Thanks for your prompt reply. MBRCheck and OTL ran fine and produced logs but as I stated in my original post, I cannot run TDSSKiller.exe. The process shows up briefly in task manger but is terminated; renaming the file to something different gives me the same results.
Here is the log from MBRCheck.
MBRCheck, version 1.2.3
ยฉ 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: Intel Corporation
BIOS Manufacturer: Intel Corp.
System Manufacturer:
System Product Name: GM5446E
Logical Drives Mask: 0x00000f8c
Kernel Drivers (total 175):
0x82409000 \SystemRoot\system32\ntoskrnl.exe
0x827B3000 \SystemRoot\system32\hal.dll
0x83002000 \SystemRoot\system32\kdcom.dll
0x8300A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8306A000 \SystemRoot\system32\PSHED.dll
0x8307B000 \SystemRoot\system32\BOOTVID.dll
0x83083000 \SystemRoot\system32\CLFS.SYS
0x830C4000 \SystemRoot\system32\CI.dll
0x831A4000 \SystemRoot\system32\DRIVERS\35858692.sys
0x831B1000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8322D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8323A000 \SystemRoot\system32\drivers\acpi.sys
0x83280000 \SystemRoot\system32\drivers\WMILIB.SYS
0x83289000 \SystemRoot\system32\drivers\msisadrv.sys
0x83291000 \SystemRoot\system32\drivers\pci.sys
0x832B8000 \SystemRoot\System32\drivers\partmgr.sys
0x832C7000 \SystemRoot\system32\drivers\volmgr.sys
0x832D6000 \SystemRoot\System32\drivers\volmgrx.sys
0x83320000 \SystemRoot\system32\drivers\intelide.sys
0x83327000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x83335000 \SystemRoot\System32\drivers\mountmgr.sys
0x83345000 \SystemRoot\system32\drivers\iastorv.sys
0x833E6000 \SystemRoot\system32\drivers\atapi.sys
0x88400000 \SystemRoot\system32\drivers\ataport.SYS
0x8841E000 \SystemRoot\system32\drivers\fltmgr.sys
0x88450000 \SystemRoot\system32\drivers\fileinfo.sys
0x88460000 \SystemRoot\System32\Drivers\ksecdd.sys
0x884D1000 \SystemRoot\system32\drivers\ndis.sys
0x885DC000 \SystemRoot\system32\drivers\msrpc.sys
0x88607000 \SystemRoot\system32\drivers\NETIO.SYS
0x88641000 \SystemRoot\System32\drivers\tcpip.sys
0x8872A000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x88800000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8890F000 \SystemRoot\system32\drivers\volsnap.sys
0x88948000 \SystemRoot\System32\Drivers\spldr.sys
0x88950000 \SystemRoot\System32\Drivers\mup.sys
0x8895F000 \SystemRoot\system32\drivers\mfehidk.sys
0x889B1000 \SystemRoot\System32\drivers\ecache.sys
0x889D8000 \SystemRoot\system32\drivers\disk.sys
0x889E9000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x88A0A000 \SystemRoot\system32\drivers\crcdisk.sys
0x88AC1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x88ACC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88AD5000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8D406000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8DE84000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8DE86000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8DF25000 \SystemRoot\System32\drivers\watchdog.sys
0x8DF32000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8DF44000 \SystemRoot\system32\DRIVERS\AVerBas.sys
0x8DF52000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8DF5D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8DF9B000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x88AE4000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8DFAA000 \SystemRoot\system32\DRIVERS\HSXHWBS2.sys
0x88B59000 \SystemRoot\system32\DRIVERS\ks.sys
0x8E803000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8E906000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8E9BB000 \SystemRoot\system32\drivers\modem.sys
0x8E9C8000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8E9D8000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8E9E6000 \SystemRoot\system32\DRIVERS\e100b325.sys
0x8EA0D000 \SystemRoot\system32\DRIVERS\parport.sys
0x8EA25000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EA38000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EA43000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EA4E000 \??\C:\Windows\system32\drivers\VMkbd.sys
0x8EA53000 \SystemRoot\system32\DRIVERS\serial.sys
0x8EA6D000 \SystemRoot\system32\DRIVERS\serenum.sys
0x8EA77000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EAA5000 \SystemRoot\system32\DRIVERS\storport.sys
0x8EAE6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EAF1000 \SystemRoot\System32\Drivers\RootMdm.sys
0x8EAF9000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EB10000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EB1B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EB3E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EB4D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8EB61000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EB76000 \SystemRoot\system32\DRIVERS\RimSerial.sys
0x8EB7D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8EB8D000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8EB8F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8EB99000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EBA6000 \SystemRoot\system32\DRIVERS\vmnetadapter.sys
0x8EBA9000 \SystemRoot\system32\DRIVERS\VMNET.SYS
0x88B83000 \SystemRoot\system32\DRIVERS\AVerCap.sys
0x8EBAC000 \SystemRoot\system32\DRIVERS\AVerTun.sys
0x8EBD5000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
0x88745000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EBD8000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x88779000 \SystemRoot\system32\drivers\HdAudio.sys
0x887B8000 \SystemRoot\system32\drivers\portcls.sys
0x8F000000 \SystemRoot\system32\drivers\drmk.sys
0x8F03D000 \SystemRoot\system32\DRIVERS\3585869.sys
0x8F08D000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F096000 \SystemRoot\System32\Drivers\Null.SYS
0x8F09D000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F0A4000 \SystemRoot\System32\drivers\vga.sys
0x8F0B0000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F0D1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F0D9000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F0E1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F0EC000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F0FA000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F103000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F119000 \SystemRoot\system32\drivers\mfetdik.sys
0x8F127000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F159000 \SystemRoot\system32\DRIVERS\smb.sys
0x8F409000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8F928000 \SystemRoot\system32\drivers\afd.sys
0x8F970000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8F987000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F989000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8F992000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x8F99F000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8F9B5000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x8F9BF000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F9CD000 \SystemRoot\system32\DRIVERS\dot4usb.sys
0x8F9DA000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F9ED000 \SystemRoot\system32\DRIVERS\Dot4.sys
0x8FA12000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x8FA20000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8FA32000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8FA6E000 \SystemRoot\system32\DRIVERS\Dot4Prt.sys
0x8FA77000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8FA81000 \??\C:\Windows\system32\drivers\lmqseyg.sys
0x8FACD000 \??\C:\Windows\system32\drivers\dhahelper.sys
0x8FAD4000 \SystemRoot\System32\Drivers\dfsc.sys
0x8FC05000 \SystemRoot\system32\DRIVERS\35858691.sys
0x90125000 \SystemRoot\System32\Drivers\fastfat.SYS
0x9014D000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9015A000 \SystemRoot\System32\Drivers\dump_iaStorV.sys
0x99090000 \SystemRoot\System32\win32k.sys
0x901FB000 \SystemRoot\System32\drivers\Dxapi.sys
0x90205000 \SystemRoot\system32\DRIVERS\monitor.sys
0x992B0000 \SystemRoot\System32\TSDDD.dll
0x992D0000 \SystemRoot\System32\cdd.dll
0x992E0000 \SystemRoot\System32\ATMFD.DLL
0x90214000 \SystemRoot\system32\drivers\luafv.sys
0x90237000 \SystemRoot\system32\drivers\spsys.sys
0x902E6000 \SystemRoot\system32\DRIVERS\vmnetbridge.sys
0x902F4000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x90304000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9032E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x90338000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9034B000 \SystemRoot\system32\drivers\HTTP.sys
0x903B8000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x903D5000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8FAEB000 \SystemRoot\System32\drivers\mpsdrv.sys
0x8FB00000 \SystemRoot\system32\drivers\mrxdav.sys
0x8FB20000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x8FB3F000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x8FB78000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x8FB90000 \SystemRoot\System32\DRIVERS\srv2.sys
0x8F16D000 \SystemRoot\System32\DRIVERS\srv.sys
0x903EE000 \??\C:\Windows\system32\drivers\hcmon.sys
0x903F8000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x8FBB7000 \??\C:\Windows\system32\Drivers\vmci.sys
0x8FC00000 \??\C:\Windows\system32\Drivers\VMparport.sys
0x8F1BB000 \??\C:\Windows\system32\Drivers\vmx86.sys
0x8FBC7000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x8FBD0000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x8F28A000 \SystemRoot\system32\drivers\peauth.sys
0x8FBD4000 \SystemRoot\System32\Drivers\secdrv.SYS
0x8FBDE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x8FBEA000 \??\C:\Windows\system32\drivers\vmnetuserif.sys
0x8FC02000 \??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys
0x8FBEF000 \??\C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys
0x8FBF3000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x8F368000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x8F37D000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x8F38F000 \SystemRoot\system32\drivers\mfeavfk.sys
0x9022F000 \SystemRoot\system32\drivers\MSPQM.sys
0x77C50000 \Windows\System32\ntdll.dll
Processes (total 74):
0 System Idle Process
4 System
552 C:\Windows\System32\smss.exe
648 C:\Windows\System32\csrss.exe
700 C:\Windows\System32\wininit.exe
712 C:\Windows\System32\csrss.exe
744 C:\Windows\System32\services.exe
784 C:\Windows\System32\lsass.exe
792 C:\Windows\System32\lsm.exe
888 C:\Windows\System32\winlogon.exe
1016 C:\Windows\System32\svchost.exe
1084 C:\Windows\System32\svchost.exe
1152 C:\Windows\System32\svchost.exe
1176 C:\Windows\System32\svchost.exe
1252 C:\Windows\System32\nvvsvc.exe
1272 C:\Windows\System32\nvvsvc.exe
1368 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\svchost.exe
1424 C:\Windows\System32\svchost.exe
1500 C:\Windows\System32\audiodg.exe
1540 C:\Windows\System32\svchost.exe
1564 C:\Windows\System32\SLsvc.exe
1948 C:\Windows\System32\spoolsv.exe
1972 C:\Windows\System32\svchost.exe
656 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
816 C:\Program Files\Bonjour\mDNSResponder.exe
1004 C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
1768 C:\Program Files\McAfee\Common Framework\FrameworkService.exe
2068 C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
2096 C:\Program Files\Common Files\microsoft shared\VS7Debug\MDM.EXE
2144 C:\Windows\System32\mfevtps.exe
2188 C:\Windows\System32\svchost.exe
2208 C:\Windows\System32\svchost.exe
2236 C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
2256 C:\Windows\System32\svchost.exe
2468 C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
2488 C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
2512 C:\Windows\System32\vmnat.exe
2532 C:\Windows\System32\svchost.exe
2568 C:\Windows\System32\SearchIndexer.exe
2616 C:\Windows\System32\drivers\XAudio.exe
2636 C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
2676 C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
2776 C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
2836 C:\Windows\System32\WUDFHost.exe
2844 C:\Windows\System32\vmnetdhcp.exe
3132 C:\Windows\System32\taskeng.exe
3472 C:\Windows\System32\dwm.exe
3504 C:\Windows\System32\taskeng.exe
3536 C:\Windows\explorer.exe
328 C:\Program Files\PowerISO\PWRISOVM.EXE
2608 C:\Program Files\iTunes\iTunesHelper.exe
964 C:\Program Files\GridService\peer.exe
2668 C:\Program Files\McAfee\Common Framework\UdaterUI.exe
2480 C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
1360 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
1000 C:\Program Files\Unlocker\UnlockerAssistant.exe
2252 C:\Windows\ehome\ehtray.exe
2220 C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
4092 C:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe
976 C:\Program Files\McAfee\Common Framework\McTray.exe
3560 C:\Windows\ehome\ehmsas.exe
4008 C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\setup_9.0.0.722_09.02.2011_20-07.exe
3712 C:\Program Files\Mozilla Firefox\firefox.exe
1672 C:\Program Files\iPod\bin\iPodService.exe
4432 C:\Windows\ehome\ehrecvr.exe
5752 C:\Program Files\Orb Networks\Orb\bin\Orb.exe
5860 C:\Program Files\Orb Networks\Orb\bin\OrbjetManager.exe
4940 C:\Users\Buddy\Desktop\HiJackThis.exe
5632 C:\Windows\System32\notepad.exe
2360 C:\Windows\System32\wbem\WmiPrvSE.exe
820 C:\Windows\System32\SearchProtocolHost.exe
4528 C:\Windows\System32\SearchFilterHost.exe
5904 C:\Users\Buddy\Desktop\MBRCheck.exe
\\.\C: โ> \\.\PhysicalDrive0 at offset 0x00000002`75028600 (NTFS)
\\.\D: โ> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (FAT32)
PhysicalDrive0 Model Number: WDCWD5000AAKS-22TMA0, Rev: 12.01C01
Size Device Name MBR Status
โโโโโโโโโโโโโโโ
465 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
Here are the logs from OTL.
