Thank you for the reply! Here are the logs you asked for.
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-12-27 16:01:07
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1637GSX rev.DL030M
Running: s3jb5ryb.exe; Driver: C:\Users\KIKIWI~1\AppData\Local\Temp\kglirkod.sys
—- System - GMER 1.0.15 —-
INT 0x52 ? 86340BF8
INT 0x72 ? 86340BF8
INT 0x72 ? 86340BF8
INT 0x92 ? 84A30BF8
INT 0xA2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB2 ? 84A30BF8
INT 0xB3 ? 86340BF8
—- Kernel code sections - GMER 1.0.15 —-
? System32\Drivers\spsw.sys The system cannot find the path specified. !
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8F406000, 0x205494, 0xE8000020]
.text USBPORT.SYS!DllUnload 8FF6F41B 5 Bytes JMP 863401D8
.text acv11a1z.SYS 8B17D000 22 Bytes [82, 53, 1C, 82, 6C, 52, 1C, …]
.text acv11a1z.SYS 8B17D017 181 Bytes [00, 32, 07, F0, 8A, 3D, 05, …]
.text acv11a1z.SYS 8B17D0CE 73 Bytes [00, 00, 00, 00, 01, C2, 03, …]
.text acv11a1z.SYS 8B17D118 185 Bytes [3F, 48, 3E, 8A, 3C, CC, 3D, …]
.text acv11a1z.SYS 8B17D1D2 22 Bytes [E0, C2, E2, 84, E3, 46, E6, …]
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\Windows\Explorer.EXE[3352] kernel32.dll!CreateProcessW 76CE1BF3 6 Bytes JMP 5F0D0F5A
.text C:\Windows\Explorer.EXE[3352] kernel32.dll!CreateProcessA 76CE1C28 6 Bytes JMP 5F0A0F5A
.text C:\Windows\Explorer.EXE[3352] kernel32.dll!LoadLibraryExW 76D09109 6 Bytes JMP 5F070F5A
.text C:\Windows\Explorer.EXE[3352] ADVAPI32.dll!CreateProcessAsUserW 77011EE9 6 Bytes JMP 5F100F5A
.text C:\Windows\Explorer.EXE[3352] ADVAPI32.dll!CreateProcessWithLogonW 770580C1 6 Bytes JMP 5F040F5A
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 853C41F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 84A321F8
Device \Driver\usbohci \Device\USBPDO-0 863481F8
Device \Driver\sptd \Device\2152195219 spsw.sys
Device \Driver\usbohci \Device\USBPDO-1 863481F8
Device \Driver\usbohci \Device\USBPDO-2 863481F8
Device \Driver\usbohci \Device\USBPDO-3 863481F8
Device \Driver\usbohci \Device\USBPDO-4 863481F8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbehci \Device\USBPDO-5 8633F1F8
Device \Driver\volmgr \Device\HarddiskVolume1 84A321F8
Device \Driver\volmgr \Device\HarddiskVolume2 84A321F8
Device \Driver\cdrom \Device\CdRom0 8633E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 853C31F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3 853C31F8
Device \Driver\atapi \Device\Ide\IdePort0 853C31F8
Device \Driver\atapi \Device\Ide\IdePort1 853C31F8
Device \Driver\atapi \Device\Ide\IdePort2 853C31F8
Device \Driver\atapi \Device\Ide\IdePort3 853C31F8
Device \Driver\cdrom \Device\CdRom1 8633E1F8
Device \Driver\cdrom \Device\CdRom2 8633E1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 86B85500
Device \Driver\Smb \Device\NetbiosSmb 86D20500
Device \Driver\PCI_PNP7201 \Device\0000004e spsw.sys
Device \Driver\iScsiPrt \Device\RaidPort0 863C31F8
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\netbt \Device\NetBT_Tcpip_{940AB514-CF60-4CF9-A04B-5887F4D92A41} 86B85500
Device \Driver\usbohci \Device\USBFDO-0 863481F8
Device \Driver\usbohci \Device\USBFDO-1 863481F8
Device \Driver\usbohci \Device\USBFDO-2 863481F8
Device \Driver\netbt \Device\NetBT_Tcpip_{A4F030BC-DB9B-4FAF-8BB5-6940A10227D9} 86B85500
Device \Driver\usbohci \Device\USBFDO-3 863481F8
Device \Driver\usbohci \Device\USBFDO-4 863481F8
Device \Driver\usbehci \Device\USBFDO-5 8633F1F8
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1Port5Path0Target1Lun0 863C0500
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1Port5Path0Target0Lun0 863C0500
Device \Driver\acv11a1z \Device\Scsi\acv11a1z1 863C0500
Device \FileSystem\cdfs \Cdfs 85C3C1F8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x14 0x82 0x43 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x73 0xD7 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0x2D 0x94 0x15 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x8D 0x07 0x0B …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x14 0x82 0x43 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD1 0x73 0xD7 0xFD …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0x2D 0x94 0x15 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x8D 0x07 0x0B …
—- Files - GMER 1.0.15 —-
File C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ILBVJL5\blogger[1].htm 0 bytes
File C:\Users\Kiki Wiki\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ILBVJL5\navbar[2].g 0 bytes
—- EOF - GMER 1.0.15 —-
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: TOSHIBA
BIOS Manufacturer: TOSHIBA
System Manufacturer: TOSHIBA
System Product Name: Satellite A215
Logical Drives Mask: 0x0000003c
Kernel Drivers (total 150):
0x81E05000 \SystemRoot\system32\ntkrnlpa.exe
0x821BE000 \SystemRoot\system32\hal.dll
0x8060C000 \SystemRoot\system32\kdcom.dll
0x80613000 \SystemRoot\system32\PSHED.dll
0x80624000 \SystemRoot\system32\BOOTVID.dll
0x8062C000 \SystemRoot\system32\CLFS.SYS
0x8066D000 \SystemRoot\system32\CI.dll
0x8074D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x807C9000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8AE02000 \SystemRoot\System32\Drivers\spsw.sys
0x8AEF5000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8AEFE000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x8AF24000 \SystemRoot\system32\drivers\acpi.sys
0x8AF6A000 \SystemRoot\system32\drivers\msisadrv.sys
0x8AF72000 \SystemRoot\system32\drivers\pci.sys
0x8AF99000 \SystemRoot\System32\drivers\partmgr.sys
0x8AFA8000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8AFAB000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8AFB5000 \SystemRoot\system32\drivers\volmgr.sys
0x8B007000 \SystemRoot\System32\drivers\volmgrx.sys
0x8B051000 \SystemRoot\system32\drivers\pciide.sys
0x8B058000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8B066000 \SystemRoot\system32\DRIVERS\pcmcia.sys
