 21:09:11 | 2145,902,592 | -HS- | M] () – C:\hiberfil.sys
[2009/06/07 00:56:42 | 000,052,253 | —- | M] () – C:\lma_log.html
[2010/10/19 20:57:31 | 000,000,078 | —- | M] () – C:\lxdx.log
[2010/10/21 21:09:10 | 3145,728,000 | -HS- | M] () – C:\pagefile.sys
[2009/07/11 13:58:24 | 000,000,150 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/01/05 17:24:49 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/11 01:52:58 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/19 13:08:35 | 000,000,286 | -HS- | M] () – C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/04/10 19:01:59 | 000,000,179 | —- | M] () – C:\Users\elliebungo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\YouTube - Broadcast Yourself..url
< %USERPROFILE%\Desktop\*.exe >
[2001/06/06 16:54:54 | 000,036,864 | —- | M] () – C:\Users\elliebungo\Desktop\Autorun.exe
[2010/08/14 10:39:01 | 054,822,952 | —- | M] (Online Media Technologies Ltd. ) – C:\Users\elliebungo\Desktop\AVSVideoConverter.exe
[2010/08/15 23:05:32 | 000,456,800 | —- | M] (NCH Software) – C:\Users\elliebungo\Desktop\disketchsetup.exe
[2010/05/11 17:41:13 | 001,180,952 | —- | M] (DivX, Inc. ) – C:\Users\elliebungo\Desktop\DivXWebPlayerInstaller.exe
[2010/09/05 14:16:51 | 000,343,696 | —- | M] (Gameforge 4D ) – C:\Users\elliebungo\Desktop\Downloader_4Story_uk_3.3.26.exe
[2010/07/10 17:58:45 | 128,891,648 | —- | M] () – C:\Users\elliebungo\Desktop\dx7sdk.exe
[2010/08/16 20:56:34 | 001,609,432 | —- | M] () – C:\Users\elliebungo\Desktop\ezcdsetup.exe
[2010/03/30 22:12:23 | 000,000,000 | —- | M] () – C:\Users\elliebungo\Desktop\Firefox Setup 3.6.2.exe
[2010/10/21 20:36:47 | 016,074,528 | —- | M] (Sun Microsystems, Inc.) – C:\Users\elliebungo\Desktop\jre-6u22-windows-i586.exe
[2010/10/21 22:36:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\elliebungo\Desktop\OTL.exe
[2010/04/22 18:30:43 | 000,634,344 | —- | M] () – C:\Users\elliebungo\Desktop\radiobar_toolbar.exe
[2010/06/22 14:33:03 | 002,347,946 | —- | M] (Codemasters ) – C:\Users\elliebungo\Desktop\sevpatch.exe
[2010/07/22 16:24:20 | 000,138,176 | —- | M] () – C:\Users\elliebungo\Desktop\Shaiya_Install_US_20090508_csd.exe
[2009/04/21 23:02:24 | 001,079,296 | —- | M] (ADDPCs) – C:\Users\elliebungo\Desktop\tempCleaner.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-20 02:02:53
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:52B72A7C
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Warhammer Battle March:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Northern Ireland 3-2 Spain Euro 2008 Qualifier.avi:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Ibiza 2007.m3u:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\HardwareHelper:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Documents\Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\Revengance recordings:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\messin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\l_e945df51aa2a427196979d332ba6fa5b.png:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\Incomplete:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\elliebungo\Desktop\connally-assassination-2.jpg:Roxio EMC Stream
@Alternate Data Stream - 64 bytes -> C:\Users\elliebungo\Documents\Northern Ireland 3-2 Spain Euro 2008 Qualifier.avi:TOC.WMV
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:E7833B2E
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:3B360415
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CD30FA91
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AFFC859A
< End of report >