the first one:
OTL logfile created on: 2/11/2011 3:58:03 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 57.22 Gb Free Space | 12.55% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32
Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/11 15:57:34 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Buddy\Desktop\OTL.exe
PRC - [2011/01/19 16:05:57 | 000,910,296 | โ- | M] (Mozilla Corporation) โ C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | โ- | M] () โ C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2010/06/29 20:35:20 | 000,755,312 | โ- | M] (Orb Networks) โ C:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe
PRC - [2010/06/29 20:35:16 | 000,286,720 | โ- | M] () โ C:\Program Files\Orb Networks\Orb\bin\OrbjetManager.exe
PRC - [2010/06/29 20:34:50 | 000,198,144 | โ- | M] (Orb Networks, Inc.) โ C:\Program Files\Orb Networks\Orb\bin\Orb.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | โ- | M] (Apple Inc.) โ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | โ- | M] (PowerISO Computing, Inc.) โ C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2010/03/29 19:26:00 | 000,227,712 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/01/18 13:33:03 | 000,198,160 | โ- | M] (RealNetworks, Inc.) โ C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/01/06 19:07:00 | 000,147,472 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2010/01/06 19:07:00 | 000,124,240 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2010/01/06 19:07:00 | 000,070,728 | โ- | M] (McAfee, Inc.) โ C:\Windows\System32\mfevtps.exe
PRC - [2010/01/06 19:07:00 | 000,066,896 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2010/01/06 19:07:00 | 000,027,960 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
PRC - [2010/01/06 19:07:00 | 000,022,816 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
PRC - [2009/10/22 05:00:04 | 000,395,824 | โ- | M] (VMware, Inc.) โ C:\Windows\System32\vmnat.exe
PRC - [2009/10/22 04:59:58 | 000,113,200 | โ- | M] (VMware, Inc.) โ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009/10/22 04:59:48 | 000,334,384 | โ- | M] (VMware, Inc.) โ C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/10/22 03:47:54 | 000,563,760 | โ- | M] (VMware, Inc.) โ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009/10/01 13:55:56 | 000,330,256 | โ- | M] (Kaspersky Lab) โ C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\setup_9.0.0.722_09.02.2011_20-07.exe
PRC - [2008/12/30 12:45:08 | 004,993,024 | โ- | M] (FS2YOU) โ C:\Program Files\GridService\peer.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | โ- | M] (Microsoft Corporation) โ C:\Windows\explorer.exe
PRC - [2008/03/14 03:00:00 | 000,226,624 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008/03/14 03:00:00 | 000,136,512 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2008/03/14 03:00:00 | 000,103,744 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2008/03/14 03:00:00 | 000,091,456 | โ- | M] (McAfee, Inc.) โ C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2007/03/23 11:02:52 | 000,269,104 | โ- | M] (VMware, Inc.) โ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
========== Modules (SafeList) ==========
MOD - [2011/02/11 15:57:34 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Buddy\Desktop\OTL.exe
MOD - [2010/07/04 16:32:36 | 000,004,608 | โ- | M] () โ C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/01/19 02:26:34 | 001,684,480 | โ- | M] (Microsoft Corporation) โ C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] โ โ (Katchall Service)
SRV - [2011/02/08 16:07:43 | 000,510,848 | โ- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] โ C:\Users\Buddy\AppData\Local\Temp\Q.exe โ (Q)
SRV - [2011/02/08 16:06:50 | 000,400,256 | โ- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] โ C:\Users\Buddy\AppData\Local\Temp\AZVX.exe โ (AZVX)
SRV - [2010/06/10 20:03:08 | 000,144,176 | โ- | M] (Apple Inc.) [Auto | Running] โ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe โ (Apple Mobile Device)
SRV - [2010/03/25 09:25:22 | 030,969,208 | โ- | M] (Microsoft Corporation) [On_Demand | Stopped] โ C:\Program Files\Microsoft Office\Office14\GROOVE.EXE โ (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/03/18 12:16:28 | 000,753,504 | โ- | M] (Microsoft Corporation) [On_Demand | Stopped] โ C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe โ (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | โ- | M] (Microsoft Corporation) [Auto | Stopped] โ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe โ (clr_optimization_v4.0.30319_32)
SRV - [2010/01/06 19:07:00 | 000,147,472 | โ- | M] (McAfee, Inc.) [Auto | Paused] โ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe โ (McShield)
SRV - [2010/01/06 19:07:00 | 000,070,728 | โ- | M] (McAfee, Inc.) [Unknown | Running] โ C:\Windows\System32\mfevtps.exe โ (mfevtp)
SRV - [2010/01/06 19:07:00 | 000,066,896 | โ- | M] (McAfee, Inc.) [Auto | Running] โ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe โ (McTaskManager)
SRV - [2010/01/06 19:07:00 | 000,022,816 | โ- | M] (McAfee, Inc.) [Auto | Running] โ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe โ (McAfeeEngineService)
SRV - [2009/10/22 05:00:04 | 000,395,824 | โ- | M] (VMware, Inc.) [Auto | Running] โ C:\Windows\System32\vmnat.exe โ (VMware NAT Service)
SRV - [2009/10/22 04:59:58 | 000,113,200 | โ- | M] (VMware, Inc.) [Auto | Running] โ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe โ (VMAuthdService)
SRV - [2009/10/22 04:59:48 | 000,334,384 | โ- | M] (VMware, Inc.) [Auto | Running] โ C:\Windows\System32\vmnetdhcp.exe โ (VMnetDHCP)
SRV - [2009/10/22 03:47:54 | 000,563,760 | โ- | M] (VMware, Inc.) [Auto | Running] โ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe โ (VMUSBArbService)
SRV - [2009/10/12 14:32:24 | 000,191,024 | โ- | M] (VMware, Inc.) [On_Demand | Stopped] โ C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe โ (ufad-ws60)
SRV - [2009/07/14 08:22:46 | 000,180,224 | โ- | M] () [On_Demand | Stopped] โ C:\Program Files\RipTiger\ElevatorService.exe โ (ElevatorService)
SRV - [2009/01/26 14:31:10 | 001,153,368 | โ- | M] (Safer Networking Ltd.) [Disabled | Stopped] โ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe โ (SBSDWSCService)
SRV - [2008/06/25 08:54:10 | 000,654,848 | โ- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] โ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe โ (FLEXnet Licensing Service)
SRV - [2008/03/14 03:00:00 | 000,103,744 | โ- | M] (McAfee, Inc.) [Auto | Running] โ C:\Program Files\McAfee\Common Framework\FrameworkService.exe โ (McAfeeFramework)
SRV - [2008/01/19 02:38:24 | 000,272,952 | โ- | M] (Microsoft Corporation) [Auto | Stopped] โ C:\Program Files\Windows Defender\MpSvc.dll โ (WinDefend)
SRV - [2008/01/19 02:33:33 | 000,136,192 | โ- | M] () [Auto | Stopped] โ \\.\globalroot\systemroot\system32\usะตrinit.exe [WARNING: \\.\globalroot\systemroot\system32\us?rinit.exe] โ (userinit)
SRV - [2007/11/14 20:46:00 | 000,131,072 | โ- | M] (Brio) [Disabled | Stopped] โ C:\Program Files\FolderSize\FolderSizeSvc.exe โ (FolderSize)
SRV - [2007/11/06 15:22:26 | 000,092,792 | โ- | M] (CACE Technologies) [On_Demand | Stopped] โ C:\Program Files\WinPcap\rpcapd.exe โ (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/03/23 11:02:52 | 000,269,104 | โ- | M] (VMware, Inc.) [Auto | Running] โ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe โ (vmount2)
========== Driver Services (SafeList) ==========
DRV - [2011/02/09 15:18:23 | 000,007,168 | โ- | M] () [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\utqyntkz.sys โ (utqyntkz)
DRV - [2011/02/08 17:14:55 | 000,053,248 | โ- | M] (eSage Lab) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\rk_remover.sys โ (rk_remover-boot)
DRV - [2010/07/10 04:37:00 | 011,008,040 | โ- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\nvlddmkm.sys โ (nvlddmkm)
DRV - [2010/06/18 12:21:34 | 000,691,696 | โ- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\System32\Drivers\sptd.sys โ (sptd)
DRV - [2010/04/12 03:44:34 | 000,059,388 | โ- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] โ C:\Windows\System32\drivers\scdemu.sys โ (SCDEmu)
DRV - [2010/04/08 20:46:06 | 000,007,168 | โ- | M] (MPlayer <
http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Kernel | System | Running] โ C:\Windows\System32\drivers\dhahelper.sys โ (DhaHelper)
DRV - [2010/01/21 00:59:58 | 000,020,864 | โ- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\lgusbdiag.sys โ (UsbDiag)
DRV - [2010/01/21 00:59:56 | 000,024,960 | โ- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\lgusbmodem.sys โ (USBModem)
DRV - [2010/01/21 00:59:56 | 000,013,056 | โ- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\lgusbbus.sys โ (usbbus)
DRV - [2010/01/06 19:07:00 | 000,343,920 | โ- | M] (McAfee, Inc.) [Kernel | Boot | Running] โ C:\Windows\system32\drivers\mfehidk.sys โ (mfehidk)
DRV - [2010/01/06 19:07:00 | 000,091,832 | โ- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\mfeavfk.sys โ (mfeavfk)
DRV - [2010/01/06 19:07:00 | 000,075,704 | โ- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\mfeapfk.sys โ (mfeapfk)
DRV - [2010/01/06 19:07:00 | 000,066,600 | โ- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\mferkdet.sys โ (mferkdet)
DRV - [2010/01/06 19:07:00 | 000,064,208 | โ- | M] (McAfee, Inc.) [Kernel | System | Running] โ C:\Windows\System32\drivers\mfetdik.sys โ (mfetdik)
DRV - [2010/01/06 19:07:00 | 000,043,288 | โ- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\mfebopk.sys โ (mfebopk)
DRV - [2009/10/22 12:54:18 | 000,037,392 | โ- | M] (Kaspersky Lab) [Kernel | Boot | Running] โ C:\Windows\system32\DRIVERS\35858692.sys โ (35858692)
DRV - [2009/10/22 05:00:46 | 000,853,936 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\vmx86.sys โ (vmx86)
DRV - [2009/10/22 05:00:44 | 000,070,704 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\vmci.sys โ (vmci)
DRV - [2009/10/22 05:00:44 | 000,026,288 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\vmnetuserif.sys โ (VMnetuserif)
DRV - [2009/10/22 05:00:44 | 000,023,216 | โ- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\VMkbd.sys โ (vmkbd)
DRV - [2009/10/22 04:59:48 | 000,014,896 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\vmparport.sys โ (VMparport)
DRV - [2009/10/22 03:47:52 | 000,032,304 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\hcmon.sys โ (hcmon)
DRV - [2009/10/22 00:13:36 | 000,031,280 | โ- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\vmusb.sys โ (vmusb)
DRV - [2009/10/22 00:13:32 | 000,036,400 | Rโ | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\vmnetbridge.sys โ (VMnetBridge)
DRV - [2009/10/22 00:13:32 | 000,016,560 | โ- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\vmnetadapter.sys โ (VMnetAdapter)
DRV - [2009/10/12 14:31:52 | 000,022,448 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys โ (vstor2-ws60)
DRV - [2009/10/09 22:31:02 | 000,311,312 | โ- | M] (Kaspersky Lab) [File_System | System | Running] โ C:\Windows\System32\drivers\3585869.sys โ (setup_9.0.0.722_09.02.2011_20-07drv)
DRV - [2009/09/25 16:59:42 | 000,128,016 | โ- | M] (Kaspersky Lab) [Kernel | System | Running] โ C:\Windows\System32\drivers\35858691.sys โ (35858691)
DRV - [2009/07/07 18:53:02 | 000,028,160 | โ- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\libusb0.sys โ (libusb0)
DRV - [2009/02/02 06:56:14 | 000,165,248 | โ- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\AVerTun.sys โ (AVMNgTunM780)
DRV - [2009/02/02 06:56:12 | 000,366,976 | โ- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\AVerCap.sys โ (AVMNgCapM780)
DRV - [2009/02/02 06:56:10 | 000,057,216 | โ- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\AVerBas.sys โ (AVMNgBasM780)
DRV - [2008/07/21 18:34:36 | 000,121,872 | โ- | M] (Kaspersky Lab) [Kernel | System | Running] โ C:\Windows\System32\drivers\kl1.sys โ (kl1)
DRV - [2008/01/19 02:43:40 | 000,309,664 | โ- | M] () [Kernel | System | Running] โ C:\Windows\System32\drivers\lmqseyg.sys โ (lmqseyg)
DRV - [2008/01/19 02:42:51 | 000,235,064 | โ- | M] (Intel Corporation) [Kernel | Boot | Running] โ C:\Windows\system32\drivers\iastorv.sys โ (iaStorV)
DRV - [2008/01/19 00:53:23 | 000,073,088 | โ- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\USBAUDIO.sys โ (usbaudio) USB Audio Driver (WDM)
DRV - [2007/11/06 15:22:06 | 000,034,064 | โ- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\npf.sys โ (NPF)