0x8B093000 \SystemRoot\System32\drivers\mountmgr.sys
0x8B0A3000 \SystemRoot\system32\drivers\atapi.sys
0x8B0AB000 \SystemRoot\system32\drivers\ataport.SYS
0x8B0C9000 \SystemRoot\system32\drivers\fltmgr.sys
0x8B0FB000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B10B000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B206000 \SystemRoot\system32\drivers\ndis.sys
0x8B311000 \SystemRoot\system32\drivers\msrpc.sys
0x8B33C000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B40C000 \SystemRoot\System32\drivers\tcpip.sys
0x8B4F6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8B607000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B717000 \SystemRoot\system32\drivers\volsnap.sys
0x8B750000 \SystemRoot\system32\DRIVERS\TVALZ_O.SYS
0x8B755000 \SystemRoot\System32\Drivers\spldr.sys
0x8B75D000 \SystemRoot\System32\Drivers\mup.sys
0x8B76C000 \SystemRoot\System32\drivers\ecache.sys
0x8B793000 \SystemRoot\system32\drivers\disk.sys
0x8B7A4000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B7C5000 \SystemRoot\system32\drivers\crcdisk.sys
0x8B7DB000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8B7E4000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x8F405000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x8F918000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F9B9000 \SystemRoot\System32\drivers\watchdog.sys
0x8B511000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x8FE06000 \SystemRoot\system32\DRIVERS\athr.sys
0x8FF35000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8FF3F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8FF7D000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8FF8C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8FFA4000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8B552000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8FFAA000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8FFBD000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8FFC8000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8FFFA000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F9C5000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8FFFC000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8F9D0000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8F9E0000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8B377000 \SystemRoot\system32\drivers\tifm21.sys
0x8B5DF000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8B17C000 \SystemRoot\System32\Drivers\acv11a1z.SYS
0x8F9EE000 \SystemRoot\system32\DRIVERS\dfmirage.sys
0x8B3C4000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0x8FE00000 \SystemRoot\system32\DRIVERS\wacomvhid.sys
0x8B3E5000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F9F5000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8AFC4000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x9040D000 \SystemRoot\system32\DRIVERS\storport.sys
0x9044E000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x90459000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x90470000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x9047B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x9049E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x904AD000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x904C1000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x904D6000 \SystemRoot\system32\DRIVERS\termdd.sys
0x904E6000 \SystemRoot\system32\DRIVERS\swenum.sys
0x904E8000 \SystemRoot\system32\DRIVERS\ks.sys
0x90512000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x9051C000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90529000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x9055E000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x90566000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys
0x9056E000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x90805000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x90921000 \SystemRoot\system32\drivers\modem.sys
0x90A02000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90D15000 \SystemRoot\system32\drivers\portcls.sys
0x90D42000 \SystemRoot\system32\drivers\drmk.sys
0x90D67000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x90D70000 \SystemRoot\System32\Drivers\Null.SYS
0x90D77000 \SystemRoot\System32\Drivers\Beep.SYS
0x90D7E000 \SystemRoot\System32\drivers\vga.sys
0x90D8A000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90D92000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90D9A000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90DA5000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90DB3000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90DBC000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90DD2000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90DDD000 \SystemRoot\system32\DRIVERS\smb.sys
0x9092E000 \SystemRoot\system32\drivers\afd.sys
0x90DF1000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x90976000 \SystemRoot\System32\DRIVERS\netbt.sys
0x909A8000 \SystemRoot\system32\DRIVERS\pacer.sys
0x909BE000 \SystemRoot\system32\DRIVERS\netbios.sys
0x909CC000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x9057F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90DF6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x909DF000 \??\C:\Windows\system32\drivers\elrawdsk.sys
0x909E3000 \SystemRoot\System32\Drivers\dfsc.sys
0x905BB000 \SystemRoot\System32\Drivers\aswSP.SYS
0x99050000 \SystemRoot\System32\win32k.sys
0x905E9000 \SystemRoot\System32\drivers\Dxapi.sys
0x8B1E4000 \SystemRoot\system32\DRIVERS\monitor.sys
0x99270000 \SystemRoot\System32\TSDDD.dll
0x99290000 \SystemRoot\System32\cdd.dll
0x992A0000 \SystemRoot\System32\ATMFD.DLL
0x807D6000 \SystemRoot\system32\drivers\luafv.sys
