whiteroses35
Topic Starter
OTL files
OTL logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS
Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKslcf5aed6f) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EB0F1EF3-DC3E-4640-A472-2910BAC289C4}\MpKslcf5aed6f.sys (Microsoft Corporation)
DRV - (X4HSEx) – C:\Program Files\Free Ride Games\X4HSEx.sys (Exent Technologies Ltd.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000 (08B0) – C:\WINDOWS\system32\drivers\CamDrO21.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.pogo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.pogo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {de404f4c-3cde-4d74-a6fb-052d099c104c}:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.2.0
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/12/09 07:39:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/09 17:54:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 06:07:47 | 000,000,000 | —D | M]
[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions
[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions\[removed]
[2011/05/01 12:03:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions
[2010/06/27 06:34:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/26 09:49:38 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/03/01 06:12:31 | 000,000,000 | —D | M] ("StumbleUpon") – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/03/26 09:49:34 | 000,000,000 | —D | M] (Messenger Plus Live US Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{de404f4c-3cde-4d74-a6fb-052d099c104c}
[2011/03/26 09:49:33 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/03/26 09:49:37 | 000,000,000 | —D | M] (Oberon GamesBar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/02/13 08:28:34 | 000,001,919 | —- | M] () – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\searchplugins\bing-zugo.xml
[2011/04/30 08:23:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 11:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\MERI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QT57T2B0.DEFAULT\EXTENSIONS\{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 09:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/02/13 08:28:49 | 000,002,191 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/09/20 11:06:19 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober19934781.xml
[2011/04/28 05:27:18 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober2202375.xml
[2011/04/27 06:27:14 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober3372062.xml
O1 HOSTS File: ([2008/08/21 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (no name) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKCU..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} http://launch.soe.com/plugin/web/SOEWebInstaller.cab (SOE Web Installer)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1270808702234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - TPSvc.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/02 19:11:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/02 06:46:50 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/01 12:05:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\meri\Recent
[2011/05/01 12:03:29 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/05/01 11:52:07 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:52:07 | 000,056,400 | —- | C] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:07 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\log
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\HiJackThis
[2011/05/01 08:38:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/04/28 05:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Pogo Games
[2011/04/27 06:29:25 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/27 06:27:08 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2011/04/27 06:27:01 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2011/04/26 08:06:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/26 08:05:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/26 08:05:53 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/20 07:27:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/04/02 08:16:59 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2011/04/02 08:11:03 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Free Ride Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Program Files\Playalot Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Playalot Games
[2011/04/02 08:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 08:05:23 | 000,053,314 | —- | C] (Exent Technologies Ltd.) – C:\WINDOWS\ExentInfo.exe
[2011/04/02 08:05:14 | 000,000,000 | —D | C] – C:\Program Files\Free Ride Games
[2011/04/02 08:05:10 | 000,000,000 | —D | C] – C:\Remote Programs
[2011/04/02 07:11:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/02 06:42:50 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/02 06:29:35 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 06:29:20 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/02 06:29:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/02 06:14:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 12:54:45 | 000,002,349 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InSpheration.lnk
[2011/05/01 12:43:16 | 000,002,345 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WordSlinger.lnk
[2011/05/01 11:59:38 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/05/01 11:52:07 | 000,056,400 | —- | M] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:06 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:48:21 | 000,002,445 | —- | M] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | M] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:51:21 | 000,002,032 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 09:33:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/28 05:28:30 | 000,001,861 | —- | M] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/16 03:23:33 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:06:38 | 000,435,688 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/16 03:06:38 | 000,068,584 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/12 04:41:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/06 10:48:01 | 000,000,354 | —- | M] () – C:\Documents and Settings\meri\Desktop\Hausernet Decoy Entry Web Site.url
