Okay, seems to have solved the issue.
I actually ran a quick scan before i did the full scan with Malwarebytes, so i'll include both logs.
Malwarebytes Log(s):
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
2010/10/31 02:40:54 PM
mbam-log-2010-10-31 (14-40-54).txt
Scan type: Quick scan
Objects scanned: 119149
Time elapsed: 6 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{k7t7807o-8f37-v7eu-7hu8-fosmjk02ov5f} (Generic.Bot.H) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Folders Infected:
C:\Windows\System32\Microsoft_KB57H43 (Trojan.Backdoor) -> Quarantined and deleted successfully.
Files Infected:
C:\Users\Admin\Desktop\YAAI.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\IELOGIN.abc (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Delete on reboot.
C:\Windows\System32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
2010/10/31 05:57:52 PM
mbam-log-2010-10-31 (17-57-52).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 292048
Time elapsed: 2 hour(s), 32 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\VritualRoot\account_generator.exe\HarddiskVolume2\Windows\System32\28463\AKV.exe (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.
C:\VritualRoot\account_generator.exe\HarddiskVolume2\Windows\System32\28463\LYIV.006 (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.
GMER Log:
GMER 1.0.15.15477 -
http://www.gmer.net
Rootkit scan 2010-11-03 18:17:48
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Admin\AppData\Local\Temp\awlcrpod.sys
—- Services - GMER 1.0.15 —-
Service system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys (*** hidden *** ) [SYSTEM] ovfsthifysemymjbksxgnuhtphivqpyppmratt <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@001d3b4a04c5 0xD7 0xBC 0x62 0x6A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247d4b43b3 0x3A 0x49 0x4F 0x0D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0023b479fd58 0x8E 0x29 0x0D 0x3B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@001ca462efbc 0xBF 0xDB 0xCE 0x3B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247db95c91 0x16 0xFF 0x54 0xD7 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0012d233506f 0xD8 0x5A 0x0B 0x66 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@002108dbc2ae 0xE9 0x66 0x13 0x7B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a80f386@0cddef0b143b 0x62 0x83 0xEE 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@imagepath \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@inst 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@ver icv190309
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cid 01
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@bid 3433472181-1097220164-287428032-609269875
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@aid 303350
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@sid 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cmddelay 14401
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthwblopfhrfwscxvrbkfwpkmrqtvpiegcj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthuvktjnxtiowespoiqafsaxmarcodknxo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthgavdhydwetxclwexvkpgcebwduxdywya.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAF 0xBF 0x99 0xCD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x52 0xC9 0xCD 0x62 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD4 0xA3 0x18 0x8A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3B 0x8E 0x4D 0x09 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x56 0xEA 0xCB 0x6D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE1 0xC5 0x4F 0x2F …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB5 0xD6 0x06 0xCB …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@001d3b4a04c5 0xD7 0xBC 0x62 0x6A …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247d4b43b3 0x3A 0x49 0x4F 0x0D …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0023b479fd58 0x8E 0x29 0x0D 0x3B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@001ca462efbc 0xBF 0xDB 0xCE 0x3B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@00247db95c91 0x16 0xFF 0x54 0xD7 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0012d233506f 0xD8 0x5A 0x0B 0x66 …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@002108dbc2ae 0xE9 0x66 0x13 0x7B …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000a3a80f386@0cddef0b143b 0x62 0x83 0xEE 0xFD …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@imagepath \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@ver icv190309
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@bid 3433472181-1097220164-287428032-609269875
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@aid 303350
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@sid 4
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main@cmddelay 14401
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthwblopfhrfwscxvrbkfwpkmrqtvpiegcj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\drivers\ovfsthpephxtpcclpuonmxwvwerxdunsyenrnm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthnfejfudcehqrvwovlddbrsitlmbhbsvx.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthuvktjnxtiowespoiqafsaxmarcodknxo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthgavdhydwetxclwexvkpgcebwduxdywya.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthifysemymjbksxgnuhtphivqpyppmratt\[removed] \systemroot\system32\ovfsthhpobrvcwfloyevtnwjtxgbdvgvbojqky.dat