0x9BC0F000 \SystemRoot\system32\DRIVERS\aswMonFlt.sys
0x9BC26000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x9BC31000 \SystemRoot\system32\drivers\spsys.sys
0x9BCE1000 \SystemRoot\system32\DRIVERS\AegisP.sys
0x9BCE5000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9BCF5000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9BD1F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9BD29000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9BD3C000 \SystemRoot\system32\drivers\HTTP.sys
0x9BDA9000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9BDC6000 \SystemRoot\system32\DRIVERS\bowser.sys
0x9BDDF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9F201000 \SystemRoot\system32\drivers\mrxdav.sys
0x9F222000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9F241000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9F27A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9F292000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9F2BA000 \SystemRoot\System32\DRIVERS\srv.sys
0x9F320000 \SystemRoot\system32\drivers\peauth.sys
0x9F308000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9F312000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9BDF4000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xCA80F000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xCA825000 \??\C:\Users\KIKIWI~1\AppData\Local\Temp\kglirkod.sys
0x77510000 \Windows\System32\ntdll.dll
Processes (total 67):
0 System Idle Process
4 System
488 C:\Windows\System32\smss.exe
556 csrss.exe
616 C:\Windows\System32\wininit.exe
628 csrss.exe
660 C:\Windows\System32\services.exe
672 C:\Windows\System32\lsass.exe
684 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\winlogon.exe
864 C:\Windows\System32\svchost.exe
936 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\Ati2evxx.exe
1056 C:\Windows\System32\svchost.exe
1092 C:\Windows\System32\svchost.exe
1108 C:\Windows\System32\svchost.exe
1216 C:\Windows\System32\audiodg.exe
1240 C:\Windows\System32\svchost.exe
1264 C:\Windows\System32\SLsvc.exe
1308 C:\Windows\System32\svchost.exe
1408 C:\Windows\System32\Ati2evxx.exe
1480 C:\Program Files\WTouch\WTouchService.exe
1532 C:\Windows\System32\wisptis.exe
1540 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
1700 C:\Windows\System32\svchost.exe
1848 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
340 C:\Windows\System32\taskeng.exe
372 C:\Windows\System32\spoolsv.exe
512 C:\Windows\System32\svchost.exe
856 C:\Windows\System32\rundll32.exe
780 C:\Windows\System32\agrsmsvc.exe
2060 C:\Windows\System32\svchost.exe
2080 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
2096 C:\Program Files\Bonjour\mDNSResponder.exe
2184 C:\Program Files\IObit\IObit Security 360\is360srv.exe
2260 C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
2312 C:\Windows\System32\svchost.exe
2328 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2372 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2412 C:\Windows\System32\svchost.exe
2456 C:\Windows\System32\Pen_Tablet.exe
2508 C:\Windows\System32\svchost.exe
2548 C:\Windows\System32\SearchIndexer.exe
3328 C:\Program Files\Alwil Software\Avast5\Setup\avast.setup
888 C:\Windows\System32\dwm.exe
1400 C:\Windows\System32\wisptis.exe
1620 C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
3352 C:\Windows\explorer.exe
3488 C:\Windows\System32\taskeng.exe
3744 C:\Windows\System32\WTablet\Pen_TabletUser.exe
1996 C:\Windows\System32\Pen_Tablet.exe
2140 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3908 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
4084 C:\Program Files\NETGEAR\WG111T\wlan111t.exe
3372 C:\Program Files\Windows Media Player\wmpnscfg.exe
1040 C:\Windows\System32\wbem\unsecapp.exe
2668 WmiPrvSE.exe
4988 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
5240 C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
2996 C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe
6080 C:\Program Files\WTouch\WTouchUser.exe
4400 C:\Windows\System32\SearchProtocolHost.exe
2700 C:\Windows\System32\SearchFilterHost.exe
1596 C:\Windows\System32\notepad.exe
2120 C:\Program Files\Mozilla Firefox\firefox.exe
4684 C:\Program Files\Mozilla Firefox\plugin-container.exe
4424 C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)
PhysicalDrive0 Model Number: TOSHIBAMK1637GSX, Rev: DL030M
Size Device Name MBR Status
——————————————–
149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
OTL logfile created on: 12/27/2010 4:07:08 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 55.21 Gb Free Space | 37.41% Space Free | Partition Type: NTFS
Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe (Windows ® Codename Longhorn DDK provider)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files\WTouch\WTouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Alwil Software\Avast5\Setup\avast.setup (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Windows\System32\wisptis.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
========== Modules (SafeList) ==========
MOD - C:\Users\Kiki Wiki\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (TipCtrl) – C:\Program Files\uTIPu\TipCtrl.exe File not found
SRV - (Akamai) – C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll ()
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (IS360service) – C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV - (TabletServicePen) – C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
========== Driver Services (SafeList) ==========
DRV - (XDva296) – C:\Windows\System32\XDva296.sys File not found
DRV - (XDva285) – C:\Windows\System32\XDva285.sys File not found