[2011/04/02 08:05:30 | 000,000,064 | —- | M] () – C:\WINDOWS\GPlrLanc.dat
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/01 11:59:38 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/05/01 11:47:52 | 000,002,445 | —- | C] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | C] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:50:35 | 000,002,032 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 10:45:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/28 05:28:30 | 000,001,861 | —- | C] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/12 04:41:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/02 08:05:30 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2011/02/13 14:28:04 | 000,000,449 | —- | C] () – C:\Program Files\0213201113280473.bat
[2011/01/15 11:05:01 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2011/01/15 11:05:01 | 000,000,180 | —- | C] () – C:\WINDOWS\ap561.ini
[2011/01/15 11:05:00 | 000,014,385 | —- | C] () – C:\WINDOWS\Tw561a.ini
[2011/01/15 11:05:00 | 000,000,081 | —- | C] () – C:\WINDOWS\Setup8a.ini
[2010/09/28 08:40:10 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/09/20 11:34:28 | 000,000,015 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2010/05/02 07:57:20 | 000,000,030 | —- | C] () – C:\WINDOWS\iedit.INI
[2010/04/12 12:30:56 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/10 10:12:30 | 000,000,116 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2010/04/10 10:04:43 | 000,000,387 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/04/10 10:04:40 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/04/08 15:44:22 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2009/12/03 10:46:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/12/02 19:13:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/12/02 19:10:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/12/02 18:00:56 | 000,000,131 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[2009/12/02 18:00:54 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2009/12/02 18:00:54 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2009/12/02 18:00:54 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2009/12/02 18:00:54 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2009/12/02 18:00:54 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2009/12/02 18:00:50 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/12/02 18:00:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/12/02 18:00:49 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2009/12/02 18:00:49 | 000,435,688 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/02 18:00:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2009/12/02 18:00:49 | 000,068,584 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/02 18:00:49 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2009/12/02 18:00:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2009/12/02 18:00:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/12/02 18:00:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2009/12/02 18:00:44 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2009/12/02 18:00:44 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2009/12/02 11:06:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/12/02 11:05:49 | 000,330,688 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
========== LOP Check ==========
[2010/04/10 10:05:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/01 16:18:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/04/26 08:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/01 18:06:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/04/01 18:01:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011/04/02 07:11:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2011/04/26 08:06:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/04/26 08:05:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/01 18:00:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2011/04/02 08:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 10:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2010/10/20 06:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GAMEON
[2011/05/01 08:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Merscom
[2010/06/27 06:30:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2011/01/09 05:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2011/04/28 05:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/04/08 15:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/23 06:20:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Qwest
[2011/04/20 07:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/05/01 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/01/11 08:14:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/04/30 11:54:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/15 13:23:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/01/15 16:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/04/08 15:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\CallingID
[2011/04/26 08:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/01 17:55:54 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon Easy-WebPrint EX
[2011/04/02 08:16:59 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2010/06/23 06:33:02 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Facebook
[2011/02/13 11:17:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\GameHouse
[2010/11/16 08:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\LimeWire
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Merscom
[2011/04/28 04:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/28 05:28:48 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2010/11/05 11:18:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Post-it® Photo Organizer
[2011/05/01 12:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/04/13 15:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Sony Online Entertainment
[2011/04/27 04:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\StumbleUpon
[2010/10/16 04:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\TitanicMystery
[2010/05/02 07:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Ulead Systems
[2010/04/26 09:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Unity
[2011/02/13 08:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\vmntemplate