DRV - [2007/06/29 08:11:02 | 000,008,704 | โ- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] โ C:\Windows\System32\drivers\XAudio.sys โ (XAudio)
DRV - [2007/06/20 02:29:56 | 000,984,064 | โ- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\HSX_DPV.sys โ (HSF_DPV)
DRV - [2007/06/20 02:28:38 | 000,267,264 | โ- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\HSXHWBS2.sys โ (HSXHWBS2)
DRV - [2007/06/20 02:28:22 | 000,660,480 | โ- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\HSX_CNXT.sys โ (winachsf)
DRV - [2007/03/23 11:03:00 | 000,018,480 | โ- | M] (VMware, Inc.) [Kernel | Auto | Running] โ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys โ (vstor2)
DRV - [2006/11/02 04:51:45 | 000,900,712 | โ- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ql2300.sys โ (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adp94xx.sys โ (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | โ- | M] (Emulex) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\elxstor.sys โ (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpahci.sys โ (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | โ- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\uliahci.sys โ (uliahci)
DRV - [2006/11/02 04:51:00 | 000,147,048 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpu320.sys โ (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | โ- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ulsata2.sys โ (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | โ- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\vsmraid.sys โ (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | โ- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ql40xx.sys โ (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ulsata.sys โ (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\adpu160m.sys โ (adpu160m)
DRV - [2006/11/02 04:50:24 | 000,088,680 | โ- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nvraid.sys โ (nvraid)
DRV - [2006/11/02 04:50:19 | 000,045,160 | โ- | M] (IBM Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nfrd960.sys โ (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | โ- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iirsp.sys โ (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | โ- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sisraid4.sys โ (SiSRaid4)
DRV - [2006/11/02 04:50:13 | 000,040,040 | โ- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\nvstor.sys โ (nvstor)
DRV - [2006/11/02 04:50:11 | 000,071,272 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\djsvs.sys โ (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\arcsas.sys โ (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_scsi.sys โ (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | โ- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sisraid2.sys โ (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | โ- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\hpcisss.sys โ (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | โ- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\arc.sys โ (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | โ- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iteraid.sys โ (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | โ- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\iteatapi.sys โ (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_sas.sys โ (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\symc8xx.sys โ (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\lsi_fc.sys โ (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sym_u3.sys โ (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | โ- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\mraid35x.sys โ (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | โ- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\sym_hi.sys โ (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | โ- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\megasas.sys โ (megasas)
DRV - [2006/11/02 04:49:30 | 000,017,512 | โ- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\viaide.sys โ (viaide)
DRV - [2006/11/02 04:49:28 | 000,016,488 | โ- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\cmdide.sys โ (cmdide)
DRV - [2006/11/02 04:49:20 | 000,014,952 | โ- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\aliide.sys โ (aliide)
DRV - [2006/11/02 03:25:24 | 000,071,808 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brserid.sys โ (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | โ- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brusbser.sys โ (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | โ- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brfiltup.sys โ (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | โ- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ C:\Windows\system32\drivers\brfiltlo.sys โ (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brserwdm.sys โ (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | โ- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\brusbmdm.sys โ (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | โ- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] โ C:\Windows\system32\drivers\ntrigdigi.sys โ (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,117,760 | โ- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\E1G60I32.sys โ (E1G60) Intelยฎ
DRV - [2006/11/02 02:30:53 | 000,464,384 | โ- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ C:\Windows\System32\drivers\BCMWL6.SYS โ (BCM43XV)
DRV - [2005/12/18 19:42:12 | 000,008,801 | โ- | M] () [Kernel | On_Demand | Stopped] โ C:\Program Files\DScaler\DSDrv4.sys โ (DSDrv4)
DRV - [2004/02/04 09:27:56 | 000,049,536 | โ- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\tiehdusb.sys โ (TIEHDUSB)
DRV - [2003/10/15 16:52:50 | 000,174,530 | โ- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] โ C:\Windows\System32\drivers\ov519vid.sys โ (ovt519)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/19 16:06:06 | 000,000,000 | โD | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/19 16:06:07 | 000,000,000 | โD | M]
[2009/12/23 13:37:34 | 000,000,000 | โD | M] (No name found) โ C:\Users\Buddy\AppData\Roaming\Mozilla\Extensions
[2011/02/10 17:42:33 | 000,000,000 | โD | M] (No name found) โ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions
[2010/09/06 14:37:05 | 000,000,000 | โD | M] (Microsoft .NET Framework Assistant) โ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 14:37:05 | 000,000,000 | โD | M] (1-Click YouTube Video Downloader) โ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\[removed]
[2011/02/10 17:42:33 | 000,000,000 | โD | M] (No name found) โ C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 13:33:28 | 000,000,000 | โD | M] (RealPlayer Browser Record Plugin) โ C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/01/06 19:07:00 | 000,023,864 | โ- | M] (McAfee, Inc.) โ C:\Program Files\Mozilla Firefox\components\Scriptff.dll
Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IE2EMBHO Class) - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll (VeryCD.com)
O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Grid Service] C:\Program Files\GridService\peer.exe (FS2YOU)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [facgupox] File not found
O4 - HKCU..\Run: [klboleds] File not found
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk = C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\startup.exe ()
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe (Smith Micro, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with &ZipScan; - C:\Program Files\ZipScan Evaluation\zs_ie.htm ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: adobe.com ([www] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashโฆr/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O24 - Desktop BackupWallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | โ- | M] () - C:\autoexec.bat โ [ NTFS ]
O33 - MountPoints2\{47119b37-d2c9-11de-8e41-005056c00008}\Shell\AutoRun\command - "" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe
O33 - MountPoints2\{632b21b5-5ce4-11df-9256-005056c00008}\Shell\AutoRun\command - "" = O:\PMBP_Win.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\amplayer.exe autorun.dat
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ "%1" %*
O35 - HKLM\..exefile [open] โ "%1" %*
O37 - HKLM\โฆcom [@ = comfile] โ "%1" %*
O37 - HKLM\โฆexe [@ = exefile] โ "%1" %*
O37 - HKCU\โฆexe [@ = exefile] โ Reg Error: Key error. File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/02/11 15:57:33 | 000,602,624 | โ- | C] (OldTimer Tools) โ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/11 15:19:40 | 000,388,608 | โ- | C] (Trend Micro Inc.) โ C:\Users\Buddy\Desktop\HiJackThis.exe
[2011/02/11 15:11:16 | 000,000,000 | RโD | C] โ C:\32788R22FWJFW
[2011/02/10 17:41:22 | 001,366,104 | โ- | C] (Kaspersky Lab ZAO) โ C:\abc12223.com
[2011/02/10 15:37:51 | 000,472,064 | โ- | C] ( ) โ C:\Users\Buddy\Desktop\RootRepeal.exe
[2011/02/10 15:26:46 | 000,611,624 | โ- | C] (Kaspersky Lab) โ C:\Users\Buddy\Desktop\GetSystemInfo.exe
[2011/02/09 14:00:11 | 000,000,000 | โD | C] โ C:\ProgramData\Kaspersky Lab
[2011/02/09 13:58:11 | 000,311,312 | โ- | C] (Kaspersky Lab) โ C:\Windows\System32\drivers\3585869.sys
[2011/02/09 13:58:11 | 000,128,016 | โ- | C] (Kaspersky Lab) โ C:\Windows\System32\drivers\35858691.sys
[2011/02/09 13:58:11 | 000,037,392 | โ- | C] (Kaspersky Lab) โ C:\Windows\System32\drivers\35858692.sys
[2011/02/09 13:58:10 | 000,000,000 | โD | C] โ C:\Users\Buddy\Desktop\Virus Removal Tool
[2011/02/09 13:56:27 | 091,126,696 | โ- | C] ( ) โ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 13:46:22 | 001,360,472 | โ- | C] (Kaspersky Lab ZAO) โ C:\Users\Buddy\Desktop\abc123.com
[2011/02/09 12:46:26 | 000,190,032 | โ- | C] (Trend Micro Inc.) โ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/08 17:14:55 | 000,053,248 | โ- | C] (eSage Lab) โ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:53:06 | 000,056,400 | โ- | C] (trend_company_name) โ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 16:02:39 | 000,000,000 | โD | C] โ C:\Program Files\ESET
[2011/02/04 16:18:44 | 000,000,000 | โD | C] โ C:\Users\Buddy\Desktop\R&R; Playlist
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/11 15:57:34 | 000,602,624 | โ- | M] (OldTimer Tools) โ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/11 15:56:24 | 000,080,384 | โ- | M] () โ C:\Users\Buddy\Desktop\MBRCheck.exe
[2011/02/11 15:43:01 | 000,000,886 | โ- | M] () โ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/11 15:19:41 | 000,388,608 | โ- | M] (Trend Micro Inc.) โ C:\Users\Buddy\Desktop\HiJackThis.exe
[2011/02/11 15:15:07 | 000,084,013 | โ- | M] () โ C:\ProgramData\nvModes.dat
[2011/02/11 15:15:07 | 000,084,013 | โ- | M] () โ C:\ProgramData\nvModes.001
[2011/02/11 15:14:47 | 000,000,882 | โ- | M] () โ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/11 15:14:37 | 000,002,480 | -Hโ | M] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/11 15:14:37 | 000,002,480 | -Hโ | M] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/11 15:14:26 | 000,067,584 | โS- | M] () โ C:\Windows\bootstat.dat
[2011/02/11 15:14:21 | 284,916,510 | โ- | M] () โ C:\Windows\MEMORY.DMP
[2011/02/11 15:11:02 | 004,266,810 | โ- | M] () โ C:\Users\Buddy\Desktop\alg.exe
[2011/02/11 14:58:08 | 000,000,418 | -Hโ | M] () โ C:\Windows\tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job
[2011/02/11 14:58:02 | 000,000,000 | โ- | M] () โ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 18:05:16 | 000,000,680 | โ- | M] () โ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2011/02/10 17:45:52 | 000,133,632 | โ- | M] () โ C:\Users\Buddy\Desktop\RKUnhookerLE.EXE
[2011/02/10 16:49:55 | 014,710,331 | โ- | M] () โ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/10 15:26:47 | 000,611,624 | โ- | M] (Kaspersky Lab) โ C:\Users\Buddy\Desktop\GetSystemInfo.exe
[2011/02/10 04:08:00 | 001,366,104 | โ- | M] (Kaspersky Lab ZAO) โ C:\abc12223.com
[2011/02/09 15:18:23 | 000,007,168 | โ- | M] () โ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:07:31 | 000,002,478 | โ- | M] () โ C:\Windows\hegames.ini