DRV - (XDva277) – C:\Windows\System32\XDva277.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (wacmoumonitor) – C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (RsFx0103) – C:\Windows\System32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\elrawdsk.sys (EldoS Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (dfmirage) – C:\Windows\System32\drivers\dfmirage.sys (DemoForge, LLC)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (AR5523) – C:\Windows\System32\drivers\WG11TND5.sys (NETGEAR, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 91 DF 33 37 A1 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.87
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\Firefox [2010/12/03 21:53:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/12/03 21:53:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/21 20:42:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/21 20:42:16 | 000,000,000 | —D | M]
[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions
[2010/06/22 13:57:06 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/26 15:53:43 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions
[2010/11/03 20:32:23 | 000,000,000 | —D | M] (FireShot) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2010/04/26 19:00:57 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/11 08:58:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/12/23 09:15:11 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/12/11 12:28:28 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/16 00:06:51 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\extensions\[removed]
[2010/12/24 12:28:48 | 000,001,820 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\bing.xml
[2010/09/02 20:51:39 | 000,002,059 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\searchplugins\daemon-search.xml
[2010/12/24 12:29:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/03 19:09:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/04 12:15:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/28 09:37:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/24 23:02:40 | 000,098,304 | —- | M] (OGPlanet Inc.) – C:\Program Files\Mozilla Firefox\plugins\npOGPPlugin.dll
O1 HOSTS File: ([2010/12/25 20:52:45 | 000,428,340 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14749 more lines…
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [JP595IR86O] C:\Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe (Windows ® Codename Longhorn DDK provider)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9}
http://www.latale.com/Launcher/ActozWebLauncher.cab (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Reg Error: Value error.)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F}
http://www.yoyogames.com/downloads/activex/YoYo.cab (YYGInstantPlay Control)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{512a183b-b7c1-11df-947b-0016d4fe31a5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell - "" = AutoRun
O33 - MountPoints2\{685596cf-1044-11df-b409-0016d4fe31a5}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c62d17cc-5fc6-11de-b885-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/12/27 16:03:54 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/26 17:58:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:21 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/12/25 20:48:56 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:48:56 | 000,056,400 | —- | C] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 11:50:00 | 001,912,872 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 11:10:37 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\TMRBLog
[2010/12/25 11:09:42 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\log
[2010/12/25 11:09:35 | 002,486,352 | —- | C] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/12/25 10:09:40 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Apps
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/12/24 15:20:17 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/12/24 11:31:25 | 000,098,392 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/24 11:27:43 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\AppData\Local\Sunbelt Software
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/12/24 11:26:12 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/12/23 09:48:49 | 000,241,664 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/16 13:10:27 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/12/16 13:02:10 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2010/12/16 12:45:53 | 000,000,000 | —D | C] – C:\Users\Kiki Wiki\Desktop\Adobe CS5
[2010/12/16 11:45:30 | 001,228,400 | —- | C] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 11:41:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Akamai
[2010/12/14 15:03:23 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/14 15:02:42 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/14 15:02:26 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/14 15:02:15 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/12/14 15:02:13 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/12/14 15:02:13 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/14 15:02:13 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/14 15:02:13 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/14 15:02:12 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/14 15:02:12 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/14 15:02:11 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/14 15:02:11 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/14 15:02:11 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/12/14 15:02:11 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/12/14 15:02:11 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/12/14 15:02:11 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/12/14 15:02:11 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/14 15:02:11 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/14 15:02:11 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/14 15:02:06 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/14 15:02:06 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/14 15:02:06 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/14 15:00:37 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/14 15:00:35 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/14 15:00:35 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/14 14:59:11 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/03 21:53:12 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/11/29 17:38:30 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/11/28 10:30:38 | 000,089,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SQSRVRES.DLL