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/04/08 14:48:22 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/08 15:50:23 | 000,000,170 | —- | M] () – C:\caEntitlementLog.txt
[2010/04/08 15:56:59 | 000,351,652 | —- | M] () – C:\caisslog.txt
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/09 03:29:30 | 000,004,828 | —- | M] () – C:\Facilitator.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/28 12:13:29 | 000,000,078 | —- | M] () – C:\lxcy.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/02 06:29:14 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/04/10 10:05:21 | 000,000,168 | —- | M] () – C:\setupfax.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/12/02 19:11:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2010/04/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 16:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/02/13 14:28:04 | 000,000,449 | —- | M] () – C:\Program Files\0213201113280473.bat
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/12/02 11:05:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/12/02 11:05:17 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/12/02 11:05:16 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/12/03 10:46:44 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2009/12/02 19:14:36 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/08 14:48:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/12/02 19:19:00 | 000,000,079 | —- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2002/08/13 19:01:26 | 000,007,431 | —- | M] () – C:\WINDOWS\Tw561a.src
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 10:03:21
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48FEB33
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE8D8202
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:813B8EB6
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03392111
< End of report >
OTL Extras logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS
Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"59160:TCP" = 59160:TCP:*:Enabled:Pando
"59160:UDP" = 59160:UDP:*:Enabled:Pando
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando – (Pando Networks)
"C:\WINDOWS\system32\lxcycoms.exe" = C:\WINDOWS\system32\lxcycoms.exe:*:Enabled:3400 Series Server
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18B148B8-50B0-4DD9-B017-18713B782F85}" = WordSlinger
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 20
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A3532ED-A121-4297-AA4F-70B60E4BD631}" = Playalot Games
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{693EF7BC-C5CA-43E6-AFA8-1F3FB63A8D92}" = Qwest Windows Live Toolbar Buttons
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112270203}" = Dream Day Wedding
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118367707}" = FREE Dream Day Honeymoon
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A63E18AC-B504-4045-AFE6-A279BBABB988}" = Qwest QuickAssist Desktop Tools
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6F65BE1-D11E-42EE-9389-84C124B905B4}" = InSpheration
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C96FF998-45BD-411E-9253-B7F2660FE280}" = Qwest Installer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"amg-1912titanicmystery" = 1912 Titanic Mystery
"amg-3cardstodeadtime" = 3 Cards to Dead Time
"amg-affairbureau" = Affair Bureau
"amg-alohasolitaire" = Aloha Solitaire
"amg-autumnstreasuresthejadecoin" = Autumn's Treasures - The Jade Coin
"amg-biggestlittleadventure" = Biggest Little Adventure
"amg-chameleongems" = Chameleon Gems
"amg-fashionassistant" = Fashion Assistant
"amg-frankensteinthedismemberedbride" = FRANKENSTEIN - The Dismembered Bride
"amg-gamehousesolitairechallenge" = GameHouse Solitaire Challenge
"amg-hiddenmagic" = Hidden Magic
"amg-janeangeltemplarmystery" = Jane Angel - Templar Mystery
"amg-jewelcharm" = Jewel Charm
"amg-liongthelostamulets" = Liong - The Lost Amulets
"amg-mahjongginvestigationsundersuspicion" = Mahjongg Investigations - Under Suspicion
"amg-mysterylegendstmsleepyhollow" = Mystery Legends™ - Sleepy Hollow
"amg-nataliebrooksmysteryathillcresthigh" = Natalie Brooks - Mystery at Hillcrest High
"amg-puzzlesolitaire" = Puzzle Solitaire
"amg-strikeball3" = Strike Ball 3
"amg-sunsetstudioloveonthehighseas" = Sunset Studio - Love on the High Seas
"amg-supercollapsepuzzlegallery4" = Super Collapse! Puzzle Gallery 4
"amg-thelostcasesofsherlockholmes" = The Lost Cases of Sherlock Holmes
"amg-thetreasuresofmysteryisland" = The Treasures of Mystery Island
"amg-thetudors" = The Tudors
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"exent_466550" = The Treasures of Montezuma
"exent_554750" = Cradle of Rome
"exent_605350" = Magic Encyclopedia
"exent_668050" = Farm Mania 2
"exent_695650" = Little Shop - Memories
"GamesBar" = GamesBar [removed]
"ie8" = Windows Internet Explorer 8
"Little Shop of Treasures 2" = Little Shop of Treasures 2
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSNINST" = MSN
"mspheres_is1" = Magic Spheres v1.0
"Rainbow Web II" = Rainbow Web II
"UnityWebPlayer" = Unity Web Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"Works2kSetup" = Microsoft Works 2000 Setup Launcher
"WT086164" = Monster Mash
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"SOE-Clone Wars" = Clone Wars
"SOE-Free Realms" = Free Realms
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/29/2011 3:15:44 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 3:55:29 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:36:26 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:37:59 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:38:30 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/30/2011 11:39:54 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:19:54 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:19:57 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:20:00 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 2:35:24 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11722
Description = Product: STOPzilla – Message 1722. STOPzilla has canceled the removal
process!
[ System Events ]
Error - 5/1/2011 8:48:36 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 11:35:55 AM | Computer Name = YOUR-845F836F3D | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).
Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
< End of report >
OTL logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS
Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)
========== Driver Services (SafeList) ==========
DRV - (MpKslcf5aed6f) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EB0F1EF3-DC3E-4640-A472-2910BAC289C4}\MpKslcf5aed6f.sys (Microsoft Corporation)
DRV - (X4HSEx) – C:\Program Files\Free Ride Games\X4HSEx.sys (Exent Technologies Ltd.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000 (08B0) – C:\WINDOWS\system32\drivers\CamDrO21.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.pogo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.pogo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {de404f4c-3cde-4d74-a6fb-052d099c104c}:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.2.0
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/12/09 07:39:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/09 17:54:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 06:07:47 | 000,000,000 | —D | M]
[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions
[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions\[removed]
[2011/05/01 12:03:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions
[2010/06/27 06:34:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/26 09:49:38 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/03/01 06:12:31 | 000,000,000 | —D | M] ("StumbleUpon") – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/03/26 09:49:34 | 000,000,000 | —D | M] (Messenger Plus Live US Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{de404f4c-3cde-4d74-a6fb-052d099c104c}
[2011/03/26 09:49:33 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/03/26 09:49:37 | 000,000,000 | —D | M] (Oberon GamesBar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/02/13 08:28:34 | 000,001,919 | —- | M] () – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\searchplugins\bing-zugo.xml
[2011/04/30 08:23:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 11:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\MERI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QT57T2B0.DEFAULT\EXTENSIONS\{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 09:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/02/13 08:28:49 | 000,002,191 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/09/20 11:06:19 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober19934781.xml
[2011/04/28 05:27:18 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober2202375.xml
[2011/04/27 06:27:14 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober3372062.xml
O1 HOSTS File: ([2008/08/21 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (no name) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKCU..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} http://launch.soe.com/plugin/web/SOEWebInstaller.cab (SOE Web Installer)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1270808702234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - TPSvc.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/02 19:11:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/02 06:46:50 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/01 12:05:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\meri\Recent
[2011/05/01 12:03:29 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/05/01 11:52:07 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:52:07 | 000,056,400 | —- | C] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:07 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\log
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\HiJackThis
[2011/05/01 08:38:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/04/28 05:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Pogo Games
[2011/04/27 06:29:25 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/27 06:27:08 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2011/04/27 06:27:01 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2011/04/26 08:06:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/26 08:05:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/26 08:05:53 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/20 07:27:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/04/02 08:16:59 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2011/04/02 08:11:03 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Free Ride Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Program Files\Playalot Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Playalot Games
[2011/04/02 08:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 08:05:23 | 000,053,314 | —- | C] (Exent Technologies Ltd.) – C:\WINDOWS\ExentInfo.exe
[2011/04/02 08:05:14 | 000,000,000 | —D | C] – C:\Program Files\Free Ride Games
[2011/04/02 08:05:10 | 000,000,000 | —D | C] – C:\Remote Programs
[2011/04/02 07:11:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/02 06:42:50 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/02 06:29:35 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 06:29:20 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/02 06:29:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/02 06:14:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 12:54:45 | 000,002,349 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InSpheration.lnk
[2011/05/01 12:43:16 | 000,002,345 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WordSlinger.lnk
[2011/05/01 11:59:38 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/05/01 11:52:07 | 000,056,400 | —- | M] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:06 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:48:21 | 000,002,445 | —- | M] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | M] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:51:21 | 000,002,032 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 09:33:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/28 05:28:30 | 000,001,861 | —- | M] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/16 03:23:33 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:06:38 | 000,435,688 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/16 03:06:38 | 000,068,584 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/12 04:41:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/06 10:48:01 | 000,000,354 | —- | M] () – C:\Documents and Settings\meri\Desktop\Hausernet Decoy Entry Web Site.url