[2011/02/09 14:00:09 | 000,002,153 | โ- | M] () โ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:57:53 | 091,126,696 | โ- | M] ( ) โ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 12:46:26 | 000,190,032 | โ- | M] (Trend Micro Inc.) โ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/09 12:46:26 | 000,056,400 | โ- | M] (trend_company_name) โ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 17:14:55 | 000,053,248 | โ- | M] (eSage Lab) โ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:50:20 | 000,609,852 | โ- | M] () โ C:\Windows\System32\perfh009.dat
[2011/02/08 16:50:20 | 000,106,018 | โ- | M] () โ C:\Windows\System32\perfc009.dat
[2011/02/08 16:27:31 | 162,309,026 | โ- | M] () โ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:26 | 000,000,020 | โ- | M] () โ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ- | M] () โ C:\fsqwr.bmp
[2011/02/07 16:44:05 | 000,000,758 | โ- | M] () โ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 16:46:50 | 001,824,872 | โ- | M] () โ C:\Windows\System32\FNTCACHE.DAT
[2011/02/06 16:28:22 | 000,000,930 | โ- | M] () โ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/02 19:04:49 | 000,013,043 | โ- | M] () โ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/02/02 18:54:32 | 000,723,956 | โ- | M] () โ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/02/01 10:36:10 | 001,360,472 | โ- | M] (Kaspersky Lab ZAO) โ C:\Users\Buddy\Desktop\abc123.com
[2011/01/16 13:38:04 | 000,013,259 | โ- | M] () โ C:\Users\Buddy\Documents\PRICE LIST.docx
[2011/01/16 13:19:07 | 000,020,480 | โ- | M] () โ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ- | M] () โ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:35 | 000,092,863 | โ- | M] () โ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ- | M] () โ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/16 12:47:24 | 000,001,097 | โ- | M] () โ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/01/13 13:39:42 | 000,030,208 | โ- | M] () โ C:\Users\Buddy\Documents\Mary Collins[1].doc
[2011/01/13 12:59:00 | 000,371,808 | โ- | M] () โ C:\Users\Buddy\Documents\Untitled3.jpg
[2011/01/13 12:57:16 | 000,312,201 | โ- | M] () โ C:\Users\Buddy\Documents\Untitled.jpg
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/11 15:56:24 | 000,080,384 | โ- | C] () โ C:\Users\Buddy\Desktop\MBRCheck.exe
[2011/02/11 15:10:59 | 004,266,810 | โ- | C] () โ C:\Users\Buddy\Desktop\alg.exe
[2011/02/11 14:58:02 | 000,000,000 | โ- | C] () โ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 17:45:51 | 000,133,632 | โ- | C] () โ C:\Users\Buddy\Desktop\RKUnhookerLE.EXE
[2011/02/09 15:18:18 | 000,007,168 | โ- | C] () โ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:00:09 | 000,002,153 | โ- | C] () โ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:07:46 | 284,916,510 | โ- | C] () โ C:\Windows\MEMORY.DMP
[2011/02/09 11:31:11 | 000,002,480 | -Hโ | C] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 11:31:11 | 000,002,480 | -Hโ | C] () โ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/08 16:11:53 | 162,309,026 | โ- | C] () โ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:09 | 000,000,020 | โ- | C] () โ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ- | C] () โ C:\fsqwr.bmp
[2011/02/07 16:43:38 | 000,000,758 | โ- | C] () โ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 17:04:36 | 018,300,670 | โ- | C] () โ C:\Users\Buddy\Desktop\02 Kind Lady-2008- Extended Mix-.mp3
[2011/02/06 17:04:36 | 014,710,331 | โ- | C] () โ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/06 17:04:36 | 011,506,751 | โ- | C] () โ C:\Users\Buddy\Desktop\04 Saturday Night Love -Phunk Disco Mix-.mp3
[2011/02/02 19:04:48 | 000,013,043 | โ- | C] () โ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/01/25 16:59:09 | 000,723,956 | โ- | C] () โ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/01/16 13:19:10 | 000,020,480 | โ- | C] () โ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ- | C] () โ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:33 | 000,092,863 | โ- | C] () โ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ- | C] () โ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/13 13:39:42 | 000,030,208 | โ- | C] () โ C:\Users\Buddy\Documents\Mary Collins[1].doc
[2011/01/13 12:59:00 | 000,371,808 | โ- | C] () โ C:\Users\Buddy\Documents\Untitled3.jpg
[2011/01/13 12:57:16 | 000,312,201 | โ- | C] () โ C:\Users\Buddy\Documents\Untitled.jpg
[2011/01/09 18:10:21 | 000,000,064 | โS- | C] () โ C:\Windows\ttyxa.sys
[2010/09/19 13:17:41 | 000,087,552 | โ- | C] () โ C:\Windows\System32\cpwmon2k.dll
[2010/09/15 14:40:39 | 000,000,005 | โ- | C] () โ C:\Windows\treeskp.sys
[2010/08/30 16:46:35 | 000,084,013 | โ- | C] () โ C:\ProgramData\nvModes.001
[2010/08/30 16:35:20 | 000,084,013 | โ- | C] () โ C:\ProgramData\nvModes.dat
[2010/08/29 17:49:26 | 000,002,640 | โ- | C] () โ C:\Users\Buddy\AppData\Local\9F5CC62F-036C-4906-A900-0D8AE1702BBC.txt
[2010/07/12 13:22:56 | 000,000,019 | โ- | C] () โ C:\Windows\System32\Apache.ini
[2010/05/24 14:33:00 | 004,670,829 | โ- | C] () โ C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | โ- | C] () โ C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | โ- | C] () โ C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | โ- | C] () โ C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,810,113 | โ- | C] () โ C:\Windows\System32\xvidcore.dll
[2010/05/24 14:33:00 | 000,336,384 | โ- | C] () โ C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | โ- | C] () โ C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | โ- | C] () โ C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | โ- | C] () โ C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | โ- | C] () โ C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | โ- | C] () โ C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | โ- | C] () โ C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | โ- | C] () โ C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | โ- | C] () โ C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | โ- | C] () โ C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | โ- | C] () โ C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | โ- | C] () โ C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | โ- | C] () โ C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | โ- | C] () โ C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | โ- | C] () โ C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | โ- | C] () โ C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | โ- | C] () โ C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | โ- | C] () โ C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | โ- | C] () โ C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | โ- | C] () โ C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | โ- | C] () โ C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | โ- | C] () โ C:\Windows\System32\mkunicode.dll
[2010/03/21 13:58:38 | 000,002,202 | -HS- | C] () โ C:\ProgramData\VH56DJI7u87yo
[2010/02/21 13:19:42 | 000,000,107 | โ- | C] () โ C:\Windows\VobEdit.INI
[2009/07/31 11:51:02 | 000,237,568 | โ- | C] () โ C:\Windows\System32\rmc_rtspdl.dll
[2009/07/10 13:34:59 | 000,155,648 | โ- | C] () โ C:\Windows\System32\libssl32.dll
[2009/07/08 16:25:22 | 000,000,092 | โ- | C] () โ C:\Windows\ka.ini
[2009/07/04 16:49:09 | 000,001,374 | โ- | C] () โ C:\Windows\disney.ini
[2009/06/17 12:11:55 | 000,036,864 | โ- | C] () โ C:\Windows\System32\DirSize.dll
[2009/06/07 11:24:04 | 000,180,224 | โ- | C] () โ C:\Windows\System32\xvidvfw.dll
[2009/04/06 13:35:27 | 000,000,038 | โ- | C] () โ C:\Windows\avisplitter.INI
[2009/03/16 14:43:31 | 000,001,222 | โ- | C] () โ C:\Windows\AZPR3.INI
[2009/01/30 20:08:03 | 000,002,478 | โ- | C] () โ C:\Windows\hegames.ini
[2009/01/29 17:29:25 | 000,004,767 | โ- | C] () โ C:\Windows\Irremote.ini
[2009/01/10 17:15:44 | 000,159,744 | โ- | C] () โ C:\Windows\System32\mmfinfo.dll
[2008/11/08 11:01:58 | 000,000,000 | โ- | C] () โ C:\Windows\Transmogrifier.INI
[2008/11/06 10:37:32 | 003,596,288 | โ- | C] () โ C:\Windows\System32\qt-dx331.dll
[2008/10/12 16:52:32 | 000,000,680 | โ- | C] () โ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2008/08/17 15:48:14 | 000,000,032 | โ- | C] () โ C:\Windows\CD_Start.INI
[2008/08/05 16:18:13 | 000,036,864 | โ- | C] () โ C:\Windows\System32\DGRip.dll
[2008/08/05 16:18:08 | 000,053,248 | โ- | C] () โ C:\Windows\System32\imslevel.dll
[2008/07/24 14:07:11 | 000,000,376 | โ- | C] () โ C:\Windows\ODBC.INI
[2008/07/23 12:16:53 | 000,000,258 | RHS- | C] () โ C:\ProgramData\ntuser.pol
[2008/06/25 10:05:43 | 000,151,552 | โ- | C] () โ C:\Windows\System32\nvRegDev.dll
[2008/06/17 09:13:06 | 000,000,604 | -Hโ | C] () โ C:\ProgramData\T2
[2008/06/17 09:13:06 | 000,000,604 | -Hโ | C] () โ C:\Program Files\STLL Notifier
[2008/06/17 07:38:16 | 000,164,352 | โ- | C] () โ C:\Windows\System32\unrar.dll
[2008/06/14 03:34:18 | 000,309,664 | โ- | C] () โ C:\Windows\System32\drivers\lmqseyg.sys
[2008/06/14 03:32:52 | 000,735,664 | โ- | C] () โ C:\Windows\System32\msjehlno.dll
[2007/11/06 15:19:28 | 000,053,299 | โ- | C] () โ C:\Windows\System32\pthreadVC.dll
[2007/10/13 04:30:20 | 000,000,137 | โ- | C] () โ C:\Windows\System32\Registration.ini
[2007/06/16 21:40:13 | 000,110,592 | โ- | C] () โ C:\Windows\System32\imsispd.dll
[2006/11/02 07:35:32 | 000,005,632 | โ- | C] () โ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | โ- | C] () โ C:\Windows\System32\pacerprf.ini
[2004/03/18 17:40:32 | 000,155,648 | โ- | C] () โ C:\Windows\System32\ssleay32.dll
[2004/03/18 17:40:24 | 000,667,648 | โ- | C] () โ C:\Windows\System32\libeay32.dll
[2003/05/09 17:36:30 | 000,151,744 | โ- | C] () โ C:\Windows\System32\ir32.dll
[2002/06/06 01:01:58 | 000,029,696 | โ- | C] () โ C:\Windows\System32\asutl8.dll
========== LOP Check ==========
[2010/07/05 13:18:58 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\adma
[2009/02/05 14:26:12 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Amazon
[2009/10/08 17:21:31 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Anvil Studio
[2008/06/16 12:07:30 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Backyard Baseball 2007
[2009/07/22 16:19:52 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\BitTorrent
[2008/08/10 14:29:48 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Bullzip
[2010/07/06 12:37:20 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\calibre
[2009/05/18 18:42:43 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Computer Aces
[2009/06/19 16:45:57 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\dBpoweramp
[2009/07/10 12:29:53 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\DiskAid
[2010/01/13 16:27:35 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\DVDCreator
[2009/12/10 17:39:10 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\FileZilla
[2009/07/22 15:00:17 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\FlashgetSetup
[2010/01/04 16:09:41 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\GrabPro
[2009/04/16 15:52:32 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\ICAClient
[2010/06/18 13:23:21 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\ImgBurn
[2010/06/02 15:49:05 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\JAM Software
[2009/01/27 12:36:05 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Leadertech
[2008/06/12 17:29:25 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\LimeWire
[2010/08/15 15:10:42 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\MPEG Streamclip
[2010/08/08 12:20:03 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\MusicBrainz
[2009/08/29 15:32:31 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Netscape
[2010/11/25 13:51:25 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Neuratron
[2009/08/09 18:49:55 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Opera
[2010/01/04 16:25:33 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Orbit
[2008/07/24 13:26:53 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\PTS Charts
[2010/01/26 17:40:34 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Red Kawa
[2009/04/16 15:52:27 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Runaware
[2010/09/12 16:57:11 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Smith Micro
[2010/03/20 15:02:07 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Thinstall
[2009/09/14 16:02:26 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Trillian
[2011/02/08 15:31:08 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\TuneUpMedia