[2010/11/28 10:30:38 | 000,072,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perf-MSSQL$SQLEXPRESS-sqlctr10.2.4000.0.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/27 16:03:54 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Kiki Wiki\Desktop\OTL.exe
[2010/12/27 16:02:25 | 000,080,384 | —- | M] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 16:00:50 | 000,000,300 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/27 15:47:53 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 15:47:53 | 000,004,160 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/27 14:10:31 | 000,296,448 | —- | M] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/27 14:04:41 | 000,000,378 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2010/12/27 11:47:58 | 000,000,312 | -HS- | M] () – C:\Windows\tasks\lwmcdovil.job
[2010/12/27 11:47:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/27 11:47:47 | 3621,830,656 | -HS- | M] () – C:\hiberfil.sys
[2010/12/26 17:59:00 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HijackThis.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:52:45 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/12/25 20:50:17 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys
[2010/12/25 20:50:17 | 000,056,400 | —- | M] (trend_company_name) – C:\Windows\System32\drivers\tmrkb.sys
[2010/12/25 17:34:14 | 000,007,268 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2010/12/25 11:50:09 | 001,912,872 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\HousecallLauncher.exe
[2010/12/25 10:23:21 | 000,000,036 | —- | M] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2010/12/25 09:40:20 | 000,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2010/12/24 19:36:06 | 003,630,896 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/24 19:31:07 | 000,000,118 | —- | M] () – C:\Windows\wininit.ini
[2010/12/24 19:23:24 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101225-205245.backup
[2010/12/24 17:53:58 | 000,000,139 | —- | M] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:37:09 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-192324.backup
[2010/12/24 15:36:34 | 000,428,340 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20101224-153709.backup
[2010/12/24 15:20:32 | 000,001,050 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | M] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/24 11:31:25 | 000,098,392 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/12/23 09:48:38 | 000,241,664 | —- | M] (Windows ® Codename Longhorn DDK provider) – C:\Windows\Wbegua.exe
[2010/12/23 09:48:38 | 000,061,440 | RHS- | M] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:15:18 | 000,000,872 | —- | M] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | M] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/22 18:23:37 | 000,000,132 | —- | M] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/21 21:28:22 | 000,000,629 | —- | M] () – C:\Windows\System32\mapisvc.inf
[2010/12/21 20:53:44 | 000,001,635 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 14:31:19 | 000,705,454 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/16 14:31:19 | 000,142,764 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/16 12:45:39 | 001,228,400 | —- | M] (Adobe Systems Incorporated) – C:\Users\Kiki Wiki\Photoshop_12_LS1.exe
[2010/12/16 12:45:35 | 1026,293,791 | —- | M] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | M] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/12/07 18:05:04 | 002,486,352 | —- | M] (Trend Micro Inc.) – C:\Users\Kiki Wiki\Desktop\RootkitBuster.exe
[2010/11/29 17:38:30 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/27 16:02:22 | 000,080,384 | —- | C] () – C:\Users\Kiki Wiki\Desktop\MBRCheck.exe
[2010/12/27 14:10:28 | 000,296,448 | —- | C] () – C:\Users\Kiki Wiki\Desktop\s3jb5ryb.exe
[2010/12/25 21:52:24 | 000,000,775 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2010/12/25 20:45:19 | 3621,830,656 | -HS- | C] () – C:\hiberfil.sys
[2010/12/25 10:23:21 | 000,000,036 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\housecall.guid.cache
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagwrn.xml
[2010/12/25 09:37:48 | 000,001,905 | —- | C] () – C:\Windows\diagerr.xml
[2010/12/24 19:33:49 | 000,000,300 | -H– | C] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/24 19:31:07 | 000,000,118 | —- | C] () – C:\Windows\wininit.ini
[2010/12/24 17:54:09 | 000,000,378 | —- | C] () – C:\Windows\tasks\AWC Startup.job
[2010/12/24 17:53:58 | 000,000,139 | —- | C] () – C:\Users\Kiki Wiki\Desktop\IObit Freeware.url
[2010/12/24 17:53:57 | 000,001,009 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare.lnk
[2010/12/24 17:53:57 | 000,000,985 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/12/24 15:20:32 | 000,001,050 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/12/24 15:20:32 | 000,001,026 | —- | C] () – C:\Users\Kiki Wiki\Desktop\Spybot - Search & Destroy.lnk
[2010/12/23 09:48:38 | 000,061,440 | RHS- | C] () – C:\Windows\System32\rasgcwh.dll