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAF 0xBF 0x99 0xCD …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x52 0xC9 0xCD 0x62 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD4 0xA3 0x18 0x8A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x3B 0x8E 0x4D 0x09 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x56 0xEA 0xCB 0x6D …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE1 0xC5 0x4F 0x2F …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB5 0xD6 0x06 0xCB …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}@mabfmloflcpanelnpkdflnmhan 0x6F 0x61 0x61 0x64 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{393AA24A-B2E8-10DC-527E-1CCD3A1A9537}@abafjmhapchpldmcpomkkbdaadimdcgeid 0x69 0x61 0x70 0x66 …
—- EOF - GMER 1.0.15 —-
OTL Log:
OTL logfile created on: 2010/11/03 06:30:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Users\Admin\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001C09 | Country: South Africa | Language: ENS | Date Format: yyyy/MM/dd
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76.00 Gb Total Space | 16.62 Gb Free Space | 21.87% Space Free | Partition Type: NTFS
Drive D: | 213.30 Gb Total Space | 11.80 Gb Free Space | 5.53% Space Free | Partition Type: NTFS
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Users\Admin\Downloads\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO)
PRC - D:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe ()
PRC - D:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - D:\Program Files\Hide My IP\HideMyIpSrv.exe (HideMyIP)
PRC - d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Windows\System32\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
========== Modules (SafeList) ==========
MOD - D:\Users\Admin\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\guard32.dll (COMODO)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (cmdAgent) – D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (TuneUp.Defrag) – C:\Windows\System32\TuneUpDefragService.exe (TuneUp Software)
SRV - (TVersityMediaServer) – C:\Users\Admin\AppData\Local\TVersity\Media Server\MediaServer.exe ()
SRV - (HideMyIpSRV) – D:\Program Files\Hide My IP\HideMyIpSrv.exe (HideMyIP)
SRV - (MBAMService) – d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Stereo Service) – C:\Windows\System32\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (TestHandler) – C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe (Fujitsu Siemens Computers)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (pgfilter) – d:\Program Files\PeerGuardian2\pgfilter.sys File not found
DRV - (pbfilter) – d:\Program Files\PeerBlock\pbfilter.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (netr28u) – C:\Windows\System32\DRIVERS\netr28u.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (cpuz132) – C:\Users\Admin\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (btusbflt) – C:\Windows\System32\drivers\btusbflt.sys File not found
DRV - (BOCDRIVE) – D:\Program Files\Comodo\CBOClean\BOCDRIVE.sys File not found
DRV - (ATP) – C:\Windows\System32\DRIVERS\cmdatp.sys File not found
DRV - (inspect) – C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (cmderd) – C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdGuard.sys (COMODO)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (PSSDK42) – C:\Windows\System32\drivers\pssdk42.sys (microOLAP Technologies LTD)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (ahcix86s) – C:\Windows\system32\drivers\ahcix86s.sys (AMD Technologies Inc.)
DRV - (JRAID) – C:\Windows\system32\drivers\jraid.sys (JMicron Technology Corp.)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (btwrchid) – C:\Windows\System32\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (btwavdt) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwaudio) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "
http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-fp&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-fp"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-fp"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "search.yahoo.com"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.25
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:0.1.8
FF - prefs.js..extensions.enabledItems: [removed]:2.4.1
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12
FF - prefs.js..network.proxy.backup.ftp: "[removed]"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "[removed]"
FF - prefs.js..network.proxy.backup.gopher_port: 80
FF - prefs.js..network.proxy.backup.socks: "[removed]"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "[removed]"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.ssl: "[removed]"
FF - prefs.js..network.proxy.ssl_port: 80
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2010/08/19 15:07:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/11/01 19:55:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/11/01 19:55:26 | 000,000,000 | —D | M]
[2010/10/27 21:37:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2010/10/27 21:37:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/06/07 16:09:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/11/02 18:41:47 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions
[2010/10/17 19:37:22 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/08/27 10:34:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2010/09/17 14:48:24 | 000,000,000 | —D | M] (WOT) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/08/21 12:35:54 | 000,000,000 | —D | M] (wmlbrowser) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/09/14 19:28:41 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/10/09 17:12:45 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/08/18 19:01:03 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/10/25 18:57:56 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/29 07:34:50 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 20:36:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 10:25:27 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/25 20:11:36 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
