aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-19 18:17:25
—————————–
18:17:25.328 OS Version: Windows 5.1.2600 Service Pack 3
18:17:25.328 Number of processors: 2 586 0x2302
18:17:25.328 ComputerName: OPTERON UserName: USER
18:17:25.984 Initialize success
Thank you for replying.
18:17:50.062 Disk 0 \Device\Harddisk0\DR0 -> \Device\00000074
18:17:50.062 Disk 0 Vendor: WDC_WD1200JB-00GVC0 08.02D08 Size: 114473MB BusType: 3
18:17:50.062 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\00000079
18:17:50.062 Disk 1 Vendor: ST3120813AS 3.AAD Size: 114473MB BusType: 3
18:17:50.062 Device \Driver\nvata -> MajorFunction 8a7cd1f8
18:17:50.078 Disk 1 MBR read successfully
18:17:50.078 Disk 1 MBR scan
18:17:50.078 Disk 1 Windows XP default MBR code
18:17:50.093 Disk 1 scanning sectors +234436545
18:17:50.109 Disk 1 scanning C:\WINDOWS\system32\drivers
18:17:56.156 Service scanning
18:17:57.265 Disk 1 trace - called modules:
18:17:57.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a7cd1f8]<<
18:17:57.265 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8a6a7ab8]
18:17:57.281 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\0000007a[0x8a6aaac0]
18:17:57.281 5 ACPI.sys[b7e74620] -> nt!IofCallDriver -> \Device\00000079[0x8a6a6030]
18:17:57.281 \Driver\nvata[0x8a6ac3b0] -> IRP_MJ_CREATE -> 0x8a7cd1f8
18:17:57.296 Scan finished successfully
18:18:56.265 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\USER\Desktop\INFECTION\MBR.dat"
18:18:56.265 The log file has been saved successfully to "C:\Documents and Settings\USER\Desktop\INFECTION\aswMBR.txt"
OTL logfile created on: 5/19/2011 6:20:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\USER\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 106.78 Gb Total Space | 6.72 Gb Free Space | 6.29% Space Free | Partition Type: NTFS
Drive D: | 5.00 Gb Total Space | 2.96 Gb Free Space | 59.09% Space Free | Partition Type: NTFS
Drive E: | 111.79 Gb Total Space | 33.78 Gb Free Space | 30.21% Space Free | Partition Type: NTFS
Drive H: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: OPTERON | User Name: USER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\USER\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\USER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\USER\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (IWin service) – File not found
SRV - (Active Common Service) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (Imapi Helper) – C:\Program Files\ISO Recorder\ImapiHelper.exe (Alex Feinman)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
========== Driver Services (SafeList) ==========
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\pnkbstrk.sys ()
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (vmm) – C:\WINDOWS\system32\drivers\VMM.sys (Microsoft Corporation)
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\bvrpmpr5.sys (Avanquest Software)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (NVR0Dev) – C:\WINDOWS\nvoclock.sys (NVidia Corp.)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\amdppm.sys (Advanced Micro Devices)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (UsbFltr) – C:\WINDOWS\system32\drivers\copperhd.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\wusbgxp.sys (Cisco-Linksys, LLC.)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.foxtab.com/?s=0&chnl;=irn…CtCyBtCtBtCzytB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://mail.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = https://login.yahoo.com/config/login_verify2?&.src=ym
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "
http://search.aol.com/aolcom/search?invocationType=tb50-ff-aolmailtb-chromesbox-en-us&query;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:3.11.3.15590
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {99079a25-328f-4bd4-be04-00955acaa0a7}:4.1.0.01
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/03/30 16:02:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox 3 Beta 3\components [2011/05/15 18:53:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3 Beta 3\plugins [2011/05/01 10:36:06 | 000,000,000 | —D | M]
[2011/05/19 14:58:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\USER\Application Data\Mozilla\Extensions
[2009/12/25 11:13:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\USER\Application Data\Mozilla\Extensions\[removed]
[2011/05/15 18:50:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions
[2010/03/07 12:36:57 | 000,000,000 | —D | M] ("Garmin Communicator") – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/07/01 20:21:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/06 16:36:40 | 000,000,000 | —D | M] (IE Tab) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2011/05/15 18:47:45 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2008/09/03 13:40:43 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2011/04/09 12:01:19 | 000,000,000 | —D | M] (Sopcast Ask Toolbar) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\[removed]
[2009/12/11 14:44:26 | 000,000,000 | —D | M] (ShopAtHome Intelligent Shopping Toolbar) – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\extensions\[removed]
[2011/05/19 13:06:22 | 000,002,568 | —- | M] () – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\searchplugins\askcom.xml
[2011/02/18 22:49:31 | 000,001,919 | —- | M] () – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\searchplugins\bing-zugo.xml
[2011/02/01 17:21:37 | 000,005,282 | —- | M] () – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\searchplugins\Foxtab Web Search.xml
[2009/11/14 13:32:58 | 000,009,949 | —- | M] () – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\searchplugins\mywebsearch.xml
[2011/03/23 08:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\mbil75g1.default\searchplugins\SearchquWebSearch.xml
[2008/11/11 21:39:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/30 16:02:38 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/07/04 13:29:02 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/06/03 05:24:02 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2008/03/08 09:58:51 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/25 15:07:52 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/15 11:04:59 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/09/27 14:28:37 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2010/07/04 13:29:14 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/07 21:21:50 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/29 07:46:27 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/29 20:13:37 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/31 17:52:52 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/15 18:47:50 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2004/11/12 23:36:20 | 000,005,120 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2008/01/07 20:45:16 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2007/01/28 12:12:30 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
O1 HOSTS File: ([2010/11/06 21:59:03 | 000,000,771 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 q4master.idsoftware.com
O1 - Hosts:
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (WBA F.C. Toolbar) - {6de481f0-7179-4ad6-a857-3dcbcfbb24d4} - C:\Program Files\WBA_F.C\prxtbWBA0.dll (Conduit Ltd.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (WBA F.C. Toolbar) - {6de481f0-7179-4ad6-a857-3dcbcfbb24d4} - C:\Program Files\WBA_F.C\prxtbWBA0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (WBA F.C. Toolbar) - {6DE481F0-7179-4AD6-A857-3DCBCFBB24D4} - C:\Program Files\WBA_F.C\prxtbWBA0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\qttask.exe (Apple Inc.)
O4 - HKCU..\Run: [Google Update] File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKLM..\RunOnce: [SpybotDeletingA3701] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4264] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4325] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4952] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA8745] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1751] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3019] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5367] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC7187] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8664] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotSnD] C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
O4 - HKCU..\RunOnce: [SpybotDeletingB1376] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4154] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB4309] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB5799] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingB8947] C:\WINDOWS\System32\command.com ()
O4 - HKCU..\RunOnce: [SpybotDeletingD1132] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD1627] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD5158] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD6184] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [SpybotDeletingD7359] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = [binary data]
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE}
https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
http://onlinedesigner.hgtv.com/images/app/view22rte.cab (View22RTE Class)
O16 - DPF: {C53BDC3D-19A0-4062-BF34-0897A4E6A6A2}
http://www.wildpockets.com/common/WildPock…oader-15079.cab (Wild Pockets Loader Plugin Control Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/14 18:31:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/02/09 21:55:59 | 000,423,304 | R— | M] (Electronic Arts) - H:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2010/02/10 02:21:09 | 000,000,000 | R–D | M] - H:\Autorun – [ CDFS ]
O32 - AutoRun File - [2010/01/31 04:21:13 | 000,367,686 | R— | M] () - H:\Autorun.ico – [ CDFS ]
O32 - AutoRun File - [2010/02/09 22:55:03 | 009,965,568 | R— | M] () - H:\autorun.dat – [ CDFS ]
O32 - AutoRun File - [2010/02/09 22:54:55 | 000,000,155 | R— | M] () - H:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{643e98da-1554-11e0-9563-0015f2170c12}\Shell\AutoRun\command - "" = O:\PMBP_Win.exe
O33 - MountPoints2\{d060c7bd-e9d7-11de-a84e-0015f2170c12}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: javarcp - (C:\WINDOWS\system32\clippbar.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/18 21:42:13 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Desktop\INFECTION
[2011/05/18 19:56:28 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Start Menu\Programs\HiJackThis
[2011/05/18 19:56:27 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/05/15 18:49:03 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Local Settings\Application Data\Ilivid Player
[2011/05/15 18:48:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{E962A392-2F87-4F8D-A7CB-75B38B581726}
[2011/05/15 18:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Application Data\searchquband
[2011/05/15 18:48:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iLivid
[2011/05/15 18:47:59 | 000,000,000 | —D | C] – C:\Program Files\iLivid
[2011/05/15 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Application Data\searchqutoolbar
[2011/05/15 18:47:38 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/05/15 18:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Local Settings\Application Data\PackageAware
[2011/05/14 14:55:29 | 000,000,000 | RH-D | C] – C:\Documents and Settings\USER\Recent
[2011/05/04 18:21:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Pokemon Online
[2011/05/04 18:20:57 | 000,000,000 | —D | C] – C:\Documents and Settings\USER\Pokemon Online
[2008/10/19 17:23:50 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\USER\Application Data\pcouffin.sys
[2004/11/24 14:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/19 18:11:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/19 18:08:02 | 000,000,426 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/05/19 18:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/05/19 17:32:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1336601894-839522115-1004UA.job
[2011/05/19 17:11:53 | 000,140,024 | —- | M] () – C:\WINDOWS\System32\drivers\pnkbstrk.sys
[2011/05/19 17:11:48 | 000,280,768 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2011/05/19 14:58:37 | 000,000,735 | —- | M] () – C:\WINDOWS\wininit.ini
[2011/05/19 12:27:27 | 000,282,624 | —- | M] () – C:\Documents and Settings\USER\Desktop\2011 bill calendar
[2011/05/19 09:17:57 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{DA49B636-0ED2-4F7B-8CFD-DF1BEB81F03C}.job
[2011/05/19 08:29:04 | 115,387,917 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/19 08:28:08 | 000,001,822 | -H– | M] () – C:\Documents and Settings\USER\My Documents\Default.rdp
[2011/05/18 19:56:28 | 000,001,982 | —- | M] () – C:\Documents and Settings\USER\Desktop\HiJackThis.lnk
[2011/05/18 08:20:20 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/18 08:17:29 | 000,272,073 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/05/18 08:17:02 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1202660629-1336601894-839522115-1004.job
[2011/05/18 08:16:59 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/18 08:15:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/18 08:15:24 | 2147,012,608 | -HS- | M] () – C:\hiberfil.sys
[2011/05/17 22:08:10 | 000,280,768 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.ex0
[2011/05/17 08:02:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/16 07:32:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1336601894-839522115-1004Core.job
[2011/05/15 20:41:08 | 000,000,000 | —- | M] () – C:\Documents and Settings\USER\Local Settings\Application Data\prvlcl.dat
[2011/05/12 23:14:53 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/09 22:41:46 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1202660629-1336601894-839522115-1004.job
[2011/05/09 10:31:19 | 000,115,417 | —- | M] () – C:\Documents and Settings\USER\Desktop\2011fishlic.pdf
[2011/05/09 10:30:58 | 000,000,034 | —- | M] () – C:\WINDOWS\System32\BD5250DN.DAT
[2011/05/04 19:26:49 | 000,000,808 | —- | M] () – C:\Documents and Settings\USER\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2011/05/01 10:36:06 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/23 20:12:23 | 000,002,515 | —- | M] () – C:\Documents and Settings\USER\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/19 14:58:34 | 000,000,735 | —- | C] () – C:\WINDOWS\wininit.ini
[2011/05/18 19:56:28 | 000,001,982 | —- | C] () – C:\Documents and Settings\USER\Desktop\HiJackThis.lnk
[2011/05/09 10:31:19 | 000,115,417 | —- | C] () – C:\Documents and Settings\USER\Desktop\2011fishlic.pdf
[2011/05/04 19:26:49 | 000,000,808 | —- | C] () – C:\Documents and Settings\USER\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2011/01/30 20:39:27 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/12/06 08:57:11 | 000,000,000 | —- | C] () – C:\Documents and Settings\USER\Local Settings\Application Data\prvlcl.dat
[2010/12/03 08:16:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/12 22:40:31 | 000,000,360 | —- | C] () – C:\WINDOWS\System32\nvUnsupRes.dat
[2010/10/14 20:25:47 | 000,487,944 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/10/14 02:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/07/05 17:06:10 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2010/07/05 17:06:10 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNRAR3.dll
[2010/07/05 17:06:10 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2010/07/05 17:06:10 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2010/06/27 11:05:22 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2010/06/18 20:54:55 | 000,138,056 | —- | C] () – C:\Documents and Settings\USER\Application Data\PnkBstrK.sys
[2010/06/18 20:54:22 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/06/03 05:24:53 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/03 12:55:36 | 000,000,000 | —- | C] () – C:\WINDOWS\Cpubu.bin
[2010/05/03 12:55:35 | 000,000,120 | —- | C] () – C:\WINDOWS\Dkafinagogutage.dat
[2010/05/03 12:53:42 | 000,000,020 | —- | C] () – C:\Documents and Settings\USER\Application Data\qvjsge.dat
[2010/04/03 22:55:32 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/02/15 22:51:27 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/08/10 18:24:36 | 000,061,796 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/05/29 16:52:26 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/28 17:31:06 | 000,000,348 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2009/05/28 17:28:47 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\SH33W32.DLL
[2009/04/06 20:08:49 | 000,004,445 | —- | C] () – C:\WINDOWS\PsycleKeys.INI
[2009/03/29 14:25:38 | 000,000,723 | —- | C] () – C:\WINDOWS\Tuareg2.ini
[2008/12/19 12:32:30 | 000,000,222 | —- | C] () – C:\WINDOWS\System32\SunData.ini
[2008/12/19 12:31:54 | 000,000,086 | —- | C] () – C:\WINDOWS\TTL3Util.ini
[2008/12/19 12:31:44 | 000,000,120 | —- | C] () – C:\WINDOWS\TTL3.ini
[2008/12/19 10:15:58 | 004,338,246 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 12:41:18 | 000,884,237 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 12:22:58 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 12:22:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 12:17:34 | 000,239,247 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 11:59:54 | 000,560,802 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2008/10/24 20:13:42 | 000,000,668 | —- | C] () – C:\Documents and Settings\USER\Application Data\vso_ts_preview.xml
[2008/10/19 17:23:50 | 000,087,608 | —- | C] () – C:\Documents and Settings\USER\Application Data\inst.exe
[2008/10/19 17:23:50 | 000,007,887 | —- | C] () – C:\Documents and Settings\USER\Application Data\pcouffin.cat
[2008/10/19 17:23:50 | 000,001,144 | —- | C] () – C:\Documents and Settings\USER\Application Data\pcouffin.inf
[2008/10/19 16:34:56 | 000,000,119 | —- | C] () – C:\WINDOWS\NNS.INI
[2008/10/06 08:44:51 | 005,068,152 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall.exe
[2008/09/28 19:54:04 | 000,000,127 | —- | C] () – C:\Documents and Settings\USER\Local Settings\Application Data\fusioncache.dat
[2008/07/24 09:51:46 | 000,140,024 | —- | C] () – C:\WINDOWS\System32\drivers\pnkbstrk.sys
[2008/07/24 09:51:42 | 000,280,768 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/07/24 09:50:12 | 000,075,136 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2007/10/20 10:43:18 | 000,000,061 | —- | C] () – C:\WINDOWS\PureEdgeAPI.ini
[2007/10/20 10:43:16 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\MSQOLE.DLL
[2007/09/04 12:56:10 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2007/07/15 13:04:20 | 000,000,150 | —- | C] () – C:\WINDOWS\ChssBase.ini
[2007/03/12 12:01:30 | 000,217,088 | —- | C] () – C:\WINDOWS\NVGfxOgl.dll
[2007/02/05 20:05:26 | 000,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2007/02/01 16:22:14 | 000,000,388 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/02 11:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2006/10/28 17:55:58 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2006/10/28 17:43:10 | 000,000,138 | —- | C] () – C:\WINDOWS\System32\dxwizard.bin
[2006/06/13 16:35:32 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2006/05/22 21:36:49 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2006/05/22 21:36:49 | 000,000,129 | —- | C] () – C:\WINDOWS\primopdf.ini
[2006/03/18 15:46:09 | 000,005,674 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/03/18 15:46:04 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/03/17 12:34:25 | 000,269,474 | —- | C] () – C:\WINDOWS\Windows XP Energy Blue Theme Pack Uninstaller.exe
[2006/03/17 11:39:25 | 000,290,904 | R— | C] () – C:\WINDOWS\System32\vc6-re200l.dll
[2006/03/16 20:12:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/15 18:10:32 | 000,075,264 | —- | C] () – C:\Documents and Settings\USER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/14 21:48:44 | 000,000,147 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2006/03/14 21:48:44 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/03/14 21:48:44 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2006/03/14 21:48:35 | 000,014,441 | —- | C] () – C:\WINDOWS\HL-5250DN.INI
[2006/03/14 21:48:22 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2006/03/14 21:48:22 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD5250DN.DAT
[2006/03/14 19:46:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/03/14 19:46:00 | 000,107,134 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2006/03/14 19:45:51 | 000,006,698 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/03/14 19:21:10 | 000,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/03/14 19:15:31 | 000,156,672 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2006/03/14 18:33:26 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/14 18:28:44 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/14 13:21:09 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/14 13:19:37 | 000,294,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/03/09 15:29:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/03/09 15:29:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/01/12 17:09:14 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\DXFLib.dll
[2006/01/12 17:08:06 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\opcode.dll
[2005/10/09 22:33:54 | 000,137,216 | —- | C] () – C:\WINDOWS\System32\secdel.dll
[2004/10/03 12:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 02:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 08:00:00 | 000,436,878 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 08:00:00 | 000,070,306 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 08:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2006/03/17 22:12:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010/10/14 22:38:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/14 19:52:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/10/24 22:06:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVSVideoBurner
[2008/10/11 22:00:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/08/23 11:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/02/15 22:51:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2009/06/16 12:44:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/10/14 22:38:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/13 20:32:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2007/04/03 22:36:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2010/10/27 18:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/06/18 16:03:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fallout3
[2009/04/08 20:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/04/09 18:31:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/10/03 21:52:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2007/10/20 10:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2007/02/12 21:12:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\scar5
[2010/07/05 17:06:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2011/05/19 14:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2010/07/05 17:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/25 11:14:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/09/28 19:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VistaCodecs
[2008/10/22 18:37:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/04/15 21:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZoneFiveSoftware
[2009/03/21 10:45:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/07/04 14:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/05 09:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/10 12:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/05/15 18:48:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{E962A392-2F87-4F8D-A7CB-75B38B581726}
[2006/05/13 11:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\.BitTornado
[2011/04/20 18:36:13 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\.minecraft
[2011/03/03 09:52:22 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Amazon
[2010/10/14 22:39:47 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\AVG10
[2008/10/12 20:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Azureus
[2011/05/01 22:53:37 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\BitTorrent
[2010/02/15 22:51:44 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Canneverbe Limited
[2009/11/07 14:27:24 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Canon
[2007/07/15 21:18:11 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\ChessBase
[2009/12/13 20:38:03 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\DAEMON Tools Lite
[2007/04/03 22:36:41 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\DassaultSystemes
[2008/04/06 13:57:37 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\DisplayTune
[2010/05/13 18:34:29 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\DNA
[2006/05/15 18:18:34 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\DWGeditor
[2010/07/28 17:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\E-centives
[2006/03/17 11:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Echo Software
[2009/04/27 12:25:04 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\eMusic
[2009/04/08 20:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\GARMIN
[2009/03/06 21:14:51 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\gtk-2.0
[2010/03/19 22:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\KendallHunt
[2007/02/17 19:36:40 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Leadertech
[2009/04/08 20:52:29 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\MotionBased
[2011/04/16 23:50:06 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\My Games
[2010/11/17 14:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Petroglyph
[2010/05/13 18:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Phex
[2007/10/23 16:40:06 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\PureEdge
[2011/02/27 17:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\RegistryKeys
[2007/02/12 21:12:24 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\scar5
[2011/05/15 18:48:12 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\searchquband
[2011/05/15 18:48:26 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\searchqutoolbar
[2008/01/13 12:53:06 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Seven Zip
[2008/02/16 12:55:58 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\ShredderChess
[2010/08/24 18:42:28 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\sldIM
[2006/03/14 21:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Thunderbird
[2009/12/25 11:13:45 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\TomTom
[2008/10/19 17:32:21 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Uniblue
[2009/09/28 19:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\VistaCodecs
[2010/12/28 12:22:40 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\vShare
[2011/04/17 12:33:09 | 000,000,000 | —D | M] – C:\Documents and Settings\USER\Application Data\Vso
[2011/05/17 08:02:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/05/19 18:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/05/19 09:17:57 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{DA49B636-0ED2-4F7B-8CFD-DF1BEB81F03C}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/07/05 17:18:10 | 000,020,084 | —- | M] () – C:\aaw7boot.log
[2006/03/14 18:31:33 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/16 00:04:46 | 000,000,397 | RHS- | M] () – C:\BOOT.BAK
[2010/05/18 13:10:17 | 000,000,223 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2006/03/14 18:31:33 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/03/28 20:47:05 | 000,000,045 | —- | M] () – C:\error.log
[2009/05/18 10:54:19 | 000,025,088 | —- | M] () – C:\Gryfinn Lunch.xls
[2011/05/18 08:15:24 | 2147,012,608 | -HS- | M] () – C:\hiberfil.sys
[2006/03/14 18:31:33 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/03/14 18:31:33 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 23:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/06 12:55:33 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/18 08:15:22 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/11/19 14:43:45 | 000,016,384 | -HS- | M] () – C:\Thumbs.db
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/03/14 18:31:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/01/06 22:17:15 | 000,001,746 | -H– | M] () – C:\Documents and Settings\USER\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/03/14 13:15:26 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/03/14 13:15:26 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/03/14 13:15:25 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/06 12:58:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/01/06 21:04:36 | 000,006,656 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/03/14 18:38:54 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\USER\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/03/14 18:38:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\USER\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/07/27 19:57:50 | 000,071,398 | —- | M] (jpshortstuff) – C:\Documents and Settings\USER\Desktop\GooredFix.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2006/03/19 20:35:58 | 000,435,968 | —- | M] (Symantec Corporation) – C:\Documents and Settings\USER\sevinst.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/03/14 18:38:53 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\USER\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/05/19 18:18:00 | 000,032,768 | -HS- | M] () – C:\Documents and Settings\USER\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 17:48:28
========== Files - Unicode (All) ==========
[2010/12/03 22:53:36 | 000,000,158 | —- | M] ()(C:\Documents and Settings\USER\Desktop\????????(Hydatophylax nigrovittatus McLachlan) ??? ???.url) – C:\Documents and Settings\USER\Desktop\띠무늬우묵날도래(Hydatophylax nigrovittatus McLachlan) 네이버 블로그.url
[2010/12/03 22:53:36 | 000,000,158 | —- | C] ()(C:\Documents and Settings\USER\Desktop\????????(Hydatophylax nigrovittatus McLachlan) ??? ???.url) – C:\Documents and Settings\USER\Desktop\띠무늬우묵날도래(Hydatophylax nigrovittatus McLachlan) 네이버 블로그.url
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
OTL Extras logfile created on: 5/19/2011 6:20:39 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\USER\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 106.78 Gb Total Space | 6.72 Gb Free Space | 6.29% Space Free | Partition Type: NTFS
Drive D: | 5.00 Gb Total Space | 2.96 Gb Free Space | 59.09% Space Free | Partition Type: NTFS
Drive E: | 111.79 Gb Total Space | 33.78 Gb Free Space | 30.21% Space Free | Partition Type: NTFS
Drive H: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: OPTERON | User Name: USER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Documents and Settings\USER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Documents and Settings\USER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"29126:TCP" = 29126:TCP:*:Enabled:Azureus
"57479:TCP" = 57479:TCP:*:Enabled:bittorrent
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Combat Arms\CombatArms.exe" = C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Program Files\Combat Arms\Engine.exe" = C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\Combat Arms\CombatArms.exe" = C:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Program Files\Combat Arms\Engine.exe" = C:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Program Files\Combat Arms\NMService.exe" = C:\Program Files\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core
"C:\Program Files\Microsoft Games\Halo\halo.exe" = C:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\LucasArts\Star Wars Battlefront II\GameData\BattlefrontII.exe" = C:\Program Files\LucasArts\Star Wars Battlefront II\GameData\BattlefrontII.exe:*:Enabled:BattlefrontII
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Microsoft Games\Halo Custom Edition\haloce.exe" = C:\Program Files\Microsoft Games\Halo Custom Edition\haloce.exe:*:Enabled:Halo
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Electronic Arts\Battlefield 2142 Deluxe Edition\BF2142.exe" = C:\Program Files\Electronic Arts\Battlefield 2142 Deluxe Edition\BF2142.exe:*:Enabled:Battlefield 2142
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Disabled:EA Download Manager
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe" = C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2 – (EA Digital Illusions CE AB)
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Game.exe" = C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Game.exe:*:Enabled:Battlefield: Bad Company™ 2 – (EA Digital Illusions CE AB)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Bethesda Softworks\Fallout 3\Fallout3.exe" = C:\Program Files\Bethesda Softworks\Fallout 3\Fallout3.exe:*:Enabled:Fallout3 – (Bethesda Softworks)
"C:\Program Files\id Software\Quake 4\Quake4.exe" = C:\Program Files\id Software\Quake 4\Quake4.exe:*:Disabled:Quake 4 – ()
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe" = C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe" = C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4807" = CanoScan LiDE 200 Scanner Driver
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4™
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26621E14-A45B-45CD-9ED9-7A0A9B585DB4}" = SolidWorks Installation Manager
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{2C08D7E7-9EE1-4A08-AFE0-745F02DCD6A4}_is1" = Pokemon Online 1.0.21
"{2C0A655C-61E7-428A-8ED2-23A3D20E7DD2}" = Data Lifeguard Tools
"{2D6ED011-055B-4041-B198-BB903827EBFB}" = Safari
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31B620F7-A6E7-4F91-AF10-6EC9DB2EA564}" = ArcSoft Panorama Maker 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4642B082-DBC9-44CA-87F3-7A0B997B9590}" = Brother HL-5250DN
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{491EAC1A-8ECB-45D5-97D1-0583D5676914}" = ProMash
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53C239F5-7E23-493D-8FB6-F8EEEA5C2154}" = Garmin Training Center
"{559FAB96-A0CD-4105-A02F-1C21DEBCEF89}" = SolidWorks Explorer 2007 sp0
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = AsusUpdate
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B5E816C-A761-4F5B-BF48-84B794556CAA}_is1" = Freelang Dictionary (wordlist)
"{6C611DD2-2685-4A76-92B5-ECD237128582}" = Type to Learn 3
"{70C4EFA5-F8B8-4015-9378-FCAA9000DF19}" = MotionBased Agent
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75FEB085-179F-4C85-B0E4-B517D2160750}" = eDrawings 2007
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.2.1.55b
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}" = Motorola Driver Installation 3.4.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{8AC9520B-25F3-4B3C-B83A-2E4B51AF8DEC}" = Fritz8
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PUBLISHERR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PUBLISHERR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PUBLISHERR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PUBLISHERR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PUBLISHERR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PUBLISHERR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0019-0000-0000-0000000FF1CE}" = Microsoft Office Publisher 2007
"{91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0019-0000-0000-0000000FF1CE}_PUBLISHERR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95FCA50A-CF7D-457E-AF69-F058F8BC2844}" = SolidWorks 2007 SP0
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9BE2AFE1-617E-478F-9BE5-DABB63B4380A}" = COSMOSMotion 2007 SP0
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA0FB0B5-D853-4F87-9261-A4BC7D503E0D}" = Microsoft Image Composite Editor
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AF2D85EE-D6F9-4E7B-B9FA-BBB9BCA9A01E}" = COSMOSWorks 2007 SP0
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B1EE1CC5-6CED-4801-BFFF-8454F21A245A}" = Garmin Communicator Plugin
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B3AEF776-7FFF-4C50-A402-9119E3849EE0}" = AVG 2011
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BABA6734-23CF-42AC-9E4C-EA2C7C80AA4E}" = AVG 2011
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BEF3EFE7-5159-436D-9BF0-CCC633179EB4}" = EVGA Display Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{CA83357B-931E-44DC-AD43-9996FEEB8116}" = Acronis True Image
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
"{DFC6573E-124D-4026-BFA4-B433C9D3FF21}" = ISO Recorder
"{E0000600-0600-0600-0600-000000000600}" = ICS Viewer 6.0
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}" = mobile PhoneTools
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F5125699-C01A-4ED8-BD3A-265DF29859FE}" = DWGeditor
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.5
"{FAF88B432344413595BB2DED98385684}" = DivX User Guide
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"7-Zip" = 7-Zip 9.15 beta
"Across Lite 2.0" = Across Lite 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"Audacity_is1" = Audacity 1.2.6
"AVG" = AVG 2011
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.2
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Canon CanoScan LiDE 200 User Registration" = Canon CanoScan LiDE 200 User Registration
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"conduitEngine" = Conduit Engine
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Creative NOMAD II Driver" = Creative NOMAD II Driver
"EADM" = EA Download Manager
"Fallout Mod Manager_is1" = Fallout Mod Manager 0.11.9
"GamePlayLabs" = GamePlayLabs Plugin
"HammerHead Rhythm Station" = HammerHead Rhythm Station
"HijackThis" = HijackThis 2.0.2
"Hugin_release_is1" = Hugin 2009.4.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iLivid" = iLivid
"InfraRecorder" = InfraRecorder
"InstallShield_{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4™
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"LVG332" = 3rd Grade
"Magic ISO Maker v5.3 (build 0221)" = Magic ISO Maker v5.3 (build 0221)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MP Navigator EX 2.0" = Canon MP Navigator EX 2.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"oggcodecs" = oggcodecs 0.71.0946
"PageRage Toolbar" = PageRage Toolbar
"PrimoPDF2.0" = PrimoPDF
"PUBLISHERR" = Microsoft Office Publisher 2007 Trial
"PunkBusterSvc" = PunkBuster Services
"QuicktimeAlt_is1" = QuickTime Alternative 1.69
"R for Windows_is1" = R for Windows 2.5.1
"RealPlayer 12.0" = RealPlayer
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"SopCast" = SopCast 3.2.9
"SpywareBlaster_is1" = SpywareBlaster 4.2
"ST6UNST #1" = Machinehead GearCalc Pro (32 bit)
"Steam App 400" = Portal
"Steam App 45000" = Sol Survivor
"TomTom HOME" = TomTom HOME 2.7.6.2056
"Veetle TV" = Veetle TV 0.9.18
"Verizon Online DSL_is1" = Verizon Online DSL
"vShare" = vShare Plugin
"WBA_F.C Toolbar" = WBA F.C. Toolbar
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WinAVR" = WinAVR 20060125 (remove only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Energy Blue Theme Pack" = Windows XP Energy Blue Theme Pack
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.5
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XP Codec Pack" = XP Codec Pack
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Acrobat Connect Add-in" = Adobe Acrobat Connect Add-in
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/19/2011 12:27:33 PM | Computer Name = OPTERON | Source = Application Error | ID = 1000
Description = Faulting application officelivesignin.exe, version 2.0.2313.0, faulting
module officelivesignin.exe, version 2.0.2313.0, fault address 0x00003ce4.
Error - 5/19/2011 12:27:35 PM | Computer Name = OPTERON | Source = Application Error | ID = 1001
Description = Fault bucket 1211938979.
Error - 5/19/2011 12:51:10 PM | Computer Name = OPTERON | Source = Application Error | ID = 1000
Description = Faulting application officelivesignin.exe, version 2.0.2313.0, faulting
module officelivesignin.exe, version 2.0.2313.0, fault address 0x00003ce4.
Error - 5/19/2011 12:51:12 PM | Computer Name = OPTERON | Source = Application Error | ID = 1001
Description = Fault bucket 1211938979.
Error - 5/19/2011 4:33:18 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 5/19/2011 4:33:18 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2078
Error - 5/19/2011 4:33:18 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2078
Error - 5/19/2011 5:10:39 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 5/19/2011 5:10:39 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2243031
Error - 5/19/2011 5:10:39 PM | Computer Name = OPTERON | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2243031
[ System Events ]
Error - 5/18/2011 12:54:58 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/18/2011 1:54:59 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/18/2011 7:35:07 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/18/2011 8:45:54 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 8:30:02 AM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 12:18:05 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 1:54:03 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 3:29:59 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 4:30:00 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
Error - 5/19/2011 6:18:02 PM | Computer Name = OPTERON | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
BOB that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F4688967-C48E-4E37-9106.
The
master browser is stopping or an election is being forced.
< End of report >