[2010/12/23 09:48:38 | 000,000,312 | -HS- | C] () – C:\Windows\tasks\lwmcdovil.job
[2010/12/23 09:15:18 | 000,000,872 | —- | C] () – C:\Users\Kiki Wiki\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2010/12/23 09:15:18 | 000,000,860 | —- | C] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/12/23 09:15:18 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/12/21 20:53:44 | 000,001,635 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/21 20:41:59 | 000,001,697 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/16 19:18:10 | 000,000,132 | —- | C] () – C:\Users\Kiki Wiki\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/12/16 11:45:30 | 1026,293,791 | —- | C] () – C:\Users\Kiki Wiki\Photoshop_12_LS1.7z
[2010/12/14 19:55:40 | 000,007,918 | —- | C] () – C:\Users\Kiki Wiki\.recently-used.xbel
[2010/11/13 21:46:21 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/09/02 20:51:26 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2010/03/17 22:21:41 | 000,000,032 | —- | C] () – C:\Windows\System32\Video Converter.dll
[2010/03/17 00:17:00 | 000,000,032 | —- | C] () – C:\Windows\System32\Cool Motion.dll
[2009/12/03 09:27:30 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/08 16:01:46 | 000,000,552 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d8caps.dat
[2009/09/06 08:45:35 | 000,005,632 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/15 11:26:15 | 000,074,703 | —- | C] () – C:\Windows\System32\mfc45.dll
[2009/07/15 11:10:50 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2009/07/15 11:10:49 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2009/07/15 11:10:49 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2009/07/15 11:10:49 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2009/07/08 18:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/24 10:01:03 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/23 17:12:10 | 000,651,264 | —- | C] () – C:\Windows\System32\libeay32.dll
[2009/06/23 17:12:10 | 000,147,456 | —- | C] () – C:\Windows\System32\ssleay32.dll
[2009/06/23 08:45:17 | 000,007,268 | —- | C] () – C:\Users\Kiki Wiki\AppData\Local\d3d9caps.dat
[2008/06/03 03:35:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2010/07/23 19:21:29 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Bitsoft
[2010/02/15 11:43:59 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\CheckPoint
[2010/09/02 21:01:42 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DAEMON Tools Lite
[2010/09/04 10:02:46 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DAEMON Tools Pro
[2010/12/24 12:00:52 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DNA
[2010/02/14 14:45:17 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DriverCure
[2010/10/11 08:29:36 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoft
[2010/06/04 21:54:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/04/26 21:20:26 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\FinalMediaPlayer
[2010/06/06 21:04:15 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\FireShot
[2010/06/05 03:58:19 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\GetRightToGo
[2010/12/14 19:55:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\gtk-2.0
[2009/08/08 22:52:32 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Handy Uninstaller
[2010/11/18 15:19:14 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\IObit
[2009/07/15 15:36:37 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\iolo
[2010/02/27 16:09:46 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Lingoes
[2010/06/21 00:05:13 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\Northcode
[2010/05/23 20:29:14 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\REAPER
[2009/06/24 22:33:40 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\TeamViewer
[2010/10/14 15:11:27 | 000,000,000 | —D | M] – C:\Users\Kiki Wiki\AppData\Roaming\WTouch
[2010/12/27 14:04:41 | 000,000,378 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2010/12/27 11:47:58 | 000,000,312 | -HS- | M] () – C:\Windows\Tasks\lwmcdovil.job
[2010/12/27 08:56:51 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/27 16:00:50 | 000,000,300 | -H– | M] () – C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/07/26 10:53:58 | 000,487,424 | —- | M] (
http://aegisknight.org/) – C:\audiere.dll
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:38 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/06/23 01:22:46 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/04/11 10:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 10:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 10:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 10:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 10:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 10:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 10:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 10:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 10:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2008/04/11 10:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/12/27 11:47:47 | 3621,830,656 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 10:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2010/02/15 11:41:18 | 000,000,197 | —- | M] () – C:\INSTALL.LOG
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/09/15 15:50:42 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/09/15 15:50:42 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/12/27 11:47:45 | 3935,436,800 | -HS- | M] () – C:\pagefile.sys
[2008/04/11 10:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 10:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 10:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/06/24 10:12:29 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/06/23 15:26:37 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 03:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 03:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-16 17:54:22
========== Files - Unicode (All) ==========
[2010/09/13 17:41:50 | 002,004,992 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3
[2010/09/13 17:41:48 | 006,051,840 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/13 17:41:48 | 003,035,136 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/13 17:41:47 | 004,376,576 | —- | C] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:21:45 | 004,376,576 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - ???? - sm4459602 - HQ.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Interstellar Flight with English Sub - Seikan Hikou - Miku and Rin - 星間飛行 - sm4459602 - HQ.mp3
[2010/09/11 11:14:33 | 006,051,840 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - ??- ???.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - シド- ミルク.mp3
[2010/09/11 11:10:49 | 003,035,136 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. ???? ????????.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - true my heart -VOCALOID2 special edit- feat. 初音ミク ブログと同音質版.mp3
[2010/09/11 11:02:53 | 002,004,992 | —- | M] ()(C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park ?A DAY IN THE LIFE?.mp3) – C:\Users\Kiki Wiki\Documents\YouTube - Jazzin'park 『A DAY IN THE LIFE』.mp3
< End of report >
OTL Extras logfile created on: 12/27/2010 4:07:08 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 55.21 Gb Free Space | 37.41% Space Free | Partition Type: NTFS
Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04C19692-20E1-4212-9EC5-BA3B0898AEFE}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{0AE4A5DE-D6F9-41DD-9D46-9C255DF6BF6B}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{41789F26-9455-4A9A-B441-0C4B522D258D}" = lport=49160 | protocol=6 | dir=in | name=akamai netsession interface |
"{483EFD29-6B80-4904-AA3D-9BADF25571AE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{56155B2B-C965-40F1-B73A-6359F77DB7A9}" = lport=51775 | protocol=6 | dir=in | name=akamai netsession interface |
"{6C83C253-696C-4417-AE22-226950AB733E}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{8E494691-5429-4D01-89A3-592A97EFAF43}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D6A4A9DB-8182-4BA1-B95A-EE4A5F4E3523}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{DB0CD793-2C48-4635-9C42-D59C305F31A9}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E2ADC45-7928-4A97-8513-B718D272717C}" = protocol=6 | dir=in | app=c:\nexon\poptag\ca.exe |
"{2862ED87-0797-4CF3-8F48-008D4C92834A}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{3DA7EA6F-3BAC-4489-AE94-D9D52E223C3D}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{3DF5BD29-C425-42C6-83AF-367A069230F8}" = protocol=6 | dir=in | app=c:\program files\ogplanet\lostsaga\autoupgrade.exe |
"{3E264563-5FEF-4ACC-9367-B0B9DF2FB56D}" = protocol=17 | dir=in | app=c:\program files\ogplanet\lostsaga\lostsaga.exe |
"{3F0FFBB6-F6E3-438F-9B98-76DECAE4AB5E}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{431493B4-9B99-4B16-92FC-89069BC71471}" = protocol=6 | dir=in | app=c:\nexon\poptag\nmcosrv.exe |
"{453A58D9-DDD0-476F-8261-FEB7ED954AF7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4CEBF241-1E82-4388-BC3E-A4C8033C15EC}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{4F6C11E6-88AE-4496-ADB7-A0FA354A2B61}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5569E7BF-3837-4F82-93EF-9EFFD125C23F}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{5981CFE7-F262-45AC-AA04-A13AB750EC1D}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{6F965EE9-2D21-4922-8433-F88E03E7E869}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{73B1934C-7C0F-4B65-B2DE-4230D7989F08}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{7A4CBD17-0092-488A-A36F-BBDD84803751}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{7EEF8BE4-FD27-45AE-9FA6-714F992D1F55}" = protocol=6 | dir=in | app=c:\program files\ogplanet\lostsaga\lostsaga.exe |
"{7F7C4808-8B88-445B-8CAE-EDBDF1AC35B3}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{822DEF79-01C9-4CFA-93C2-4080423BF5C6}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{A09EE0DE-2834-4FBD-B3CB-30E1B6650A66}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A1EA4971-F2D3-4125-8E07-521FAC2D3194}" = protocol=17 | dir=in | app=c:\nexon\poptag\ca.exe |
"{B6C574B2-5DB4-45F0-B7A5-7AA25277C937}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B9ED01BF-4D7F-4EC9-A8A3-80F811CB0DC1}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{BD75B57D-A891-424A-BE17-F816FD272B6D}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{D41944FB-2C67-4AE1-8307-092FAAFB0E38}" = protocol=17 | dir=in | app=c:\nexon\poptag\nmcosrv.exe |
"{D642394C-11D1-4283-95C8-09D22866D6E4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D9D384DE-64DF-44F3-826D-F576D54E54D8}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{E903D496-ECC7-4C94-9C13-40877EF09835}" = protocol=17 | dir=in | app=c:\program files\ogplanet\lostsaga\autoupgrade.exe |
"{F0DFD4F9-EF22-43F5-B971-EBDA59F1B309}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version5\teamviewer.exe |