[2010/10/27 20:36:20 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2890cvvj.default\extensions\[removed]
O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [COMODO Internet Security] D:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] d:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\HMIPCore.dll (My Privacy Tools, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.2
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/x-mrml {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\Common Files\A&W;\MidRadio.ocx (YAMAHA CORPORATION)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\AutoRun\command - "" = J:\smass\safemass.exe – File not found
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\explore\command - "" = J:\.\\\\smass\\\safemass.exe – File not found
O33 - MountPoints2\{335fede8-59e0-11de-b641-000a3a80f386}\Shell\open\command - "" = J:\smass\\\\\safemass.exe – File not found
O33 - MountPoints2\{4327e74b-843c-11df-a306-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{4327e74b-843c-11df-a306-000a3a80f386}\Shell\AutoRun\command - "" = M:\autorun.exe – File not found
O33 - MountPoints2\{69426cdc-7787-11de-aeaa-000a3a80f386}\Shell\AutoRun\command - "" = C:\Windows\System32\shell32.dll – [2010/07/26 18:55:26 | 011,581,440 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{7e3c19b4-95ad-11df-8727-000a3a80f386}\Shell\AutoRun\command - "" = L:\SANJA\radic.exe – File not found
O33 - MountPoints2\{7e3c19b4-95ad-11df-8727-000a3a80f386}\Shell\open\command - "" = L:\SANJA\radic.exe – File not found
O33 - MountPoints2\{7e3c19b7-95ad-11df-8727-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{7e3c19b7-95ad-11df-8727-000a3a80f386}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O33 - MountPoints2\{fe0b9b9f-7c53-11de-b546-000a3a80f386}\Shell - "" = AutoRun
O33 - MountPoints2\{fe0b9b9f-7c53-11de-b546-000a3a80f386}\Shell\AutoRun\command - "" = N:\Autorun.exe – File not found
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O34 - HKLM BootExecute: ("autocheck autochk *") - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/03 17:41:13 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\busdsl
[2010/11/03 12:21:24 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\umie work doc's
[2010/11/02 19:29:26 | 000,000,000 | —D | C] – C:\Program Files\CF3B5
[2010/11/02 10:24:39 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\110 Premium HD Wallpapers 1280 X 1024
[2010/10/31 19:53:12 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/10/31 13:55:05 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2010/10/31 13:54:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/31 13:54:58 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/31 13:54:57 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/10/31 13:21:48 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\New Folder
[2010/10/30 16:38:13 | 000,282,928 | —- | C] (My Privacy Tools, Inc.) – C:\Windows\System32\HMIPCore.dll
[2010/10/30 15:48:54 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/10/30 15:15:11 | 000,163,840 | —- | C] (My Privacy Tools, Inc.) – C:\Windows\System32\SecureNet.dll
[2010/10/30 14:50:48 | 000,485,920 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvusmb.exe
[2010/10/30 14:50:47 | 000,155,648 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\NVCOSMB.DLL
[2010/10/30 14:50:12 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\wallpapers
[2010/10/30 11:17:38 | 000,000,000 | —D | C] – C:\Hotspot Shield
[2010/10/28 19:34:19 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\Sorted Albums
[2010/10/26 16:54:17 | 000,000,000 | —D | C] – D:\Users\Admin\Videos\VirtualDJ
[2010/10/25 21:18:37 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Dropbox
[2010/10/25 18:58:13 | 000,000,000 | —D | C] – C:\Program Files\DVDVideoSoft
[2010/10/22 10:54:46 | 000,000,000 | —D | C] – C:\Program Files\TVersity Codec Pack
[2010/10/22 10:54:24 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\TVersity
[2010/10/21 15:26:23 | 000,000,000 | —D | C] – C:\ProgramData\Trusteer
[2010/10/21 11:19:18 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\nbt
[2010/10/20 19:43:14 | 000,000,000 | —D | C] – C:\Users\Admin\.microemulator
[2010/10/19 12:18:26 | 000,080,936 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwavdt.sys
[2010/10/19 12:18:26 | 000,016,168 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwrchid.sys
[2010/10/19 12:18:25 | 000,079,400 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwaudio.sys
[2010/10/19 12:18:21 | 000,233,472 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\BtwRSupport.dll
[2010/10/19 12:18:03 | 000,000,000 | —D | C] – C:\Windows\System32\es-MX
[2010/10/19 12:18:03 | 000,000,000 | —D | C] – C:\Windows\System32\es-AR
[2010/10/14 20:28:47 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\new house selected
[2010/10/14 11:38:41 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\masud uct
[2010/10/11 14:51:23 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\eU mixes
[2010/10/09 19:40:26 | 000,028,928 | —- | C] (TuneUp Software) – C:\Windows\System32\uxtuneup.dll
[2010/10/09 19:06:45 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/10/09 19:01:42 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/10/09 18:50:28 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2009
========== Files - Modified Within 30 Days ==========
[2010/11/03 18:28:53 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2010/11/03 18:28:49 | 000,013,999 | —- | M] () – C:\Users\Admin\Desktop\Okay.docx
[2010/11/03 18:28:31 | 000,002,465 | —- | M] () – C:\Users\Admin\Desktop\Microsoft Word 2007.lnk
[2010/11/03 18:19:25 | 000,031,871 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/03 18:19:14 | 000,000,508 | —- | M] () – C:\Windows\tasks\1-Click Maintenance.job
[2010/11/03 18:19:13 | 000,031,871 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/03 18:19:10 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/03 18:19:08 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 18:19:07 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/03 18:18:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/03 18:18:56 | 2012,397,568 | -HS- | M] () – C:\hiberfil.sys
[2010/11/03 17:17:36 | 000,006,604 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/11/03 16:50:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 11:00:21 | 000,051,514 | —- | M] () – C:\Users\Admin\Desktop\Composit assignment Nov 03 2010.docx
[2010/11/03 10:03:01 | 000,638,346 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/03 10:03:01 | 000,121,342 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/03 10:02:08 | 000,169,472 | —- | M] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/02 18:23:29 | 000,048,252 | —- | M] () – C:\Users\Admin\Desktop\Composit assignment Nov 2010 4-00.docx
[2010/11/02 15:59:50 | 000,000,162 | -H– | M] () – C:\Users\Admin\Desktop\~$mposit assignment Nov 2010 4-00.docx
[2010/11/02 14:27:42 | 000,046,692 | —- | M] () – D:\Users\Admin\Videos\Composit assignment Nov 2010.docx
[2010/11/01 07:23:45 | 003,742,272 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/31 19:53:15 | 000,000,810 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/10/31 13:56:12 | 000,000,620 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/30 18:55:54 | 000,000,258 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/10/30 16:38:01 | 000,000,588 | —- | M] () – C:\Users\Admin\Desktop\Hide My IP.lnk
[2010/10/30 15:32:45 | 000,062,993 | —- | M] () – C:\Users\Admin\AppData\Roaming\SQLite3.dll
[2010/10/30 11:03:19 | 000,000,600 | —- | M] () – C:\Users\Admin\PUTTY.RND
[2010/10/27 21:13:08 | 000,000,754 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/26 16:54:27 | 000,000,654 | —- | M] () – C:\Users\Admin\Desktop\Virtual DJ Pro.lnk
[2010/10/26 15:49:06 | 001,717,198 | —- | M] () – C:\Users\Admin\Desktop\Track 2.mp3
[2010/10/26 09:38:54 | 000,000,588 | —- | M] () – C:\Users\Admin\Desktop\Hide My MAC Address.lnk
[2010/10/26 09:07:44 | 000,000,606 | —- | M] () – C:\Users\Admin\Desktop\RAR Repair Tool.lnk
[2010/10/22 22:02:20 | 000,037,249 | —- | M] () – C:\Users\Admin\Desktop\grade 12 external exams.pdf
[2010/10/22 14:43:46 | 000,078,504 | —- | M] (COMODO) – C:\Windows\System32\drivers\inspect.sys
[2010/10/22 10:54:47 | 000,002,220 | —- | M] () – C:\Users\Admin\Desktop\TVersity.lnk
[2010/10/20 20:41:39 | 000,000,568 | —- | M] () – C:\Users\Admin\AppData\Roaming\AutoGK.ini
[2010/10/20 20:38:23 | 000,000,691 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC.lnk
[2010/10/20 19:43:59 | 000,000,008 | —- | M] () – C:\Users\Admin\AppData\Local\.mpid
[2010/10/19 16:00:08 | 000,294,912 | —- | M] () – C:\Users\Admin\Desktop\gmer.exe
[2010/10/19 15:43:09 | 000,022,046 | —- | M] () – C:\Users\Admin\Desktop\rap-rnb disc.nri
[2010/10/19 12:24:18 | 000,000,697 | —- | M] () – C:\Users\Admin\Desktop\IsoBuster.lnk
[2010/10/19 12:18:09 | 000,000,743 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2010/10/18 21:07:18 | 000,276,716 | —- | M] () – C:\Users\Admin\Desktop\30402EME2008.pdf
[2010/10/12 14:36:19 | 004,521,903 | —- | M] () – C:\Users\Admin\Desktop\Sound 1.mp3
[2010/10/12 06:54:57 | 000,074,703 | —- | M] () – C:\Windows\System32\mfc45.dll
[2010/10/11 16:05:42 | 003,001,054 | —- | M] () – C:\Users\Admin\Desktop\Sound 2.mp3
[2010/10/09 19:41:22 | 000,001,857 | —- | M] () – C:\Users\Admin\Desktop\TuneUp Utilities.lnk
[2010/10/09 19:41:22 | 000,001,849 | —- | M] () – C:\Users\Admin\Desktop\1-Click Maintenance.lnk
[2010/10/06 10:40:43 | 000,012,589 | —- | M] () – D:\Users\Admin\Videos\Sceanario Planning Summary Session 3.docx
[2010/10/05 21:40:35 | 000,001,038 | —- | M] () – C:\Users\Admin\Desktop\Free Studio.lnk
[2010/10/04 21:01:29 | 000,285,480 | —- | M] (COMODO) – C:\Windows\System32\guard32.dll
[2010/10/04 21:00:17 | 000,030,112 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmdhlp.sys
[2010/10/04 21:00:10 | 000,017,256 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmderd.sys
[2010/10/04 21:00:04 | 000,236,088 | —- | M] (COMODO) – C:\Windows\System32\drivers\cmdGuard.sys
========== Files Created - No Company Name ==========
[2010/11/03 18:28:48 | 000,013,999 | —- | C] () – C:\Users\Admin\Desktop\Okay.docx
[2010/11/03 18:18:56 | 2012,397,568 | -HS- | C] () – C:\hiberfil.sys
[2010/11/03 12:36:14 | 000,294,912 | —- | C] () – C:\Users\Admin\Desktop\gmer.exe
[2010/11/03 10:00:56 | 000,051,514 | —- | C] () – C:\Users\Admin\Desktop\Composit assignment Nov 03 2010.docx
[2010/11/02 15:59:50 | 000,000,162 | -H– | C] () – C:\Users\Admin\Desktop\~$mposit assignment Nov 2010 4-00.docx
[2010/11/02 15:59:49 | 000,048,252 | —- | C] () – C:\Users\Admin\Desktop\Composit assignment Nov 2010 4-00.docx
[2010/11/01 09:21:32 | 000,046,692 | —- | C] () – D:\Users\Admin\Videos\Composit assignment Nov 2010.docx