[2011/02/06 16:41:52 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\uTorrent
[2009/01/07 18:19:25 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\ViStart
[2009/01/30 17:10:22 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\VitySoft
[2010/08/11 13:53:01 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\WinFF
[2010/08/24 15:18:25 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\WNR
[2010/01/13 16:40:19 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\Xilisoft Corporation
[2009/02/16 17:18:54 | 000,000,000 | โD | M] โ C:\Users\Buddy\AppData\Roaming\XnView
[2011/02/10 16:52:52 | 000,032,526 | โ- | M] () โ C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/11 14:58:08 | 000,000,418 | -Hโ | M] () โ C:\Windows\Tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.exe >
[1998/10/26 09:50:26 | 000,012,288 | โ- | M] (Kristy Turlington) โ C:\bin2iso.exe
[2004/10/15 11:17:32 | 002,322,511 | โ- | M] () โ C:\DVDScan37.exe
[2010/07/15 15:36:12 | 000,031,275 | โ- | M] () โ C:\iso2usbld.exe
[2007/08/22 16:02:00 | 000,032,768 | โ- | M] () โ C:\mspformat.exe
[2008/08/25 22:15:57 | 027,160,064 | โ- | M] () โ C:\RainMMS.exe
[2009/06/18 00:52:10 | 000,430,592 | โ- | M] () โ C:\setup.exe
[2005/04/14 11:02:20 | 000,019,456 | โ- | M] () โ C:\ui_install.exe
[2005/03/22 12:55:24 | 000,200,767 | โ- | M] () โ C:\ul_format.exe
[2010/07/21 14:56:07 | 000,049,152 | โ- | M] () โ C:\ul_install.exe
[2007/10/30 18:17:16 | 001,810,432 | โ- | M] () โ C:\ZenoReader.exe
< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | โ- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | โ- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D โ C:\Windows\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | โ- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | โ- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | โ- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | โ- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | โ- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F โ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | โ- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 โ C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2009/06/15 10:53:24 | 000,021,504 | โ- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF โ C:\Windows\System32\svchost.exe
[2009/06/15 10:53:24 | 000,021,504 | โ- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF โ C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | โ- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 โ C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | โ- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 โ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | โ- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 โ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006/11/02 04:45:57 | 000,308,224 | โ- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD โ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | โ- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 โ C:\Windows\System32\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | โ- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 โ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /mp /s >
========== Files - Unicode (All) ==========
[2008/06/14 03:32:52 | 000,136,192 | โ- | C] ()(C:\Windows\System32\us?rinit.exe) โ C:\Windows\System32\usะตrinit.exe
[2008/01/19 02:33:33 | 000,136,192 | โ- | M] ()(C:\Windows\System32\us?rinit.exe) โ C:\Windows\System32\usะตrinit.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A5682AEF
< End of report >
and the second one:
OTL Extras logfile created on: 2/11/2011 3:58:03 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 57.22 Gb Free Space | 12.55% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32
Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] โ rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] โ Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ "%1" %*
cmdfile [open] โ "%1" %*
comfile [open] โ "%1" %*
cplfile [cplopen] โ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ "%1" %*
helpfile [open] โ Reg Error: Key error.
hlpfile [open] โ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile โ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] โ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] โ rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] โ "%1" %*
regfile [merge] โ Reg Error: Key error.
scrfile [config] โ "%1"
scrfile [install] โ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ "%1" /S
txtfile โ Reg Error: Key error.
Unknown [openas] โ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] โ "C:\Program Files\VideoLAN\VLC\vlc.exe" โstarted-from-file โplaylist-enqueue "%1" ()
Directory [Browse with XnView] โ "C:\Program Files\XnView\xnview.exe" "%1" (XnView,
http://www.xnview.com)
Directory [cmd] โ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] โ "C:\Program Files\VideoLAN\VLC\vlc.exe" โstarted-from-file โno-playlist-enqueue "%1" ()
Directory [runas] โ cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] โ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type โ File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-884816068-2633634329-2448390406-1000]
"EnableNotificationsRef" = 0
"EnableNotifications" = 3
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0038710A-A6B6-41CD-9DB5-A9E8FC939FAE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{02675B35-6399-4C07-8605-28A27FAB8F4A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{04133178-D39B-4A65-916D-EF882EE16693}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{072FFBCE-AC60-4519-A652-038EC17D4592}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{07FA89AF-722E-45C6-A102-424F2D4DDD5B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{082487FF-3623-415A-82BA-7C4A1D1F0D27}" = lport=2869 | protocol=6 | dir=in | app=system |
"{08D737F0-30B4-403A-982F-2831F36D4688}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0BF9F76E-F446-41FB-B23B-43C850F26023}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0E2E9FF6-64A0-43B5-9D6E-2A9FFA59DBFC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{1011D1DD-4D45-4CC1-902A-378B8ABA3DAF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{12AC736D-6305-4D82-B430-8FED7A6F7E66}" = lport=2869 | protocol=6 | dir=in | app=system |
"{12B67DA8-447E-45BE-BC3F-585E090C15E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{141F209E-778A-4223-94C9-08444295D16A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1BD51608-D53B-4F27-8C67-2B761076781A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1BE556D5-9DCE-451B-AF23-922CEF84FFB7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1D0C565D-0815-44F8-8D08-4380267B9D9C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{222BBB4D-2316-4644-9D3A-511E81159012}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2432BCA9-56CF-42F1-AB5C-1B560E3497D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{25B9B28A-B1F2-4042-B535-16BF3E4988C3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{26900A16-6E42-428C-95D4-6D16AB8686DB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{26B7913D-0EAC-45BA-AD6B-FBF3E94B04F6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{27210CAC-2490-4F9F-8B7B-A7998A28B254}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2D4E0C06-62C4-4FEF-9BB8-F6323A28D160}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3418E948-D7AC-45EB-A252-E645F072D1CF}" = rport=138 | protocol=17 | dir=out | app=system |
"{3652DF46-DFB8-4803-9D5C-5B740A14D04E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3A27482B-AC15-47E9-BA26-D8E5C11213F6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3B0524FF-0E24-49A6-87DA-7310FA677D80}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3B4875B2-968F-4E83-BA0A-CCFC11201E09}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3F19CCC9-1F24-443F-9ADE-7CBC240A0D17}" = lport=2869 | protocol=6 | dir=in | app=system |
"{40341610-A6E1-432D-82D1-035130DB172E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42BD5233-7CCE-4A71-9248-44BD5F243B5B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{44BF84F3-D6DF-4E08-8144-BC4867354E1B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{47ABCA2D-B361-4F0B-9781-1DE7966E67FA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{485E353C-882C-4170-90D3-597B949D2C5D}" = rport=139 | protocol=6 | dir=out | app=system |
"{4A8F6F5D-8C37-45DA-9B90-B87C3874E735}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4AA32FB7-2E84-4D2B-892B-600F3CF4FAF9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4C4D17DE-7047-44F0-B642-B0B49B1BD880}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4D0BF242-8B44-45CE-B178-D0A976080AE8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4D861D62-181C-48A2-943D-4041EB6BB425}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4E937579-16FF-42B8-AD55-9549E19E1AD0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4EE0F3AF-FFC7-47F2-AA37-6B6A12D8CCFA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{547B4C16-DB5A-4FC5-8110-45F9DCD43B66}" = lport=2869 | protocol=6 | dir=in | app=system |
"{54C55CFB-6293-457A-B43A-81BCC30F2B0F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5593ED7E-4CB6-4D67-9037-7C26DBD6C21D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{56230CEB-54A5-42C0-A0C7-60E499F53CC6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{57CBB570-C089-4E01-8393-FF189D14A3E5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{5A37A3B2-7E34-42D9-BF38-2E2EB6CC360D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5B3E831B-D7D9-423C-986B-83EB89786CB4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5F1937FB-B4A3-4BD8-A70C-B75990268984}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6285B48E-6869-451E-B064-C681DAE83376}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{633CB5E8-E304-4ED9-8C63-A6015B48600A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{689A76D7-BC75-4AD0-85E3-F88BE5421D9C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6B59CAFE-47D7-4C2E-91EB-44E8A48F1FEE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6B62AB14-1D08-493D-BD0E-0AD64A22287E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6BC3C9AF-29C8-41C2-A77D-B30E99DE7477}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6F3D7B3C-080E-4C8A-AB49-293CCC9D6DDA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6FE7EBF4-A4C9-4B1F-8D5B-EFE6A153A677}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{740C96D5-D77D-4C1E-9ED5-E728350438BB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{77047727-C053-45EA-AA07-0A831476AE0E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{78E775E3-4D5F-43A3-A941-78F8D0CAD798}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{79C37851-A5DF-4A64-94AD-C3A25A84BC6B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7A3C952B-9BC5-4AA2-B7A4-3D691D8465DD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7D7DB8FB-FF5E-4D58-8CBD-C2AEF42558BE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7F260A66-7C53-4F1A-84B2-B39367A016B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{85720613-BFD6-4559-B0FD-E7203A487FE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{86B113EF-61DF-4BB2-BB3A-F0287913E044}" = lport=2869 | protocol=6 | dir=in | app=system |
"{87AABC01-6786-4301-A35E-CEA6964F10D4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{892AB5BD-81E3-4CB9-975D-93DC2AED8A81}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{89727718-0FA9-4456-90D4-98013475A896}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{89D06362-4696-4A50-B6BA-B1EB20E95010}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8AB6A6F3-1342-4D0A-82E1-378EC086BA5C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8ADF727D-65EC-46C4-ADBF-92019CAFDC64}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8B52B786-07AA-429E-8EB0-C10FBCE6417A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8C851D2C-4DC2-4C9F-8B40-1746086883B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8DA17614-6ABE-422F-845D-FF48A47756F4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8F2C9246-A70E-4B6F-B298-6791329EF3F1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9256340F-BFEA-429E-B575-C9807DC6D00C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{97DA4303-EE85-44B8-8E8A-DECF77E40D39}" = lport=2869 | protocol=6 | dir=in | app=system |
"{99D758BA-9850-46F4-B157-FA5FF680E63C}" = lport=139 | protocol=6 | dir=in | app=system |