"{F1E8B8B5-0551-4DA5-B81A-5C5C9FB20868}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{F6822CCE-3EDC-4C86-A7D9-BB3859440770}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{FE24A2CB-4790-48B5-BEE7-9198B1BE5077}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"TCP Query User{3EAC2078-9A66-4AD4-AE6B-780BC06D6267}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"TCP Query User{4ED94695-FA36-4606-8DAD-DC9380B270BE}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{62D90031-3B72-4156-9231-93F7C7E4E2FB}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"TCP Query User{69F4FC7B-3B72-4C25-B223-366307CE31AD}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{A2852FBB-D8E9-4484-9D25-70E0ACB37E0C}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{44306FEC-FA9A-4298-91D1-41657AD40C3B}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{4B8847F1-04F4-4D64-8CD3-26C1E307CB62}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"UDP Query User{BDDEAC7F-81D9-42A3-924F-D40698E57906}C:\users\kiki wiki\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\kiki wiki\program files\dna\btdna.exe |
"UDP Query User{E55CCD6C-32A8-4822-AC56-9AD164E98E02}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{F0E4708C-DBA1-4903-AD39-8A466FE4451B}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02EE107B-8D95-4949-8935-4DEBE8F08BE3}" = Bing Bar Platform
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB03}" = La Tale
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26119A24-8F74-4F62-A278-AB3984B12C04}" = Microsoft Web Platform Installer 2.0 RC
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 22
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.239_Foxconn Installation Program
"{29BB979E-63CC-439C-8B9B-D628949BA889}" = N.E.O.Online
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{51123D42-6B9C-4B93-900C-29F9EC5963C9}" = NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5AE3D9F1-9E9E-4015-8787-E22705AA32C5}" = msxml4
"{5B161932-9D42-4D5E-858D-29BF4C670944}" = Microsoft SQL Server 2008 Setup Support Files
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{94317163-C5D1-4FCE-A0D9-F48FE06A7D7D}" = Microsoft SQL Server 2008 Native Client
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E989D16F-0B39-4E74-8BD5-149BEE1477FE}" = Microsoft SQL Server 2008 RsFx Driver
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C60F3E-70CF-42BF-8FEC-7B101A8C4868}" = IrisOnline
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = TIPCI
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"7-Zip" = 7-Zip 9.17 beta
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Akamai" = Akamai NetSession Interface
"Alarm_is1" = Alarm
"All ATI Software" = ATI - Software Uninstall Utility
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"FormatFactory" = FormatFactory 2.40
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free Studio_is1" = Free Studio version 4.8
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9
"Game Booster_is1" = Game Booster
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HyperCam 2" = HyperCam 2
"InstallShield_{F7B05784-334C-4F76-8BAB-30ABEB7FD534}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"IObit Security 360_is1" = IObit Security 360
"IsoBuster_is1" = IsoBuster 2.5
"LameACM" = LameACM
"Legend of Edda" = Legend of Edda USA_v1.0
"Lingoes Translator_is1" = Lingoes 2.6.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"OGPlanet Game Launcher US" = OGPlanet Game Launcher
"Pen Tablet Driver" = Bamboo
"Revo Uninstaller" = Revo Uninstaller 1.89
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TeamViewer 5" = TeamViewer 5
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Traverso_is1" = Traverso 0.49.1
"Uninstall_is1" = Uninstall 1.0.0.1
"VisualRoute" = VisualRoute
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 7/15/2009 12:50:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 12:50:12 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 12:50:12 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:08 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:08 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:09 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:38 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:38 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
Error - 7/15/2009 2:12:44 PM | Computer Name = KikiWiki-PC | Source = avast! | ID = 33554522
Description =
[ Application Events ]
Error - 8/3/2010 4:00:59 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/4/2010 4:00:59 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/4/2010 4:01:20 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/5/2010 4:00:41 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/5/2010 4:01:01 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/5/2010 9:36:17 PM | Computer Name = KikiWiki-PC | Source = Application Hang | ID = 1002
Description = The program sparkle.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 2f44 Start Time: 01cb3507b1548a61 Termination Time: 6
Error - 8/6/2010 4:00:08 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/6/2010 4:00:28 AM | Computer Name = KikiWiki-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 8/6/2010 4:58:04 AM | Computer Name = KikiWiki-PC | Source = EventSystem | ID = 4621
Description =
Error - 8/6/2010 4:58:09 AM | Computer Name = KikiWiki-PC | Source = IS360service | ID = 0
Description =
[ System Events ]
Error - 12/27/2010 11:51:40 AM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 12/27/2010 11:51:52 AM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 12/27/2010 11:53:00 AM | Computer Name = KikiWiki-PC | Source = WMPNetworkSvc | ID = 866297
Description =
Error - 12/27/2010 11:53:22 AM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 12/27/2010 11:53:22 AM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 12/27/2010 2:47:32 PM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 12/27/2010 2:47:45 PM | Computer Name = KikiWiki-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 12/27/2010 2:49:22 PM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 12/27/2010 2:49:22 PM | Computer Name = KikiWiki-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 12/27/2010 4:58:27 PM | Computer Name = KikiWiki-PC | Source = WMPNetworkSvc | ID = 866297
Description =
< End of report >