[2010/10/31 19:53:15 | 000,000,810 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/10/31 13:55:01 | 000,000,620 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/30 18:55:54 | 000,000,258 | —- | C] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/10/30 16:38:01 | 000,000,588 | —- | C] () – C:\Users\Admin\Desktop\Hide My IP.lnk
[2010/10/30 15:32:45 | 000,062,993 | —- | C] () – C:\Users\Admin\AppData\Roaming\SQLite3.dll
[2010/10/30 14:50:48 | 000,002,674 | —- | C] () – C:\Windows\System32\nvsmb.nvu
[2010/10/30 11:03:08 | 000,000,600 | —- | C] () – C:\Users\Admin\PUTTY.RND
[2010/10/26 16:54:27 | 000,000,654 | —- | C] () – C:\Users\Admin\Desktop\Virtual DJ Pro.lnk
[2010/10/26 09:38:54 | 000,000,588 | —- | C] () – C:\Users\Admin\Desktop\Hide My MAC Address.lnk
[2010/10/26 09:07:44 | 000,000,606 | —- | C] () – C:\Users\Admin\Desktop\RAR Repair Tool.lnk
[2010/10/22 22:02:17 | 000,037,249 | —- | C] () – C:\Users\Admin\Desktop\grade 12 external exams.pdf
[2010/10/22 11:12:00 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/10/22 10:54:47 | 000,002,220 | —- | C] () – C:\Users\Admin\Desktop\TVersity.lnk
[2010/10/20 20:38:23 | 000,000,691 | —- | C] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC.lnk
[2010/10/19 15:43:09 | 000,022,046 | —- | C] () – C:\Users\Admin\Desktop\rap-rnb disc.nri
[2010/10/19 12:32:17 | 001,717,198 | —- | C] () – C:\Users\Admin\Desktop\Track 2.mp3
[2010/10/19 12:24:18 | 000,000,697 | —- | C] () – C:\Users\Admin\Desktop\IsoBuster.lnk
[2010/10/18 21:07:13 | 000,276,716 | —- | C] () – C:\Users\Admin\Desktop\30402EME2008.pdf
[2010/10/17 21:21:07 | 000,000,008 | —- | C] () – C:\Users\Admin\AppData\Local\.mpid
[2010/10/13 18:06:10 | 000,000,829 | —- | C] () – C:\Users\Admin\Desktop\Revo Uninstaller.lnk
[2010/10/12 14:30:47 | 000,000,508 | —- | C] () – C:\Windows\tasks\1-Click Maintenance.job
[2010/10/12 06:54:57 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2010/10/11 16:05:48 | 004,521,903 | —- | C] () – C:\Users\Admin\Desktop\Sound 1.mp3
[2010/10/11 16:05:04 | 003,001,054 | —- | C] () – C:\Users\Admin\Desktop\Sound 2.mp3
[2010/10/09 19:41:22 | 000,001,857 | —- | C] () – C:\Users\Admin\Desktop\TuneUp Utilities.lnk
[2010/10/09 19:41:22 | 000,001,849 | —- | C] () – C:\Users\Admin\Desktop\1-Click Maintenance.lnk
[2010/10/06 10:08:20 | 000,012,589 | —- | C] () – D:\Users\Admin\Videos\Sceanario Planning Summary Session 3.docx
[2010/10/05 21:40:35 | 000,001,038 | —- | C] () – C:\Users\Admin\Desktop\Free Studio.lnk
[2010/09/02 11:26:05 | 000,395,776 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/09/02 11:26:05 | 000,262,144 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/09/02 11:26:04 | 002,255,360 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/09/02 11:26:04 | 000,112,640 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/08/23 16:23:54 | 000,819,200 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/08/23 16:23:54 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/23 12:20:03 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2010/08/23 11:52:37 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2010/08/20 08:19:08 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/07/30 20:58:53 | 000,014,324 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2010/07/30 17:26:09 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/07/29 17:08:53 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/06/10 06:31:04 | 000,089,088 | —- | C] () – C:\Windows\System32\nvimage.dll
[2009/05/17 17:01:04 | 000,000,064 | —- | C] () – C:\Users\Admin\AppData\Roaming\GPRSUAC.ini
[2009/04/14 14:17:21 | 000,001,024 | —- | C] () – C:\Users\Admin\AppData\Roaming\WavCodec.wff
[2009/04/13 11:37:18 | 000,002,554 | —- | C] () – C:\Windows\WAVEMIX.INI
[2009/04/13 11:37:18 | 000,000,165 | —- | C] () – C:\Windows\SimTower.ini
[2009/04/08 00:32:46 | 000,000,027 | —- | C] () – C:\Windows\System32\VideoGenieSetup.ini
[2009/03/26 18:24:44 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2009/03/15 20:33:09 | 000,000,025 | —- | C] () – C:\Windows\SIERRA.INI
[2009/03/15 20:32:22 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2009/03/15 20:32:22 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2009/03/15 20:32:22 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2009/03/10 09:45:01 | 000,000,568 | —- | C] () – C:\Users\Admin\AppData\Roaming\AutoGK.ini
[2009/02/08 19:30:05 | 000,001,722 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/02/08 14:31:26 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2009/02/07 21:02:03 | 000,169,472 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/30 18:09:32 | 000,031,871 | —- | C] () – C:\ProgramData\nvModes.001
[2009/01/30 18:09:29 | 000,031,871 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/01/17 16:56:11 | 000,006,596 | —- | C] () – C:\Users\Admin\AppData\Roaming\NMM-MetaData.db
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/04/25 16:23:38 | 000,012,288 | —- | C] () – C:\Windows\System32\EvOnlDiag.dll
[2007/08/14 16:35:24 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2007/03/29 23:00:40 | 000,203,264 | R— | C] () – C:\Windows\System32\CddbCdda.dll
[2006/11/02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2009/05/22 14:09:41 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Ableton
[2010/10/09 18:47:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Audacity
[2010/09/29 12:13:59 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/02/20 21:17:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2009/05/14 18:28:02 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\CoSoSys
[2009/07/30 12:28:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools
[2010/08/16 16:41:39 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2010/08/08 22:32:46 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DAEMON Tools Pro
[2010/10/25 21:37:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Dropbox
[2010/08/27 16:47:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Foxit Software
[2010/10/01 13:44:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GARMIN
[2010/08/18 19:00:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GrabPro
[2009/02/07 21:58:18 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\iWin
[2010/09/02 11:00:02 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\KC Softwares
[2010/08/18 19:18:09 | 000,000,000 | RHSD | M] – C:\Users\Admin\AppData\Roaming\licenses
[2010/10/19 20:01:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Mp3tag
[2010/09/11 12:17:37 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\NCH Swift Sound
[2009/01/17 16:56:11 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Nokia
[2009/02/02 00:48:35 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Nokia Multimedia Player
[2010/10/27 21:20:12 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Orbit
[2010/09/29 15:50:34 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PC Suite
[2010/07/30 20:58:52 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PeerNetworking
[2009/07/27 16:09:00 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PopCapv1002
[2009/04/13 12:02:53 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PopCapv1005eni
[2010/08/18 19:21:40 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ProgSense
[2009/07/02 22:13:32 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Publish Providers
[2010/06/25 13:29:26 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\RipIt4Me
[2010/06/26 20:01:28 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Sony
[2010/09/29 16:16:03 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2009/03/01 17:30:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Template
[2009/07/29 15:29:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\TuneUp Software
[2009/06/07 15:59:49 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Uniblue
[2009/04/09 20:31:45 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\VBA-M
[2010/11/03 18:19:14 | 000,000,508 | —- | M] () – C:\Windows\Tasks\1-Click Maintenance.job
[2010/11/03 17:17:37 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:343FF046
< End of report >
OTL Extras logfile created on: 2010/11/03 06:30:04 PM - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Users\Admin\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001C09 | Country: South Africa | Language: ENS | Date Format: yyyy/MM/dd
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 76.00 Gb Total Space | 16.62 Gb Free Space | 21.87% Space Free | Partition Type: NTFS
Drive D: | 213.30 Gb Total Space | 11.80 Gb Free Space | 5.53% Space Free | Partition Type: NTFS
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "D:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – D:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [TVersity] – "C:\Users\Admin\AppData\Local\TVersity\Media Server\GUILaunch.exe" -type "folder" -url "%1" -title "" -tags "" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"d:\Program Files\Orbitdownloader\orbitdm.exe" = d:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"d:\Program Files\Orbitdownloader\orbitnet.exe" = d:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010A52B5-1503-4AA2-815F-5E607C3182B3}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{017D5C4E-CA03-41DD-860A-795E5DA26E02}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0A008A25-8891-4ACB-9041-38FFC16E80ED}" = lport=10243 | protocol=6 | dir=in | app=system |
"{0F9B9839-9137-446F-A9B7-2A514D3A0F77}" = lport=2869 | protocol=6 | dir=in | app=system |
"{10DBC619-53BD-4DF2-9B01-BBCFFBFC789C}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{1B63DDA3-1A2D-49B0-8766-43851AB9596E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2174F2A4-642A-43D6-8F9D-4D169F02C918}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2B9C56EA-794B-46E2-AA1C-F00C9E68AB55}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{452BE090-F2C6-4659-98FB-00A8E9422F93}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{47078F47-9658-4FC2-A086-C189389C5A58}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{4AE81D53-3CF4-45E5-870E-37E270364CBB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5653D1A0-D88A-4393-9038-4AD95D37F5E3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6426DE85-DAD0-455C-B118-2BED2723C65B}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{68A34F69-A932-454F-8A33-CC2AA5F6B87E}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6F8E9CF7-18B0-41B8-BCE2-89083590906C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6F8EF1D7-6955-4900-AA84-38168108596D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8981149E-3C68-4A67-954F-FF0E33F389A5}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{8D280A15-B5B3-460D-87D0-BE16821219A2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9B3FABD1-85FE-4DCF-8265-74FCDD2B429C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A4CF896C-0CC7-4D63-BA47-0614CE23ABB5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ACD881DD-4A0B-4D85-A3D7-51625FCC9F17}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{B0816E85-E213-4057-AE5A-67F42D48D95C}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{BA00934C-7955-4F9D-AEDE-3F55C2DFD976}" = lport=6004 | protocol=17 | dir=in | app=d:\program files\microsoft office\office12\outlook.exe |
"{C30E763D-FE74-403E-952C-BAD4A80B2860}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C4F14115-DA3A-48AE-8857-277B341DE530}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D23FACA4-D971-4F8D-8B44-64D330EAD1E0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D39BC4AA-56FD-4FC6-A51F-AF30FB55598A}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{DD380062-A053-42C5-99A1-9F132D7BDF0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E6CE22DD-5C59-463F-AE3C-C92DE6212302}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F61D9B4F-0B2B-4864-A762-C8CFC7DF0234}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A0E047-B5B9-42F9-B586-EE0C2274D1EB}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\~os5a12.tmp\rlvknlg.exe |
"{029CE5DC-7A35-4447-A56B-EB9DC5A99E99}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{03537E98-9783-40F1-B476-9CCAEC1B3A68}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0A5F7222-FBC8-481A-A5D5-FEE2177C8896}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{126BDA01-BA2F-4061-A10A-1C57ED2F01F5}" = dir=in | app=c:\program files\electronic arts\command & conquer 3\retailexe\1.0\cnc3game.dat |
"{2005C06F-60B1-4C9A-962C-9F45228A8873}" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{25A1EFBE-D4FC-4DAC-A655-DFCA19BFDB6D}" = protocol=6 | dir=in | app=d:\program files\itunes\itunes.exe |
"{26ECF40B-82E5-443F-BEDC-8BAC721ABA6E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3006944B-54E4-40CD-9830-CEE31FFB4D15}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{35A42432-7F65-49AC-A2B9-DA71C4BFBC96}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{4072CBC3-219B-48F1-986A-EE0B8B9239B2}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{4415E845-9CA6-4D18-9266-3BA536280DC2}" = protocol=6 | dir=out | app=system |
"{4F998EC3-2A7C-4904-A610-65C504F81622}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{541E312B-AEF2-4FD2-97B2-E1A5A207CA27}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6A032606-225E-4A43-B7E2-C642A2358E47}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{6DB07A9D-E782-41FF-B19C-F9445A11703A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6E739134-2248-4FA4-8BCC-36C440DB5FD8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6FC9AE88-960C-4EBB-BCE5-6F141210439E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7069E2B6-8352-416D-87ED-709CA9849A34}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\tversity\media server\mediaserver.exe |
"{7674B8CD-F682-47E4-8999-873E3636FF49}" = protocol=17 | dir=in | app=d:\program files\frostwire\frostwire.exe |
"{7B3CB058-9691-472B-AFBB-230D015A24FE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{838D9553-86CD-4738-A5D7-AA4B019B602E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{840EEC3F-0A35-4929-B7ED-708730FF6937}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{86B3841E-2652-4BB7-9237-782607E2C6E0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8E47882E-7CF6-4D0D-90D9-6D7FFFB595C7}" = protocol=6 | dir=in | app=d:\program files\frostwire\frostwire.exe |
"{96BBADAB-C5D9-40C2-B254-889552C09158}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97B8D886-42E1-4246-8161-8AA5F84472BC}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe |
"{C8BDA7FC-2AC9-45A2-AD09-31397D4B9577}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{C90AECF4-C33C-46FC-955B-357DA0DB2F36}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E564E0D1-864C-48E6-9BB8-732BA4D521D1}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\tversity\media server\mediaserver.exe |
"{E5FF1FDB-31CD-4F95-B890-48069197D8B7}" = protocol=17 | dir=in | app=d:\program files\itunes\itunes.exe |
"{EFD21019-2202-4D16-8FDC-422D8E886BF3}" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege 2\dungeonsiege2.exe |
"{F257C99D-AB14-48B5-9967-4362E13BD162}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{2365559B-0531-4C5F-9670-9507BCB2B065}D:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"TCP Query User{50511DC7-1528-4F94-918F-7B22B62917EB}D:\program files\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=d:\program files\musicbrainz picard\picard.exe |
"TCP Query User{AB404709-E06A-4B91-A4E8-0E876823CE76}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{AED02F83-EBE6-442E-9B8D-7286FE321D91}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B48F2A79-14B8-41E0-845C-1991919EF0D8}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{CD3FE4EC-9075-402B-8763-D85C377ED227}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{ECA21325-0323-4D3D-9BE3-21A46AFCA332}D:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"TCP Query User{F4F9F111-B42E-4E19-AA8E-A754259B4ADA}D:\program files\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=d:\program files\dc++\dcplusplus.exe |
"UDP Query User{0056195B-A82C-407E-AC67-0134B392F466}D:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"UDP Query User{11F4DC77-DEE8-424B-A07B-81EA25982F53}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{4DA5C8C4-6D74-45A7-AC89-7BB4F52499CA}D:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=d:\program files\mozilla firefox\firefox.exe |
"UDP Query User{653A51B3-489F-4D9B-903F-875728F72526}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{B3775C90-0D11-4570-AEC0-4086289119CF}D:\program files\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=d:\program files\musicbrainz picard\picard.exe |
"UDP Query User{B6B997EB-C274-457B-9AB5-BD104477C142}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{C5F21D4E-B0C6-4DC7-B293-26AFA891EE0B}D:\program files\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=d:\program files\dc++\dcplusplus.exe |
"UDP Query User{F7689D61-C6A2-4475-887A-705AB0C9DD0D}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5400
"{06680048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Standard 2006
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2A0A6470-FD0F-4F45-9B11-85F3167DB943}" = Nokia Flashing Cable Driver
"{2F926AE7-9FB7-4B34-906F-9C29A6D146A7}" = SystemDiagnostics
"{373C3C97-2FA9-4E18-85A2-255060C21033}" = Nero 8 Essentials
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{60B8D26D-5D6D-21D5-0366-3664E5DE3471}" = ATI Catalyst Install Manager
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6CDC68BB-C997-4ADC-9BA0-6293FB88521E}" = Sonic Foundry Sound Forge 6.0a
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BE2669E-2BD8-4164-A8B5-C904C864B403}" = WA Update v3.50 beta2
"{9C05FA75-0337-4523-AA57-9D3511018887}" = Nokia PC Suite
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A563C4F4-BE36-4956-BA0B-E02BDD9F70D5}" = Dungeon Siege 2 Broken World
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFC454ED-A26F-4816-826B-C35129D82E1F}" = Fujitsu Siemens Computers Recovery
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B132E67C-EEA5-492B-B368-543CD88D8569}" = AnyDVD Registration
"{B6AA55E6-9228-4392-A19E-593339BC1BE1}" = Garmin ANT Agent
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBDE9C7D-CF52-4558-B23E-B66359CB586A}" = Nokia Connectivity Cable Driver
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DFBABF95-AB6F-4843-BEEE-B6560F355BC2}" = Billion 400G
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE4086E1-FA7F-4A7A-8FC5-061337B5787E}" = PS3.ProxyServer
"24DA573F901348FFDFF7717497830D45BE0C362E" = Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2)
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AutoGK" = Auto Gordian Knot 2.55
"AviSynth" = AviSynth 2.5
"CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A" = Windows Driver Package - Nokia Modem (03/05/2008 3.7)
"CCleaner" = CCleaner
"ClassicPro" = ClassicPro© v1.15
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DMX5_is1" = DriverMax 5
"DungeonSiege2" = Dungeon Siege 2
"DVD Shrink_is1" = DVD Shrink 3.2
"E092B2EBF2FFE83E896F8F7F829A7B5D7D1B2F9D" = Windows Driver Package - Nokia Modem (03/13/2008 6.86.0.1)
"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)
"ExpressBurn" = Express Burn Disc Burning Software
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FL Studio 7" = FL Studio 7
"Foxit Reader" = Foxit Reader
"Free DVD Video Burner_is1" = Free DVD Video Burner version 2.4
"Free Video to DVD Converter_is1" = Free Video to DVD Converter version 1.6
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 4.0
"Hide My MAC Address_is1" = Hide My MAC Address 2.2
"HMIP50_is1" = Hide My IP 5.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IsoBuster_is1" = IsoBuster 2.8
"KC Softwares SUMo_is1" = KC Softwares SUMo
"LameACM" = Lame ACM MP3 Codec
"Live 7.0.14" = Live 7.0.14
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MixMeister BPM Analyzer_is1" = MixMeister BPM Analyzer 1.0
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"Mp3tag" = Mp3tag v2.46a
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Orbit_is1" = Orbit Downloader
"PROHYBRIDR" = 2007 Microsoft Office system
"RAR Repair Tool_is1" = RAR Repair Tool v.4.0
"RealAlt_is1" = Real Alternative 2.0.2 Lite
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Revo Uninstaller" = Revo Uninstaller 1.89
"Shockwave" = Shockwave
"Switch" = Switch Sound File Converter
"TVersity Codec Pack" = TVersity Codec Pack 1.4
"TVersity Media Server" = TVersity Media Server 1.9.2
"Uninstall_is1" = Uninstall 1.0.0.1
"Virtual DJ Pro Full - Atomix Productions" = Virtual DJ Pro Full - Atomix Productions
"VLC media player" = VLC media player 1.1.3
"VobSub" = VobSub v2.23 (Remove Only)
"Winamp" = Winamp
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Xvid_is1" = Xvid 1.2.2 final uninstall
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"419506f87bc706d3" = MXit EVO
"Billion 400G" = Billion 400G
"Dropbox" = Dropbox
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"mpowerplayer" = mpowerplayer
"Prism" = Prism Video File Converter
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2010/11/02 04:20:11 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:20:39 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:21:11 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:21:33 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:31:31 AM | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
Error - 2010/11/02 04:33:34 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:34:46 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 04:36:03 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 08:09:10 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
Error - 2010/11/02 08:53:26 AM | Computer Name = Admin-PC | Source = RasClient | ID = 20227
Description =
[ OSession Events ]
Error - 2009/02/09 02:24:04 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 44
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 11:19:39 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 11:19:46 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 12:19:01 PM | Computer Name = Admin-PC | Source = HTTP | ID = 15016
Description =
Error - 2010/11/03 12:19:14 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 2010/11/03 12:20:38 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 2010/11/03 12:21:09 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 12:21:15 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 2010/11/03 12:21:18 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7001
Description =
< End of report >
Whoa. A plethora of information up there