"{9BC64A32-EA00-49D4-8C67-187C2D6EF13A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9D803016-E55E-466B-AEA0-CB61D281D616}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9FAA681D-0480-41B7-B98D-B63F80309315}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A1F271AC-F435-4B74-86A0-3B39265A61B8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A3570CDD-52A4-4C72-983B-95FBF614B011}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A371BB45-DD44-4DF9-BED3-A664AD8792A6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A3BE162D-01E6-468D-84BB-911F9A236D3B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A4035793-D268-431F-99B4-C1D69E0F1654}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AA5C8AE6-5AFA-4322-B80D-661CE2129B80}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{ABF30DA0-DE75-4263-A7C6-D6906CB706CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AC03C9B7-6A8E-4AC5-99FD-5BA203428FD2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AD94DCBC-1A47-43F5-810D-4D50ABCA5D51}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AF13D2BD-373C-49CF-8B99-5408AE4AE955}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B0094948-604A-4E91-BB4F-D5E99FAE77B0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B0859248-C48D-47DC-9132-BA82FD59D26E}" = lport=138 | protocol=17 | dir=in | app=system |
"{B984A4A9-9886-435A-A3AD-8795F27CBA2C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB534745-2E50-492E-A050-BF3215383548}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BE18AB25-DBDF-4481-95E3-1884962B5555}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BFD94C60-7E55-4265-8D69-726A87B2AF39}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C42B860D-01EF-4774-817E-32F2BFBABB98}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C4D519BA-E541-4C08-B781-EDCF2541EAA7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CBF46718-0AF4-4BC7-8E74-AD181DE67C5C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{CE12DAF4-1593-4373-BB94-858ED82B91ED}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CF57F923-0EF8-49E5-AE22-98E4217AB2D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D220EF44-A4A5-43A9-B250-F27987C7E2F2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D31B48CD-77F8-48BB-BBE0-ACE96A6C06DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D6318E45-23A2-4EB9-A13B-25C6F48D303A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D692E065-3752-4BE6-A4DD-65E76A60991A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D92CCEAB-4B09-4D1B-8DDB-1131D7854ABE}" = rport=137 | protocol=17 | dir=out | app=system |
"{DCE53EA0-B44C-4773-A152-E0B5DEBDB63D}" = lport=445 | protocol=6 | dir=in | app=system |
"{DD477C1D-A3B3-4A46-BDE2-C48764F942A5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DDE3E533-88DA-4EDF-BA55-6C7CBA3C1897}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE6906EC-51DB-437F-801B-2E2922355DAF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE7DE82C-AC63-4241-9BB6-737B3D5EB9B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DED0A12E-B4FE-42AF-91F5-E31E7E94A8CD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E095AD90-F621-4DF5-B2D2-213E5A7E2BDE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E342BD32-C732-498D-87DF-A60BF8DB4100}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E373046A-154E-445C-8BED-6ECDCA63E13E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E3F0BDB0-E6F3-4ADF-A8AA-6524EE83FCC3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E4097165-9D17-4165-A54E-7116EB08A9D6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E4F96B15-939B-4FD4-BA65-863C233210B1}" = rport=445 | protocol=6 | dir=out | app=system |
"{E57396D3-5A48-4B07-9E57-54194C3F89A2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E66DF4A3-600E-4664-BECA-2F927EC4BDA9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E960FB48-5982-4AA9-A793-B31671DDE852}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA699B67-7AB1-4340-9DA4-D42BEA75CA21}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA69A46B-E70D-4196-B988-11B568F83332}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA840964-07B6-4819-B401-54904E20E3D2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F10059AD-2D68-47C3-9D2E-B2A7537F3E6D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F2C66EE3-4CD9-4432-88B7-3C30AD0A6302}" = lport=137 | protocol=17 | dir=in | app=system |
"{F2DCF78E-EB79-4A57-AE75-E69EFD78F000}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F74302DF-97E0-4415-B5CF-CD5B5A3196E4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{F8B8ED35-9EAC-4FE1-87DC-2E2F492F59FE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F9194DC5-0BE9-4E0D-BE94-3FDBDA78F110}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FB14F465-FDF5-471B-BF8C-F284E0D26743}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FC2C7EE4-7A98-41C1-8FA5-D869B70C2381}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FD785925-6D3C-442D-8834-95F9704AF216}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FFB0AEA1-4489-4371-9608-E6A458C1D940}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{028C1277-0547-42D2-901F-B314F41F63F9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{04071031-E0D4-42C8-81AC-1E54473F5E7F}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{04775E9C-7606-449E-BABC-4D73864D67CE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{05B338FA-3BA1-40DA-B8F7-E2406993DE76}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{061FEC75-9762-4855-A26E-9AC410FDC8A5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{06A9C4EE-E0B1-438A-B1ED-503E72D3FA24}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{0830BA37-BC0D-4EF8-8E1E-4F381BBE3289}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbir.exe |
"{084F7C45-86AD-49F5-AA9C-0E0A440EE313}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{089D0100-58A1-4F6D-B0DA-9A50F16A95F4}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{094201E1-2B1F-4834-BF93-06784EFFBF0B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{0CF1E1B4-9A2D-4799-B643-CA7E34391D25}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{0E133A97-1974-47E0-B3C7-4B3660346F5C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{102F8A87-DF45-4F03-A863-97B0013E71E4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{106ED8B4-1F00-45A2-A277-93B7097E8A7C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1176750E-798D-4C55-845A-C6B715190D7C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{11A8DD28-6B44-4145-96B7-C2BB57490124}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{11FDF9FA-CB09-41A2-A1C9-1FC09C1CDAD5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{13C9FBB3-D57C-4D63-B7C8-49BCFF71B8E3}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14914349-68CE-4544-A818-2EF28D9601DF}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14C18A59-3B00-4CEE-9A9D-C8FCB807997B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14DD9F83-9C0A-4615-9107-235DD7BDED44}" = protocol=6 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe |
"{150E2550-D576-454D-ADDF-59DA271A525D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{151E3E54-2ABA-41F9-BB52-C71A394DBC2C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{158B6896-8A9B-475F-B41C-A4F96503FADA}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{16256B54-E8C4-47DF-B230-D32AC90CD43A}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbsetupwizard.exe |
"{18987352-7F44-442B-8745-ECE1258C19B8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1B0AB08A-6720-4229-8B51-F010CA435876}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1C2597C8-AB83-4D5D-A6F5-027443C23F18}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orblauncher.exe |
"{1DEC7882-8F2C-4F5D-86C5-DA01C21E0A5C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1EA6F1FE-C1E4-4077-A09C-3010E3081493}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{1F3C8F75-8323-4636-846F-A24073B7B5FB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{204D7BB7-92F5-447C-A48D-F415EE8986CF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{24ECE452-DF94-4312-9E19-C4C979994373}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{25497AFF-C892-439C-9E45-54B5953EF72C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{27A10407-3FC3-4633-B33A-62B7D76DAF08}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{27E2E497-8777-4C2E-B67F-CD1E212A7CF4}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{2A3222CF-2F03-488C-90BB-26A1E37C6274}" = protocol=17 | dir=in | app=c:\program files\gridservice\peer.exe |
"{2A431852-FBE9-47D2-91CF-F6255957D720}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2CC2A91C-0CA7-4873-8F85-DED7891BEE1F}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{2D68F57B-BB98-422F-A041-B42B19B88C27}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2D6A2F7A-A071-4E54-8D3D-F7F4BA57B341}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2DA5AF1B-B18D-4F89-B044-A9B9478635DB}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2EC2BA18-0349-4BF3-8D58-4F7682763DE8}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2FDA6AA1-5589-4A46-B6B2-9D6D36FFD326}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{31BA544E-C4C5-446B-B6A2-492D514496C2}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orb.exe |
"{33E17E6B-B2CA-4F2B-AC5A-2277D3EB49C3}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbjetmanager.exe |
"{35B48F4C-5892-4F02-9FDC-1157F50D3C5D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{3915E601-4155-4B56-80BF-52F5C15AEE1B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{39E3A514-3258-421C-9A16-5233DD858585}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{3AF24F69-40FD-4E92-8577-6D002C6B62D5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{3BB475D3-1B94-464C-837D-E1B37AF064B0}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{3BB53E58-DFBF-43F8-B47D-D02124B8A6C4}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{3BFEF07B-031A-4040-969F-4C80CBB3513E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{3DC499E5-80B6-4972-8237-B4A653E03501}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4207DCCA-13B4-4F46-B22D-6EF90C56C4C0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{438BEEA7-F74C-4524-BDAF-5A2BB657B359}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{43F775D8-3E7B-4A88-8AF6-260214E510DA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4465BAAB-137F-4423-9AE8-1C4A79084D53}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{44EC5020-7BD1-459C-B560-5189CCC29D46}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{477BB934-476E-4E3B-8440-428FC0766140}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{49DF4CEF-2F87-473E-88F5-C131F7B6736A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4A99AA79-BBED-407B-8CE4-E9DF9F474B22}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4BA9D218-7FDD-4EC3-AF10-3D36BDAAC3B4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{513ADD08-48F6-41EC-B7F5-CD1A2BDB0E34}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{52BAB8F8-2648-4794-9A68-8FEFC4F01547}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{52C39967-1A5F-4734-A333-17D45719DE8B}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{52F3B807-9207-4552-9ABB-8C392603A3D4}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{53011F87-1243-451A-9B85-ACE66B5FFDA1}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{53521128-1B67-4A75-9ABD-30A32DFFDEEB}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{5465A2AF-500C-47D4-BCDB-050107A40E3A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{557064EB-02D6-4CE7-820B-8DD5ABAE74DD}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{56115686-40F0-4CF7-A617-A0290FA00A07}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{57179EEC-A10E-4A9C-ACED-EC388C2C545B}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{59137205-D94A-4D11-AFA1-EC337E333023}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{5955078B-D9CA-437C-B897-6837534E5578}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{5AD1A5D3-1690-4436-9790-221425851D6F}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware workstation\vmware-authd.exe |
"{5BC8DBEC-36EF-40B1-BDC0-D14AFCBFA618}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{5DA0CE24-56E0-450A-897A-36FF7EFC877A}" = protocol=6 | dir=in | app=c:\program files\gridservice\peer.exe |