[2011/04/02 08:05:30 | 000,000,064 | —- | M] () – C:\WINDOWS\GPlrLanc.dat
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/01 11:59:38 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/05/01 11:47:52 | 000,002,445 | —- | C] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | C] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:50:35 | 000,002,032 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 10:45:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/28 05:28:30 | 000,001,861 | —- | C] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/12 04:41:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/02 08:05:30 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2011/02/13 14:28:04 | 000,000,449 | —- | C] () – C:\Program Files\0213201113280473.bat
[2011/01/15 11:05:01 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2011/01/15 11:05:01 | 000,000,180 | —- | C] () – C:\WINDOWS\ap561.ini
[2011/01/15 11:05:00 | 000,014,385 | —- | C] () – C:\WINDOWS\Tw561a.ini
[2011/01/15 11:05:00 | 000,000,081 | —- | C] () – C:\WINDOWS\Setup8a.ini
[2010/09/28 08:40:10 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/09/20 11:34:28 | 000,000,015 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2010/05/02 07:57:20 | 000,000,030 | —- | C] () – C:\WINDOWS\iedit.INI
[2010/04/12 12:30:56 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/10 10:12:30 | 000,000,116 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2010/04/10 10:04:43 | 000,000,387 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/04/10 10:04:40 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/04/08 15:44:22 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2009/12/03 10:46:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/12/02 19:13:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/12/02 19:10:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/12/02 18:00:56 | 000,000,131 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[2009/12/02 18:00:54 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2009/12/02 18:00:54 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2009/12/02 18:00:54 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2009/12/02 18:00:54 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2009/12/02 18:00:54 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2009/12/02 18:00:50 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/12/02 18:00:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/12/02 18:00:49 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2009/12/02 18:00:49 | 000,435,688 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/02 18:00:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2009/12/02 18:00:49 | 000,068,584 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/02 18:00:49 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2009/12/02 18:00:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2009/12/02 18:00:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/12/02 18:00:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2009/12/02 18:00:44 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2009/12/02 18:00:44 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2009/12/02 11:06:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/12/02 11:05:49 | 000,330,688 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
========== LOP Check ==========
[2010/04/10 10:05:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/01 16:18:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/04/26 08:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/01 18:06:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/04/01 18:01:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011/04/02 07:11:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2011/04/26 08:06:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/04/26 08:05:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/01 18:00:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2011/04/02 08:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 10:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2010/10/20 06:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GAMEON
[2011/05/01 08:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Merscom
[2010/06/27 06:30:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2011/01/09 05:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2011/04/28 05:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/04/08 15:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/23 06:20:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Qwest
[2011/04/20 07:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/05/01 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/01/11 08:14:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/04/30 11:54:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/15 13:23:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/01/15 16:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/04/08 15:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\CallingID
[2011/04/26 08:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/01 17:55:54 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon Easy-WebPrint EX
[2011/04/02 08:16:59 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2010/06/23 06:33:02 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Facebook
[2011/02/13 11:17:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\GameHouse
[2010/11/16 08:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\LimeWire
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Merscom
[2011/04/28 04:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/28 05:28:48 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2010/11/05 11:18:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Post-it® Photo Organizer
[2011/05/01 12:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/04/13 15:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Sony Online Entertainment
[2011/04/27 04:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\StumbleUpon
[2010/10/16 04:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\TitanicMystery
[2010/05/02 07:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Ulead Systems
[2010/04/26 09:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Unity
[2011/02/13 08:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\vmntemplate
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/04/08 14:48:22 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/08 15:50:23 | 000,000,170 | —- | M] () – C:\caEntitlementLog.txt
[2010/04/08 15:56:59 | 000,351,652 | —- | M] () – C:\caisslog.txt
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/09 03:29:30 | 000,004,828 | —- | M] () – C:\Facilitator.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/28 12:13:29 | 000,000,078 | —- | M] () – C:\lxcy.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/02 06:29:14 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/04/10 10:05:21 | 000,000,168 | —- | M] () – C:\setupfax.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/12/02 19:11:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2010/04/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 16:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2011/02/13 14:28:04 | 000,000,449 | —- | M] () – C:\Program Files\0213201113280473.bat
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/12/02 11:05:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/12/02 11:05:17 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/12/02 11:05:16 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/12/03 10:46:44 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2009/12/02 19:14:36 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/08 14:48:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/12/02 19:19:00 | 000,000,079 | —- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2002/08/13 19:01:26 | 000,007,431 | —- | M] () – C:\WINDOWS\Tw561a.src
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 10:03:21
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48FEB33
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE8D8202
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:813B8EB6
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03392111
< End of report >
OTL Extras logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS
Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"59160:TCP" = 59160:TCP:*:Enabled:Pando
"59160:UDP" = 59160:UDP:*:Enabled:Pando
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando – (Pando Networks)
"C:\WINDOWS\system32\lxcycoms.exe" = C:\WINDOWS\system32\lxcycoms.exe:*:Enabled:3400 Series Server
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18B148B8-50B0-4DD9-B017-18713B782F85}" = WordSlinger
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 20
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A3532ED-A121-4297-AA4F-70B60E4BD631}" = Playalot Games
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{693EF7BC-C5CA-43E6-AFA8-1F3FB63A8D92}" = Qwest Windows Live Toolbar Buttons
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112270203}" = Dream Day Wedding
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118367707}" = FREE Dream Day Honeymoon
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A63E18AC-B504-4045-AFE6-A279BBABB988}" = Qwest QuickAssist Desktop Tools
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6F65BE1-D11E-42EE-9389-84C124B905B4}" = InSpheration
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C96FF998-45BD-411E-9253-B7F2660FE280}" = Qwest Installer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"amg-1912titanicmystery" = 1912 Titanic Mystery
"amg-3cardstodeadtime" = 3 Cards to Dead Time
"amg-affairbureau" = Affair Bureau
"amg-alohasolitaire" = Aloha Solitaire
"amg-autumnstreasuresthejadecoin" = Autumn's Treasures - The Jade Coin
"amg-biggestlittleadventure" = Biggest Little Adventure
"amg-chameleongems" = Chameleon Gems
"amg-fashionassistant" = Fashion Assistant
"amg-frankensteinthedismemberedbride" = FRANKENSTEIN - The Dismembered Bride
"amg-gamehousesolitairechallenge" = GameHouse Solitaire Challenge
"amg-hiddenmagic" = Hidden Magic
"amg-janeangeltemplarmystery" = Jane Angel - Templar Mystery
"amg-jewelcharm" = Jewel Charm
"amg-liongthelostamulets" = Liong - The Lost Amulets
"amg-mahjongginvestigationsundersuspicion" = Mahjongg Investigations - Under Suspicion
"amg-mysterylegendstmsleepyhollow" = Mystery Legends™ - Sleepy Hollow
"amg-nataliebrooksmysteryathillcresthigh" = Natalie Brooks - Mystery at Hillcrest High
"amg-puzzlesolitaire" = Puzzle Solitaire
"amg-strikeball3" = Strike Ball 3
"amg-sunsetstudioloveonthehighseas" = Sunset Studio - Love on the High Seas
"amg-supercollapsepuzzlegallery4" = Super Collapse! Puzzle Gallery 4
"amg-thelostcasesofsherlockholmes" = The Lost Cases of Sherlock Holmes
"amg-thetreasuresofmysteryisland" = The Treasures of Mystery Island
"amg-thetudors" = The Tudors
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"exent_466550" = The Treasures of Montezuma
"exent_554750" = Cradle of Rome
"exent_605350" = Magic Encyclopedia
"exent_668050" = Farm Mania 2
"exent_695650" = Little Shop - Memories
"GamesBar" = GamesBar [removed]
"ie8" = Windows Internet Explorer 8
"Little Shop of Treasures 2" = Little Shop of Treasures 2
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSNINST" = MSN
"mspheres_is1" = Magic Spheres v1.0
"Rainbow Web II" = Rainbow Web II
"UnityWebPlayer" = Unity Web Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"Works2kSetup" = Microsoft Works 2000 Setup Launcher
"WT086164" = Monster Mash
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"SOE-Clone Wars" = Clone Wars
"SOE-Free Realms" = Free Realms
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/29/2011 3:15:44 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 3:55:29 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:36:26 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:37:59 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/29/2011 7:38:30 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 4/30/2011 11:39:54 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:19:54 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:19:57 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 4:20:00 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.
Error - 5/1/2011 2:35:24 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11722
Description = Product: STOPzilla – Message 1722. STOPzilla has canceled the removal
process!
[ System Events ]
Error - 5/1/2011 8:48:36 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 11:35:55 AM | Computer Name = YOUR-845F836F3D | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).
Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
< End of report >