"{5EE3B6CE-C13C-4A26-A7EF-572BDA921004}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60FB3409-C5BE-4E06-834B-89DE75CFB9A4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{616FE863-1F4E-4F1F-960C-05918921B6F6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{61837AC6-CA35-4448-9EFF-E012FF6FE659}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{625F90E7-B013-443D-9EF3-FAB0618659F4}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{626DBC38-97B2-455D-8597-569E73939740}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{62755CAF-9F8F-42B3-8FDA-328A8E5E853C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{63106BCA-3862-4064-A3B8-DB5A2B516270}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{63AF5338-60FF-42AB-BD1D-13DD8908539E}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orb.exe |
"{6519DBF6-28BF-4A8E-A88C-76409D8DCEDA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6587D758-F9E6-4561-8789-DC1D95E6E1FF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{6588FE6C-1470-4D3B-B4B7-CD980A6FF613}" = protocol=17 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe |
"{6AB4C37C-A52E-4DE7-A462-F408D9D23AAA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6AE57194-59A7-40A9-8317-E0E9D91793EC}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6C8F7314-AC03-4E07-B3E9-3F3EB6CE2EE6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{6FAC0B7C-9FDA-4698-8F46-5D380A56B2BE}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{703184A4-2BAD-4DC5-BBE2-F2F7EDEE09E4}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware workstation\vmware-authd.exe |
"{74A363AE-3478-4E27-9F46-47DE8248C516}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{74B25ADC-66CE-4F2E-882F-2E1155C072CF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{78D43445-74B2-4D10-9C75-57CBE92B8C1A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{79376691-CDE4-4C19-9BD0-B31D82139114}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{7C405808-C0F6-46CB-BFEB-75936215AFB7}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{7C4CD6E9-D1B9-4FD1-A039-B2FC5592F946}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{7CE1F3AF-A141-42A2-8BF5-684DFB5CEC65}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{7E98F96C-E3CF-48B9-9AA9-ABAABE9E4A4D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{7FFFA1DF-0F6D-4B7D-82FB-8D1B9BCC0422}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{817D71C0-FC58-4531-8C68-0CE4857B293A}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{81C741B2-22B8-47EA-BFAD-1188585F4A00}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{8450D329-B889-4928-B3F6-5A964EBE7F4D}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orblauncher.exe |
"{850ED9D6-DA6C-4419-9493-A9CE1AD12DB0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{88ABCE84-A4AE-4A25-804F-6EDD0E3204F7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{89E64CCF-8688-46D1-8569-29A489ACA18E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{8A069829-BDE8-4C0E-BA46-0EEF355F6C87}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{8B5F969D-DB68-4AF7-B067-1DF74FA9B9BF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{8C89145F-FA46-479E-89F1-1D57F90A2311}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9029534B-11C6-4F24-9963-D7D1C3B8E99E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{90FCF779-F77D-4ACE-85AA-7F7FEB2013FC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{925104C8-6AA4-41B6-8AEA-B6E826B196EC}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{92EE15B6-6643-408B-8CDE-50FFE6514E8B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{937C4CE6-0B91-40A3-9280-BBE6CD945A68}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{98591E0F-F9F3-4BF8-AF00-EFD623F7D9A0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{99298F5D-B351-4019-8F2C-CBFE3FD2FB28}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbtray.exe |
"{99448B74-6509-4699-9D4B-826DA7403ACB}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9A0094EE-306D-4E7E-8731-24350D31FEB6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9BEBBE0C-1322-4615-8E9E-077982D1D077}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9D8B838C-A664-4BB9-A06E-91331D3859ED}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9F0ADE44-F342-43C8-84D9-5418D1E7E676}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9F219DB4-C7CF-4474-A85B-25B886B48D45}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A1FFEED7-F5E0-41E2-9FDF-C76620BD1809}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2449480-EA2F-4787-960E-67B9296E8B87}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A29270A5-8E78-419E-A1A5-6C5B91434BF5}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A59CA635-EAF4-4B9C-B556-92EC1B91E654}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A6490E52-C09A-4CF4-B214-F85C7AB04262}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbstreamerclient.exe |
"{A993DEBD-7925-4750-AA46-F020DDE15A9E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{B0777501-548D-4827-95F8-EB9C75F2433C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{B14569F3-8ED6-4DCA-9463-6D18F67E6F7D}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbir.exe |
"{B4077713-4BFC-4CF6-ACF6-477535B74421}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{B4B06BA9-EDFB-470F-86FB-C08AA5E828FE}" = protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{B696C256-C633-436D-AC8A-373F31F84BB5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B9201CC2-2748-46F4-9920-7175EC647790}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbstreamerclient.exe |
"{B9D4BF43-4328-4826-8F9E-93BA3E363481}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{BEA9361E-B752-40EC-8EC4-E213AAAFB03B}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbtray.exe |
"{C245BB6E-88ED-4E0C-8EF2-3D1D50AE3246}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C260B664-6CA3-4A9C-8D3B-1EDDA76ACBF9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C391C8D2-DC00-4450-8FFE-A97FAE869E31}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C47F06B5-42EB-454E-B18E-462A6FB5DB58}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C47FAFEC-E1B7-4710-B072-41026F8A3695}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C5169B7B-E1BE-4637-A68B-6A0FA1ECBB1B}" = protocol=17 | dir=in | app=c:\users\buddy\appdata\local\asam.exe |
"{C522D02E-6D1B-45FC-9273-1983FEF0DF58}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C61B0329-078F-49F6-A32A-19C94C8DE62E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{C63DEDBD-89D7-4A57-B4BA-1DB8FE813F8B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C720CEAE-B0F7-4F9B-BC5F-2E6D7CE7E706}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C8CEC9A7-6B78-4231-B195-B5401BDB7D21}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C91184B9-ED64-4022-9B25-71E571C2EED7}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{CA0CA2D8-C2D0-46B9-90BC-DDCAE24C715B}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{CB2C717A-9B8D-4619-B1CE-09D74302B82C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CB48E0F2-91E6-45FF-8DB6-4C8B4CE5E5F0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CBC57300-65EC-425D-B1C6-2E6951BD859E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{CE331336-CE9B-4E10-A403-C80D5A5A8271}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CE5DD0B3-AFAA-41CD-866C-7743B07CBD13}" = protocol=17 | dir=in | app=c:\windows\system32\services.exe |
"{D03A6B8C-0B94-41DB-A426-BDC03BB9897C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4B80243-D24A-47C7-86CB-5622A8843CAA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4CD1C15-A348-4C14-90F1-B07E5D0BE7B9}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4DF6F5D-660D-4914-BB5D-1FBC8CC54343}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{D68B2B8D-DCBF-4472-8188-7E91B7588B8E}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbcontrolpanel.exe |
"{DC78CDDE-745D-4B69-8E0B-1C3E3CFEB6F9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{DCD506BE-22EE-46DE-81E4-D7A174750169}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E0226679-D331-4C0F-A207-CFB594883845}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbjetmanager.exe |
"{E0C0736E-932F-4A1A-A3BD-C6C5A60BF68B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E0D51666-8C60-42C2-A154-714C5E710018}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E1AEABA8-7391-4E61-B9E4-960123A1C8A4}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E26F5185-01C2-4933-BC4E-19CA92E02A2F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E4C492F4-C6F1-46BE-AAB1-8F04C3A996C4}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E4CCDFEE-0D6F-4B88-9992-E5B61B77894B}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{E5F4FE5F-F396-4AB1-8FFD-1B9FBE0117AF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E73C6628-CACE-4AE1-BAA1-D2FE88F37255}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E85289FD-794E-4439-84CD-478FE8E6022B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{EBFF72C6-0202-47EA-9AE2-6FB82F695B87}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbsetupwizard.exe |
"{EF1FDDDF-3FDE-4FCD-BD87-ED6D2CDA0F3F}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{F20FC67E-D2C0-4D08-9280-A03A62E764D2}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F43BC183-A780-4AF5-A9E6-8D7EBC1BA88A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{F4D13C11-B2D1-4981-96DF-AFE47B456898}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F5E9F260-B9E8-4BA1-B744-874665E8E2DB}" = protocol=6 | dir=in | app=c:\users\buddy\appdata\local\asam.exe |
"{F63F7673-1D5A-440F-8A4C-C315F06CBE62}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F798CE31-DDEB-4A8D-AC4C-9C935E634366}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F8E93EA3-0CDA-4CB0-A167-48CB10A79CC9}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F9400835-349E-4239-9F0E-78506BC44903}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FC16A81B-631E-4285-9E36-2ED043B1E03A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FED2EC95-4B39-4AF2-874C-0CA7EDA95BC3}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbcontrolpanel.exe |
"{FEE64386-291C-4E98-82B0-BECC590035BF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{FF1762E4-A361-4B57-8A8A-392CACEBF5CC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{FFA52EAE-3741-48FF-86B5-02813D1F2003}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"TCP Query User{273DF01A-B650-4132-B3B3-AFACB84A8A74}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{2E1A58C4-D54C-4562-9931-C0272791F9AF}C:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{30B0E3D7-A7D2-4859-88A3-023496653A5D}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{4F304581-CD7E-441D-9FBB-B8029DBC05C8}C:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe" = protocol=6 | dir=in | app=c:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe |
"TCP Query User{50396E98-187C-4735-A6A4-63CABE0ED212}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{5BF43656-E979-4CB8-8367-230A6DE106BD}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{5CA16B13-9C13-4562-B239-8EE931E11EE4}C:\windows\system32\msupdate.exe" = protocol=6 | dir=in | app=c:\windows\system32\msupdate.exe |
"TCP Query User{64CB1F41-EB96-4345-B6E2-8E486467FF0C}C:\program files\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=c:\program files\musicbrainz picard\picard.exe |
"TCP Query User{6732AF4E-43C7-4106-867D-96C4FFA05C9E}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"TCP Query User{6BEB4DEE-8DF5-4ACD-A382-9F5397EC1BE0}C:\program files\easymule\emule.exe" = protocol=6 | dir=in | app=c:\program files\easymule\emule.exe |
"TCP Query User{7775C53E-1ED2-4E68-BB13-7619CD288610}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{7FAFBD81-939A-4B4B-917D-A231FBB257AA}C:\users\buddy\flashget_9973_1.exe" = protocol=6 | dir=in | app=c:\users\buddy\flashget_9973_1.exe |
"TCP Query User{816AB801-B93F-474B-A769-C8F6F85B1B15}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{CEBA1429-3B70-4C60-B6F4-D8ACD70A38CA}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{D2050883-34B3-46E4-9163-2108DCBBEB7B}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{D75CA748-9AA1-47E3-82AA-EA97F6650468}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe |
"TCP Query User{FC79F710-187B-4F98-8EAD-7A54F34E2B83}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{06E88B6C-2D3C-4D39-A54C-58406EED118D}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{2DE2C14F-F900-4E99-9E9E-BDE617F5FC91}C:\users\buddy\flashget_9973_1.exe" = protocol=17 | dir=in | app=c:\users\buddy\flashget_9973_1.exe |
"UDP Query User{33EE43B4-F7ED-48B7-BF5F-2381E0740FC9}C:\program files\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=c:\program files\musicbrainz picard\picard.exe |
"UDP Query User{41F0EB9A-6964-46EE-8BCD-5402724C9542}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{43C7B7BE-2A39-4326-B7CE-19E88A4FAB66}C:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{4C1247DA-87E8-488E-919A-EEEA7C0353F4}C:\program files\easymule\emule.exe" = protocol=17 | dir=in | app=c:\program files\easymule\emule.exe |
"UDP Query User{4F8F1E4D-CE3B-4908-AB4D-0657CBC5DBB3}C:\windows\system32\msupdate.exe" = protocol=17 | dir=in | app=c:\windows\system32\msupdate.exe |
"UDP Query User{55179B5A-1474-47B5-BCA9-16C3192E5809}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe |
"UDP Query User{62440872-4C4B-42A3-B02D-1ACC3B018480}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"UDP Query User{990C0DED-2BE7-477E-BEEE-2425ABB96DF2}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{B5168D4C-2609-4B46-9365-14EF9A9F07D6}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{CD25C382-A4A1-41F0-8E1A-4213771373FB}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{D24D7225-C5C0-4E85-807A-DF7EF385A836}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{E6EE78A1-126F-4F94-9D54-A9AD0C5EFD4E}C:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe" = protocol=17 | dir=in | app=c:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe |
"UDP Query User{E8C30749-253D-49EC-BE24-3C5F24D8A65C}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{F39C1798-555F-41E0-B99B-046FF9E46A0D}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{FDE81636-31CD-4646-AC4F-90CC25AAE05D}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08DEC21F-F7E5-46F9-81D1-3ED30BD3AEC9}" = CASIO USB Driver V1.2.2474.0623
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Javaโข 6 Update 13
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Javaโข 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Javaโข 6 Update 7
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36C9E08A-BE2B-40A0-83C5-576748F7B777}" = TestDrive Client
"{37003C6E-DC86-4233-B5CE-665D82DFA7EB}" = Backyard Skateboarding
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47609E69-4C5E-48B1-A889-24C6B82B5C04}" = Vista Shortcut Manager
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{495B6040-801F-474C-ADB8-309F132CF5F9}" = iPhoneBrowser
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F}" = GetDataBack for NTFS
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Simsโข 2 Teen Style Stuff
"{5D51C5DC-3604-4C3B-981B-309340755447}" = Pantech Handset Driver
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5DC0DF76-3B2F-4C38-BE34-58627949BC1A}" = Mega Manager
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{601D774D-0D04-4CB1-9E3B-5394FAAFA1FB}" = VMware DiskMount Utility
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64963F0E-03F2-4B59-8D1B-1806545E7092}" = NVIDIA DDS Utilities
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Simsโข 2 Kitchen & Bath Interior Design Stuff
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6DF94034-2D3C-4D67-ABE7-1C728399B963}_is1" = PDF Rider 0.4
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Simsโข 2 IKEAยฎ Home Stuff
"{6E7F1130-F68A-46A1-96ED-5BFE51A3A605}" = Backyard Baseball 2005
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Simsโข 2 H&M;ยฎ Fashion Stuff
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{85F4CBCB-9BBC-4B50-A7D8-E1106771498D}" = Orca
"{86488BFF-6368-4EB9-8567-BA2E2E2BDB20}_is1" = ZipScan Evaluation 2.2c
"{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Simsโข 2 FreeTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{68D57797-481D-4FAA-A53A-060E8EE67654}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{945126B3-E790-45FE-A5B4-D108DB681B61}" = Sibelius Scorch (ActiveX Only)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A20DF6AC-0300-45E2-8152-7D677E4E8CF5}" = HotFile AutoDownloader
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3BC1DBD-64D6-4EBC-0091-24C811662D40}" = Madden NFL 08
"{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation
"{A5CD6670-1F48-45A3-B3E4-8238FECD1FA5}" = File Downloader
"{A638557B-1F13-40A0-9627-C892FBCA6960}" = McAfee Agent
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A90C03D6-08E1-4C59-B93B-6919A6C0AC19}" = TSP_CODEC
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AFD4597D-56CC-447F-AA68-C1BF1AEA448E}_is1" = RipTiger 2.7.4
"{B0B46A1F-EC96-44A4-A9FB-62FE33BAF7DE}" = Rapidshare Auto Downloader 4.1
"{B1526BF0-3991-4899-9998-78BCC746C256}" = Help 1.0
"{B1EDEBF1-B4DA-46A5-B346-D1B580548EAA}" = iPhone Folders
"{B2AB8AF6-AE06-438F-A3D5-C9FBFBDB0AC0}" = Backyard Basketball 2004
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BEE7766E-C99F-4735-A42B-77924324F253}" = Backyard Soccer 2004
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Simsโข 3
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem Driver
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}" = Windows Vista Upgrade Advisor
"{CBF9963A-C3CB-4676-BDEA-78C2BC1055E8}" = calibre
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}" = WinZip 11.2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D6D4828F-A5B2-11D4-8F73-0050DA0F6297}" = The Sims File Cop
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Simsโข 2 Seasons
"{E0B289FB-8053-099A-59E4-CC825EA4F3CB}" = MDownloader
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7269FD6-34EA-4617-8752-6739AA384080}" = V CAST Media Manager
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Simsโข 2 Celebration! Stuff
"{F00A3A54-C293-8F64-7C6D-9A4C09106FD8}" = Antivirus 2010
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0EB3969-C007-4ABE-9245-990C5E021A8F}_is1" = Sibelius Sounds Essentials for Sibelius 6
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Simsโข 2 Bon Voyage
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7
"{FB068BA4-C6EA-4D47-A491-C40E23E77F89}" = Motorola Driver Installation 3.9.0
"{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}" = Folder Size for Windows
"{FDF64A37-4842-48CD-A424-2C38444D36FD}" = LG Android Drivers
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"7-Zip" = 7-Zip 4.57
"A7563CE811A177DD86E2680F4A65B8D083CE4D72" = Windows Driver Package - ViXS Systems Inc. ViXS PureTV-U (12/07/2007 6.2.100.12)
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Advanced FTP Password Recovery" = Advanced FTP Password Recovery (remove only)
"Advanced ZIP Password Recovery" = Advanced ZIP Password Recovery
"AFPL Ghostscript 8.53" = AFPL Ghostscript 8.53
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AsUninst.exe" = Anvil Studio
"Audacity_is1" = Audacity 1.2.6
"AviSynth" = AviSynth 2.5
"Backyard Baseball 2003" = Backyard Baseball 2003
"Backyard Basketball" = Backyard Basketball
"Backyard Football" = Backyard Football
"Backyard Soccer MLS Edition" = Backyard Soccer MLS Edition
"Barbieโข Beach Vacationโข" = Barbie Beach Vacation
"BitrateView" = BitrateView
"BlackBerry_{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"blueprint ObjectEditor_is1" = blueprint ObjectEditor 1.0.0
"CEP - Colour Enable Packages_is1" = CEP - Color Enable Package
"CNXT_MODEM_PCI_HSF" = Soft Data Fax Modem with SmartCP
"CodecInstaller" = CodecInstaller 2.10.1
"Color Correction Wizard_is1" = Color Correction Wizard 1.1
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Digital Ear4" = Digital Ear
"DivX Setup.divx.com" = DivX Setup
"D-Link VGA Webcam" = D-Link VGA Webcam
"Download Manager" = Download Manager 2.3.9
"DragonUnPACKer5_is1" = Dragon UnPACKer 5
"DScaler 4.1.15_is1" = DScaler 4.1.15
"Duplicate Music Files Finder_is1" = Duplicate Music Files Finder 1.5.5
"DVD Shrink_is1" = DVD Shrink 3.2
"easyMule" = easyMule
"Elecard MPEG-2 PlugIn for WMP 4.1.100318" = Elecard MPEG-2 PlugIn for WMP
"Emicsoft HD Video Converter_is1" = Emicsoft HD Video Converter
"eMule" = eMule
"ESET Online Scanner" = ESET Online Scanner v3
"FAR Edit Version 1.0_is1" = FAR Edit Version 1.0
"ffdshow_is1" = ffdshow [rev 2975] [2009-05-28]
"FileZilla Client" = FileZilla Client [removed]
"FLAC" = FLAC 1.2.1b (remove only)
"FLV to AVI MPEG WMV 3GP MP4 iPod Converter_is1" = FLV to AVI MPEG WMV 3GP MP4 iPod Converter 5.2.0603
"FLVCodec" = PlayFLV
"Game Extractor" = Game Extractor 2.0
"Google Earth Pro 4.2" = Google Earth Pro 4.2
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Gtk+ Runtime Environment" = Gtk+ Runtime Environment 2.12.9-2
"ImgBurn" = ImgBurn
"ImTOO iPod Manager" = ImTOO iPod Computer Transfer
"InstallShield_{B2AB8AF6-AE06-438F-A3D5-C9FBFBDB0AC0}" = Backyard Basketball 2004
"InstallShield_{BEE7766E-C99F-4735-A42B-77924324F253}" = Backyard Soccer 2004
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"IsoBuster_is1" = IsoBuster 2.8
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"Magic Video Converter_is1" = Magic Video Converter 8.7.10.189
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"MediaPortal" = MediaPortal
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MixMeister BPM Analyzer_is1" = MixMeister BPM Analyzer 1.0
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"MusicBrainz Picard" = MusicBrainz Picard
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"Netscape Navigator ([removed])" = Netscape Navigator ([removed])
"Network Play System (Patching)" = Network Play System (Patching)
"Neuratron AudioScore Lite" = Neuratron AudioScore Lite
"Neuratron AudioScore Ultimate Demo" = Neuratron AudioScore Ultimate Demo
"Neuratron PhotoScore Lite" = Neuratron PhotoScore Lite
"Neuratron PhotoScore Ultimate" = Neuratron PhotoScore Ultimate
"Neuratron PhotoScore Ultimate Demo" = Neuratron PhotoScore Ultimate Demo
"Nick-O-Matic Design Factory 1.0" = Nick-O-Matic Design Factory
"NirSoft ShellExView" = NirSoft ShellExView
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"nzb" = nzb
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Ogg Codecs" = Ogg Codecs 0.81.15562
"oggcodecs" = oggcodecs 0.71.0946
"OpenSSL_is1" = OpenSSL 0.9.6m
"Orb" = Orb
"pdfsam" = pdfsam
"plist Editor for Windows" = plist Editor for Windows 1.0.2
"PowerISO" = PowerISO
"ProxySwitcher Standard_is1" = ProxySwitcher Standard
"PSP Video 9" = PSP Video 9 5.03
"PTS Box and Whisker Charter_is1" = PTS Box and Whisker Charter 1.03
"RADVideo" = RAD Video Tools
"RaySource" = RaySource 2.1.10.8366
"RealAlt_is1" = Real Alternative 1.9.0
"RealPlayer 12.0" = RealPlayer
"Replay Media Catcher 3.02" = Replay Media Catcher 3.02
"ShadowExplorer_is1" = ShadowExplorer 0.4
"Sibelius 6_is1" = Sibelius [removed]
"Sibelius Sounds Essentials" = Sibelius Sounds Essentials
"SimPE_is1" = SimPE 0.68 (alpha)
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"StepMania" = StepMania (remove only)
"SystemRequirementsLab" = System Requirements Lab
"Tau Producer" = Tau Producer (remove only)
"TiLP2_is1" = TiLP2 1.14
"TreeSize Free_is1" = TreeSize Free V2.4
"True Audio DirectShow Codecs Suite" = True Audio DirectShow Codecs Suite (remove only)
"TuneUpMedia" = TuneUp Companion 1.9.0
"Tunnelier" = Bitvise Tunnelier 4.35 (remove only)
"Unlocker" = Unlocker 1.9.0
"vghd" = VirtuaGuy HD
"Videora iPod touch Converter" = Videora iPod touch Converter 5.04
"VLC media player" = VLC media player 1.1.2
"VMware_Workstation" = VMware Workstation
"Who Wants To Be A Millionaire Kids Edition" = Who Wants To Be A Millionaire Kids Edition
"Willowrd.exe" = Willow Road Screen Art
"WinFF_is1" = WinFF 1.2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"Wondershare HD Video Converter_is1" = Wondershare HD Video Converter(Build [removed])
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"XnView_is1" = XnView 1.95.4
"Xvid_is1" = Xvid 1.2.1 final uninstall
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"aaa" = aaa
"Advanced Archive Password Recovery" = Advanced Archive Password Recovery
"BitTorrent" = BitTorrent
"f031ef6ac137efc5" = Dell Driver Download Manager
"intelliScore Polyphonic WAV to MIDI Converter Demo" = intelliScore Polyphonic WAV to MIDI Converter Demo
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"uTorrent" = ยตTorrent
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >