timjohn
Topic Starter
In the past week the internet on my home network intermittently slows down to near 0 speeds, while the browser interface for my router shows that the connection is still at full strength. I've isolated the problem to what i believe to be an infection on one of the computers. Whenever I turn it off or disconnect it from the network the problem is solved for all the other machines. It's offline now and I'm posting from another computer.
Here's my OTL log:
OTL logfile created on: 6/22/2011 1:06:53 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Heinrich Kids\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.30 Gb Available Physical Memory | 45.28% Memory free
5.95 Gb Paging File | 4.20 Gb Available in Paging File | 70.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 107.24 Gb Free Space | 37.50% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.34 Gb Free Space | 11.03% Space Free | Partition Type: NTFS
Drive J: | 967.22 Mb Total Space | 966.63 Mb Free Space | 99.94% Space Free | Partition Type: FAT
Computer Name: HEINRICHKIDS-PC | User Name: Heinrich Kids | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Heinrich Kids\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\Registry Mechanic\RMTray.exe (PC Tools )
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
========== Modules (SafeList) ==========
MOD - C:\Users\Heinrich Kids\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (EhttpSrv) – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TeamViewer4) – C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (eamonm) – C:\Windows\SysNative\DRIVERS\eamonm.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\DRIVERS\ehdrv.sys (ESET)
DRV:64bit: - (epfwwfpr) – C:\Windows\SysNative\DRIVERS\epfwwfpr.sys (ESET)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (CAXHWBS2) – C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (teamviewervpn) – C:\Windows\SysNative\DRIVERS\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\DRIVERS\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (PCD5SRVC{E2AF211B-86DA020A-05040000}) – C:\Program Files (x86)\PC-Doctor for Windows\pcd5srvc_x64.pkms (PC-Doctor, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - File not found
IE - HKCU\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?ilc=1"
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/21 22:48:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/11/23 22:06:18 | 000,000,000 | —D | M]
[2011/05/21 22:49:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Extensions
[2011/06/20 16:00:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Firefox\Profiles\gz2rfve9.default\extensions
[2011/06/20 16:00:59 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Firefox\Profiles\gz2rfve9.default\extensions\[removed]
[2011/05/21 22:48:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
[2010/04/07 14:43:57 | 000,000,000 | —D | M] (Move Media Player) – C:\USERS\HEINRICH KIDS\APPDATA\ROAMING\MOVE NETWORKS
[2011/04/14 11:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - Reg Error: Value error. File not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - Reg Error: Value error. File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (NCH EN Toolbar) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKCU..\Run: [Apoxiqaquzu] File not found
O4 - HKCU..\Run: [iLike] File not found
O4 - HKCU..\Run: [Jxofifurizevu] File not found
O4 - HKCU..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKCU..\Run: [NvCplDaemonTool] File not found
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files (x86)\Registry Mechanic\RMTray.exe (PC Tools )
O4 - HKCU..\Run: [RTHDBPL] File not found
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.2.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{39345b6a-d5ee-11dd-9fff-00226837a8a5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{791266c1-198f-11de-a70e-00226837a8a5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{e2ae1b85-13d7-11de-ae76-00226837a8a5}\Shell\Auto\command - "" = system16.exe
O33 - MountPoints2\{e2ae1b85-13d7-11de-ae76-00226837a8a5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system16.exe
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\WDSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/22 13:04:42 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/20 16:00:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Search Toolbar
[2011/06/17 03:08:14 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/17 03:08:14 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/17 03:08:13 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/17 03:08:12 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/06/17 03:08:12 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/06/17 03:08:12 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/06/17 03:08:12 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/06/17 03:08:12 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 14:31:08 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/14 16:16:31 | 000,000,000 | —D | C] – C:\Users\Heinrich Kids\AppData\Local\RagdollSoft
[2011/06/06 13:04:42 | 000,000,000 | —D | C] – C:\Users\Heinrich Kids\AppData\Local\Unity
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/22 13:11:28 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/22 13:05:07 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/22 13:00:58 | 000,712,548 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/22 13:00:58 | 000,604,264 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/22 13:00:58 | 000,112,756 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/22 12:02:38 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/22 12:02:38 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/22 12:02:29 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/22 12:02:28 | 000,000,240 | —- | M] () – C:\Windows\tasks\PAV.job
[2011/06/22 12:02:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/22 12:02:21 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2011/06/20 15:58:59 | 039,823,604 | —- | M] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
[2011/06/17 03:42:14 | 000,340,968 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/27 18:02:08 | 000,002,619 | —- | M] () – C:\Users\Heinrich Kids\Desktop\Microsoft Word.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/20 15:51:05 | 039,823,604 | —- | C] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
[2010/10/30 09:52:40 | 000,000,000 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\Icugubi.bin
[2010/10/30 09:52:39 | 000,000,120 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\Kheloziqipuzi.dat
[2010/08/04 21:06:50 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/02/26 17:25:18 | 000,001,028 | —- | C] () – C:\Users\Heinrich Kids\AppData\Roaming\WavCodec.wff
[2009/11/25 17:42:37 | 000,000,224 | —- | C] () – C:\Windows\SIERRA.INI
[2009/11/25 17:41:59 | 000,021,840 | —- | C] () – C:\Windows\SysWow64\SIntfNT.dll
[2009/11/25 17:41:59 | 000,017,212 | —- | C] () – C:\Windows\SysWow64\SIntf32.dll
[2009/11/25 17:41:59 | 000,012,067 | —- | C] () – C:\Windows\SysWow64\SIntf16.dll
[2009/09/17 03:29:56 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/17 03:28:57 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/09/17 03:28:13 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 08:36:43 | 000,160,298 | —- | C] () – C:\Windows\hpqins00.dat
[2009/06/07 19:53:51 | 000,000,680 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\d3d9caps.dat
[2009/04/03 17:21:54 | 000,765,952 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009/04/03 17:21:54 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/02/12 22:01:35 | 000,021,074 | —- | C] () – C:\Users\Heinrich Kids\AppData\Roaming\UserTile.png
[2009/01/02 18:31:24 | 000,172,544 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/01 19:20:02 | 000,133,447 | —- | C] () – C:\Windows\hppins20.dat
[2009/01/01 19:19:53 | 000,016,655 | —- | C] () – C:\Windows\hppmdl20.dat
[2008/12/30 20:15:03 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/12/30 06:18:34 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/08/06 09:04:20 | 000,107,384 | —- | C] () – C:\Windows\hpqins13.dat
[2008/08/06 08:40:30 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/08/06 08:40:30 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2009/02/15 12:36:28 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\aAvgApi
[2010/06/05 19:32:50 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\acccore
[2010/01/03 00:08:19 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\AuctioneerDb
[2011/01/12 18:18:08 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Azureus
[2009/09/30 22:56:25 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Deusty
[2010/12/24 15:28:31 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Downloaded Installations
[2010/11/23 22:00:50 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\ESET
[2009/01/25 20:46:08 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Gamelab
[2009/09/21 22:34:37 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\iLike
[2009/08/18 13:46:03 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Image Zone Express
[2011/05/08 13:46:25 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\iWin
[2010/10/29 22:10:52 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\LolClient
[2009/04/06 18:27:21 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\NCH Swift Sound
[2009/02/12 22:01:34 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\PeerNetworking
[2010/08/13 16:18:55 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\PlayFirst
[2009/02/04 22:39:42 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Printer Info Cache
[2009/12/11 23:19:20 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1
[2010/07/13 10:19:12 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\SPORE Creature Creator
[2010/10/08 05:18:32 | 000,000,000 | -HSD | M] – C:\Users\Heinrich Kids\AppData\Roaming\SystemProc
[2009/10/08 17:30:34 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\TeamViewer
[2009/01/22 18:05:40 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\WildTangent
[2009/05/20 06:48:44 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\WinBatch
[2011/06/22 12:02:28 | 000,000,240 | —- | M] () – C:\Windows\Tasks\PAV.job
[2011/06/21 22:14:22 | 000,032,522 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/08/06 09:21:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/04/29 15:28:33 | 000,000,250 | —- | M] () – C:\FINIS_IT.TXT
[2011/06/22 12:02:21 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2010/06/05 19:32:33 | 000,000,359 | -H– | M] () – C:\IPH.PH
[2011/06/22 12:02:20 | 3397,791,744 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/17 17:36:03 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/12/19 14:59:10 | 000,001,658 | -H– | M] () – C:\Users\Heinrich Kids\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/19 08:52:35 | 000,000,574 | -HS- | M] () – C:\Users\Heinrich Kids\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/22 13:05:07 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/20 15:58:59 | 039,823,604 | —- | M] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
And the Extras log:
OTL Extras logfile created on: 6/22/2011 1:06:53 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Heinrich Kids\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.30 Gb Available Physical Memory | 45.28% Memory free
5.95 Gb Paging File | 4.20 Gb Available in Paging File | 70.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 107.24 Gb Free Space | 37.50% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.34 Gb Free Space | 11.03% Space Free | Partition Type: NTFS
Drive J: | 967.22 Mb Total Space | 966.63 Mb Free Space | 99.94% Space Free | Partition Type: FAT
Computer Name: HEINRICHKIDS-PC | User Name: Heinrich Kids | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = D1 C5 00 B7 39 38 CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12ADE82E-0DBA-4618-A39C-43B8E7987BA8}" = lport=5938 | protocol=6 | dir=in | name=teamviewer |
"{1D9F0610-68C4-4477-A1CF-5D01964C5B52}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{22BB8242-9FB0-49EF-85B7-B7C79FB3ADEE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{26839DA1-EF2B-4D20-9E58-9857BC34EA32}" = lport=138 | protocol=17 | dir=in | app=system |
"{34A6595B-6ABD-47B7-B2D0-401A00DECB86}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{45FF398A-EC73-47C9-BD19-E0F68551A22D}" = lport=137 | protocol=17 | dir=in | app=system |
"{499A87D0-7986-4EF8-8345-1751FC42E74E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4B538520-F447-4A12-A4EA-5C0930B9BA52}" = rport=137 | protocol=17 | dir=out | app=system |
"{5E9FF7A3-C864-417B-ABF1-C5874D7DCFE6}" = rport=445 | protocol=6 | dir=out | app=system |
"{646EE8D8-8894-40D1-B85E-C9C712B49311}" = lport=139 | protocol=6 | dir=in | app=system |
"{64FC2786-0F76-4732-8292-F5112902D1D6}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6DC285E7-B88F-4D6C-8F17-5D0A9F59865D}" = lport=8380 | protocol=17 | dir=in | name=league of legends launcher |
"{6E5A090B-A576-4F80-AC40-BB3E38DACD2E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{8344EFC1-8EDD-4102-93AF-4F349304F65D}" = lport=8380 | protocol=6 | dir=in | name=league of legends launcher |
"{8432AE6E-84B2-418E-AA0F-CDC4770C2F80}" = rport=138 | protocol=17 | dir=out | app=system |
"{86CFB88F-5D5C-4C7F-9938-0559E11670FB}" = lport=80 | protocol=6 | dir=in | name=teamviewer2 |
"{8BB76035-0116-46A5-9298-E2C2B6C87B47}" = rport=139 | protocol=6 | dir=out | app=system |
"{9D6562A0-0F3F-452E-A336-95512E7135CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A95EE3F0-EF82-4E33-863E-BE81D5363E51}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C9DFCCE9-57A2-4508-9926-C64F9FD171B6}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{CF995F9F-6E96-49D0-8DBF-8394803529BF}" = lport=445 | protocol=6 | dir=in | app=system |
"{D2DB1B1D-F0BB-427D-8F0A-09BB5680EB85}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02BAF3BF-63AB-4DA0-8B1D-75617C4B514A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{164F3B72-FA40-491E-8AD9-E0511EC97155}" = protocol=17 | dir=in | app=c:\windows\system32\msra.exe |
"{1F34F8FB-E8E7-49AC-BBB2-040195AAB7B5}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{2385F6AA-6995-4C17-8AAD-60805AA5771F}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{2B0426DA-1E34-46EF-BF2F-E2179861F048}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version4\teamviewer.exe |
"{2BFE2C67-E2CE-4735-9A0A-441E457C1FF7}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{2DFF1108-5925-44C4-8307-BFA4486E9835}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{32CEAD5B-7D57-4AB3-A7A4-7A6FB2285618}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{3A8A3E3E-2351-4462-A5A1-8E6836F04A68}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{3A903840-4059-48CF-A22A-58FE6784974E}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{3F38959A-EA97-4A37-9345-23B26C2D5400}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{4E33B177-83AF-438E-A9B7-51521E830321}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6624D611-F64F-4962-AB31-4C45397EB15E}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{6D28B6D4-C504-4EF5-8589-1F1D34097FCD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{70608EE2-010C-44A3-AF82-20C9E215688A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{746F6149-F5DB-4235-9F36-93523BA09873}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7A7E8387-0ADC-4ECC-9312-427264B10D34}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7B7B6357-B4EE-4A2A-A3F0-1044A0A1A219}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{7FC60A31-F11E-47C5-8598-86ECAF836BF9}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{895C8CD1-3F58-4D97-AE45-1D1DA4928AEB}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{89F4252D-A309-425B-9758-76473ED7022E}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{900E4DB0-0B91-40E0-B8AD-D03786C9167D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{92FDDDEE-FE8B-4035-A28C-DBE82C987B16}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{AAFF1CC7-9761-4BC2-AEFE-84A52ACDB4F0}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{AB414111-A1DD-4E50-A838-39F4AB1D9D73}" = protocol=6 | dir=in | app=c:\windows\system32\msra.exe |
"{B1259AE5-B78F-4EA8-870D-A659E70EF4B0}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{C58D2EFF-DC50-43AF-9082-1E69E2F31215}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{CE39721C-C88B-4C1E-8A21-95920ECC4B68}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{CE7F8CAB-39D7-4394-ADF9-C4BD8E401884}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version4\teamviewer.exe |
"{CED757FE-1101-4949-AE45-9494A37D0C77}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D3E9F45C-F9EC-420B-B8DF-344A8DC6D739}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{D9F1AB76-0BAB-487D-A38B-DFE5CCE0F9FC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E10DE5AB-5133-480E-B8FB-43B7C28BF630}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F06EA45F-2429-43A9-9593-19227EBB1DF3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F31BFB5C-5C33-4BA9-992A-5D51549547EC}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FBB89990-7949-4269-9BB0-93E0B6EBE604}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"TCP Query User{2D2F86FB-7CE1-48D6-9EC4-5B0B90DBC5C1}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"TCP Query User{2F99119C-0327-4D99-872F-CD40CD30778A}C:\program files (x86)\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"TCP Query User{4A3A1E59-5D4B-4838-A771-D3202EE3CEC3}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"TCP Query User{5AB783C8-B14E-480F-9DB5-1790D9E6D3C3}C:\program files (x86)\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"TCP Query User{81D01731-F965-45C0-81FD-2C4443A5E98A}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"TCP Query User{A5CE5DAB-A99E-4D58-88CB-3836E4152C72}C:\games\proun beta\proun.exe" = protocol=6 | dir=in | app=c:\games\proun beta\proun.exe |
"TCP Query User{C45CB190-1BF3-4EF6-B00B-F73295A79BB0}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{C7B08DE9-3A84-470A-9FD5-43A9898F0081}C:\games\proun beta\proun.exe" = protocol=6 | dir=in | app=c:\games\proun beta\proun.exe |
"TCP Query User{D08C850F-1A12-40CD-9607-D51693ED03B0}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"TCP Query User{E5EF7AE1-59FA-43B4-AE05-976F58553DFF}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{F2BAAD99-9FD7-460F-B967-EDCAD3DCB02C}C:\program files (x86)\deusty\mojo\mojo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\deusty\mojo\mojo.exe |
"UDP Query User{18545F1D-7223-4D5C-AB35-A966BA8CE694}C:\games\proun beta\proun.exe" = protocol=17 | dir=in | app=c:\games\proun beta\proun.exe |
"UDP Query User{2E03EBAB-F8BE-4B12-BB65-16BBFEEAB512}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{2F3D8845-A2EA-4128-88B4-413BBA3B9516}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{3F51A4A2-EE82-4E24-A3BD-D543A7B7E11E}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{746CA3F3-9E86-428B-B55B-E358E7775C00}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{98CA0011-6550-40C5-B741-9A081E894F3D}C:\games\proun beta\proun.exe" = protocol=17 | dir=in | app=c:\games\proun beta\proun.exe |
"UDP Query User{A26FB44B-88C0-4F09-B31B-880997BFAC1D}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{DBDFA360-E7C8-4F8F-BF1B-CE9D38ADC926}C:\program files (x86)\deusty\mojo\mojo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\deusty\mojo\mojo.exe |
"UDP Query User{EB108010-09B0-4FFF-A439-44B8E157E35B}C:\program files (x86)\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"UDP Query User{FFB999F5-26ED-46B8-AF55-E871C1B01905}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes
"{0F8B958D-3998-4FA3-B857-31B6E0BB9C98}" = ESET NOD32 Antivirus
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6CDA735E-D099-4ee8-94FC-2681BF33966C}" = SF_CDA_ToolboxIni64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{78F697ED-EC97-4D8D-881D-838984EA9855}" = 64 Bit HP CIO Components Installer
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{981DE354-9301-440f-AAFC-025AA2354A93}" = HP Deskjet & Photosmart Printer Driver Software 8.0.A
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Soft Data Fax Modem with SmartCP
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{12BE3579-A34B-47BD-A65C-82B1754E71E1}" = D4100
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{28780589-C504-4A32-B630-2F12546123A4}_is1" = Rubber Ninjas 1.05
"{2CB05D97-7301-455F-B2FE-857EB492CDBC}" = Mojo
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3C97C9C5-1AF3-41B0-B61C-185C06C75EE6}" = D4100_Help
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58F33687-EE1F-FE06-AC2B-6858503C33F2}" = Quick Hit - Football
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5EECEB40-3EE2-4762-872D-264346A26B84}_is1" = Rubber Ninjas Demo 1.05
"{6009F2FC-EC56-4e28-B91C-0BA5104D6419}" = SF_CDA_Software
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{8427F2DB-5833-4DBB-AFE9-D5358B6DF32F}" = League of Legends
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90EC11E4-854E-4C0F-9B4C-76D6C7CF7C68}" = Linksys WUSB600N Dual-Band Wireless-N USB Network Adapter
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9718521B-A345-4ad9-A52B-74D1435FB708}" = SF_CDA_ProductContext
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E1C256F5-58C6-44E9-939A-E1189C8126E2}" = Google SketchUp Pro 7
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AviSynth" = AviSynth 2.5
"conduitEngine" = Conduit Engine
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"ExpressBurn" = Express Burn Disc Burning Software
"InstallShield_{90EC11E4-854E-4C0F-9B4C-76D6C7CF7C68}" = Linksys Dual-Band Wireless-N USB Network Adapter
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MyWebSearch bar Uninstall" = My Web Search (MyWebFace)
"NCH_EN Toolbar" = NCH EN Toolbar
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Proun Beta" = Proun Beta
"quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1" = Quick Hit - Football
"Registry Mechanic_is1" = Registry Mechanic 9.0
"Search Toolbar" = Search Toolbar
"Sibelius Scorch Plugin_is1" = Sibelius Scorch Plugin [removed]
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"sp41119" = sp41119
"sp44626" = sp44626
"Switch" = Switch Sound File Converter
"TeamViewer 4" = TeamViewer 4
"UnityWebPlayer" = Unity Web Player
"WavePad" = WavePad Sound Editor
"WildTangent hp Master Uninstall" = My HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Move Media Player" = Move Media Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/11/2011 2:02:31 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/12/2011 2:02:35 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/12/2011 10:01:41 AM | Computer Name = HeinrichKids-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/12/2011 10:02:00 AM | Computer Name = HeinrichKids-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/13/2011 2:00:02 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/13/2011 7:43:48 PM | Computer Name = HeinrichKids-PC | Source = Application Error | ID = 1000
Description = Faulting application mDNSResponder.exe, version 2.0.4.0, time stamp
0x4cae1be1, faulting module mDNSResponder.exe, version 2.0.4.0, time stamp 0x4cae1be1,
exception code 0xc0000005, fault offset 0x0000110a, process id 0x8c0, application
start time 0x01cc27a248a75a02.
Error - 6/14/2011 2:02:36 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/14/2011 2:09:40 PM | Computer Name = HeinrichKids-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/15/2011 2:02:31 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/16/2011 2:02:33 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
[ System Events ]
Error - 12/30/2008 5:38:39 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:43 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:47 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:51 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:56 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:39:00 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:39:04 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/31/2008 1:20:12 PM | Computer Name = HeinrichKids-PC | Source = BROWSER | ID = 8032
Description =
Error - 1/1/2009 5:55:16 PM | Computer Name = HeinrichKids-PC | Source = HTTP | ID = 15016
Description =
Error - 1/1/2009 11:23:21 PM | Computer Name = HeinrichKids-PC | Source = HTTP | ID = 15016
Description =
< End of report >
Here's my OTL log:
OTL logfile created on: 6/22/2011 1:06:53 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Heinrich Kids\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.30 Gb Available Physical Memory | 45.28% Memory free
5.95 Gb Paging File | 4.20 Gb Available in Paging File | 70.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 107.24 Gb Free Space | 37.50% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.34 Gb Free Space | 11.03% Space Free | Partition Type: NTFS
Drive J: | 967.22 Mb Total Space | 966.63 Mb Free Space | 99.94% Space Free | Partition Type: FAT
Computer Name: HEINRICHKIDS-PC | User Name: Heinrich Kids | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Heinrich Kids\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\Registry Mechanic\RMTray.exe (PC Tools )
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
========== Modules (SafeList) ==========
MOD - C:\Users\Heinrich Kids\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (EhttpSrv) – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TeamViewer4) – C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (eamonm) – C:\Windows\SysNative\DRIVERS\eamonm.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\DRIVERS\ehdrv.sys (ESET)
DRV:64bit: - (epfwwfpr) – C:\Windows\SysNative\DRIVERS\epfwwfpr.sys (ESET)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (CAXHWBS2) – C:\Windows\SysNative\DRIVERS\CAXHWBS2.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (teamviewervpn) – C:\Windows\SysNative\DRIVERS\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\DRIVERS\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (PCD5SRVC{E2AF211B-86DA020A-05040000}) – C:\Program Files (x86)\PC-Doctor for Windows\pcd5srvc_x64.pkms (PC-Doctor, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - File not found
IE - HKCU\..\URLSearchHook: {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/?ilc=1"
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/21 22:48:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/11/23 22:06:18 | 000,000,000 | —D | M]
[2011/05/21 22:49:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Extensions
[2011/06/20 16:00:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Firefox\Profiles\gz2rfve9.default\extensions
[2011/06/20 16:00:59 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Heinrich Kids\AppData\Roaming\Mozilla\Firefox\Profiles\gz2rfve9.default\extensions\[removed]
[2011/05/21 22:48:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
[2010/04/07 14:43:57 | 000,000,000 | —D | M] (Move Media Player) – C:\USERS\HEINRICH KIDS\APPDATA\ROAMING\MOVE NETWORKS
[2011/04/14 11:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - Reg Error: Value error. File not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - Reg Error: Value error. File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (NCH EN Toolbar) - {37483b40-c254-4a72-bda4-22ee90182c1e} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files (x86)\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (NCH EN Toolbar) - {37483B40-C254-4A72-BDA4-22EE90182C1E} - C:\Program Files (x86)\NCH_EN\tbNCH_.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKCU..\Run: [Apoxiqaquzu] File not found
O4 - HKCU..\Run: [iLike] File not found
O4 - HKCU..\Run: [Jxofifurizevu] File not found
O4 - HKCU..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKCU..\Run: [NvCplDaemonTool] File not found
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files (x86)\Registry Mechanic\RMTray.exe (PC Tools )
O4 - HKCU..\Run: [RTHDBPL] File not found
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.2.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{39345b6a-d5ee-11dd-9fff-00226837a8a5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{791266c1-198f-11de-a70e-00226837a8a5}\Shell\AutoRun\command - "" = WDSetup.exe
O33 - MountPoints2\{e2ae1b85-13d7-11de-ae76-00226837a8a5}\Shell\Auto\command - "" = system16.exe
O33 - MountPoints2\{e2ae1b85-13d7-11de-ae76-00226837a8a5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system16.exe
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\WDSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/22 13:04:42 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/20 16:00:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Search Toolbar
[2011/06/17 03:08:14 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/17 03:08:14 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/17 03:08:13 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/17 03:08:12 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/06/17 03:08:12 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript9.dll
[2011/06/17 03:08:12 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/06/17 03:08:12 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/06/17 03:08:12 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 14:31:08 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/14 16:16:31 | 000,000,000 | —D | C] – C:\Users\Heinrich Kids\AppData\Local\RagdollSoft
[2011/06/06 13:04:42 | 000,000,000 | —D | C] – C:\Users\Heinrich Kids\AppData\Local\Unity
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/22 13:11:28 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/22 13:05:07 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/22 13:00:58 | 000,712,548 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/22 13:00:58 | 000,604,264 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/22 13:00:58 | 000,112,756 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/22 12:02:38 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/22 12:02:38 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/22 12:02:29 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/22 12:02:28 | 000,000,240 | —- | M] () – C:\Windows\tasks\PAV.job
[2011/06/22 12:02:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/22 12:02:21 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2011/06/20 15:58:59 | 039,823,604 | —- | M] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
[2011/06/17 03:42:14 | 000,340,968 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/05/27 18:02:08 | 000,002,619 | —- | M] () – C:\Users\Heinrich Kids\Desktop\Microsoft Word.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/20 15:51:05 | 039,823,604 | —- | C] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
[2010/10/30 09:52:40 | 000,000,000 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\Icugubi.bin
[2010/10/30 09:52:39 | 000,000,120 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\Kheloziqipuzi.dat
[2010/08/04 21:06:50 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/02/26 17:25:18 | 000,001,028 | —- | C] () – C:\Users\Heinrich Kids\AppData\Roaming\WavCodec.wff
[2009/11/25 17:42:37 | 000,000,224 | —- | C] () – C:\Windows\SIERRA.INI
[2009/11/25 17:41:59 | 000,021,840 | —- | C] () – C:\Windows\SysWow64\SIntfNT.dll
[2009/11/25 17:41:59 | 000,017,212 | —- | C] () – C:\Windows\SysWow64\SIntf32.dll
[2009/11/25 17:41:59 | 000,012,067 | —- | C] () – C:\Windows\SysWow64\SIntf16.dll
[2009/09/17 03:29:56 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/17 03:28:57 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/09/17 03:28:13 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 08:36:43 | 000,160,298 | —- | C] () – C:\Windows\hpqins00.dat
[2009/06/07 19:53:51 | 000,000,680 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\d3d9caps.dat
[2009/04/03 17:21:54 | 000,765,952 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009/04/03 17:21:54 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/02/12 22:01:35 | 000,021,074 | —- | C] () – C:\Users\Heinrich Kids\AppData\Roaming\UserTile.png
[2009/01/02 18:31:24 | 000,172,544 | —- | C] () – C:\Users\Heinrich Kids\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/01 19:20:02 | 000,133,447 | —- | C] () – C:\Windows\hppins20.dat
[2009/01/01 19:19:53 | 000,016,655 | —- | C] () – C:\Windows\hppmdl20.dat
[2008/12/30 20:15:03 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/12/30 06:18:34 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/08/06 09:04:20 | 000,107,384 | —- | C] () – C:\Windows\hpqins13.dat
[2008/08/06 08:40:30 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/08/06 08:40:30 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2009/02/15 12:36:28 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\aAvgApi
[2010/06/05 19:32:50 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\acccore
[2010/01/03 00:08:19 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\AuctioneerDb
[2011/01/12 18:18:08 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Azureus
[2009/09/30 22:56:25 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Deusty
[2010/12/24 15:28:31 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Downloaded Installations
[2010/11/23 22:00:50 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\ESET
[2009/01/25 20:46:08 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Gamelab
[2009/09/21 22:34:37 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\iLike
[2009/08/18 13:46:03 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Image Zone Express
[2011/05/08 13:46:25 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\iWin
[2010/10/29 22:10:52 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\LolClient
[2009/04/06 18:27:21 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\NCH Swift Sound
[2009/02/12 22:01:34 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\PeerNetworking
[2010/08/13 16:18:55 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\PlayFirst
[2009/02/04 22:39:42 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\Printer Info Cache
[2009/12/11 23:19:20 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1
[2010/07/13 10:19:12 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\SPORE Creature Creator
[2010/10/08 05:18:32 | 000,000,000 | -HSD | M] – C:\Users\Heinrich Kids\AppData\Roaming\SystemProc
[2009/10/08 17:30:34 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\TeamViewer
[2009/01/22 18:05:40 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\WildTangent
[2009/05/20 06:48:44 | 000,000,000 | —D | M] – C:\Users\Heinrich Kids\AppData\Roaming\WinBatch
[2011/06/22 12:02:28 | 000,000,240 | —- | M] () – C:\Windows\Tasks\PAV.job
[2011/06/21 22:14:22 | 000,032,522 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/08/06 09:21:32 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/04/29 15:28:33 | 000,000,250 | —- | M] () – C:\FINIS_IT.TXT
[2011/06/22 12:02:21 | 3084,050,432 | -HS- | M] () – C:\hiberfil.sys
[2010/06/05 19:32:33 | 000,000,359 | -H– | M] () – C:\IPH.PH
[2011/06/22 12:02:20 | 3397,791,744 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/17 17:36:03 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/12/19 14:59:10 | 000,001,658 | -H– | M] () – C:\Users\Heinrich Kids\AppData\Roaming\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/19 08:52:35 | 000,000,574 | -HS- | M] () – C:\Users\Heinrich Kids\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/06/22 13:05:07 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Users\Heinrich Kids\Desktop\OTL.exe
[2011/06/20 15:58:59 | 039,823,604 | —- | M] () – C:\Users\Heinrich Kids\Desktop\ProunBetainstaller.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:D1B5B4F1
< End of report >
And the Extras log:
OTL Extras logfile created on: 6/22/2011 1:06:53 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Heinrich Kids\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.30 Gb Available Physical Memory | 45.28% Memory free
5.95 Gb Paging File | 4.20 Gb Available in Paging File | 70.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.94 Gb Total Space | 107.24 Gb Free Space | 37.50% Space Free | Partition Type: NTFS
Drive D: | 12.15 Gb Total Space | 1.34 Gb Free Space | 11.03% Space Free | Partition Type: NTFS
Drive J: | 967.22 Mb Total Space | 966.63 Mb Free Space | 99.94% Space Free | Partition Type: FAT
Computer Name: HEINRICHKIDS-PC | User Name: Heinrich Kids | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = D1 C5 00 B7 39 38 CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12ADE82E-0DBA-4618-A39C-43B8E7987BA8}" = lport=5938 | protocol=6 | dir=in | name=teamviewer |
"{1D9F0610-68C4-4477-A1CF-5D01964C5B52}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{22BB8242-9FB0-49EF-85B7-B7C79FB3ADEE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{26839DA1-EF2B-4D20-9E58-9857BC34EA32}" = lport=138 | protocol=17 | dir=in | app=system |
"{34A6595B-6ABD-47B7-B2D0-401A00DECB86}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{45FF398A-EC73-47C9-BD19-E0F68551A22D}" = lport=137 | protocol=17 | dir=in | app=system |
"{499A87D0-7986-4EF8-8345-1751FC42E74E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4B538520-F447-4A12-A4EA-5C0930B9BA52}" = rport=137 | protocol=17 | dir=out | app=system |
"{5E9FF7A3-C864-417B-ABF1-C5874D7DCFE6}" = rport=445 | protocol=6 | dir=out | app=system |
"{646EE8D8-8894-40D1-B85E-C9C712B49311}" = lport=139 | protocol=6 | dir=in | app=system |
"{64FC2786-0F76-4732-8292-F5112902D1D6}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{6DC285E7-B88F-4D6C-8F17-5D0A9F59865D}" = lport=8380 | protocol=17 | dir=in | name=league of legends launcher |
"{6E5A090B-A576-4F80-AC40-BB3E38DACD2E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{8344EFC1-8EDD-4102-93AF-4F349304F65D}" = lport=8380 | protocol=6 | dir=in | name=league of legends launcher |
"{8432AE6E-84B2-418E-AA0F-CDC4770C2F80}" = rport=138 | protocol=17 | dir=out | app=system |
"{86CFB88F-5D5C-4C7F-9938-0559E11670FB}" = lport=80 | protocol=6 | dir=in | name=teamviewer2 |
"{8BB76035-0116-46A5-9298-E2C2B6C87B47}" = rport=139 | protocol=6 | dir=out | app=system |
"{9D6562A0-0F3F-452E-A336-95512E7135CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A95EE3F0-EF82-4E33-863E-BE81D5363E51}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C9DFCCE9-57A2-4508-9926-C64F9FD171B6}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{CF995F9F-6E96-49D0-8DBF-8394803529BF}" = lport=445 | protocol=6 | dir=in | app=system |
"{D2DB1B1D-F0BB-427D-8F0A-09BB5680EB85}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02BAF3BF-63AB-4DA0-8B1D-75617C4B514A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{164F3B72-FA40-491E-8AD9-E0511EC97155}" = protocol=17 | dir=in | app=c:\windows\system32\msra.exe |
"{1F34F8FB-E8E7-49AC-BBB2-040195AAB7B5}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{2385F6AA-6995-4C17-8AAD-60805AA5771F}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{2B0426DA-1E34-46EF-BF2F-E2179861F048}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version4\teamviewer.exe |
"{2BFE2C67-E2CE-4735-9A0A-441E457C1FF7}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{2DFF1108-5925-44C4-8307-BFA4486E9835}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{32CEAD5B-7D57-4AB3-A7A4-7A6FB2285618}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{3A8A3E3E-2351-4462-A5A1-8E6836F04A68}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{3A903840-4059-48CF-A22A-58FE6784974E}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{3F38959A-EA97-4A37-9345-23B26C2D5400}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{4E33B177-83AF-438E-A9B7-51521E830321}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6624D611-F64F-4962-AB31-4C45397EB15E}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{6D28B6D4-C504-4EF5-8589-1F1D34097FCD}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{70608EE2-010C-44A3-AF82-20C9E215688A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{746F6149-F5DB-4235-9F36-93523BA09873}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7A7E8387-0ADC-4ECC-9312-427264B10D34}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7B7B6357-B4EE-4A2A-A3F0-1044A0A1A219}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{7FC60A31-F11E-47C5-8598-86ECAF836BF9}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{895C8CD1-3F58-4D97-AE45-1D1DA4928AEB}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{89F4252D-A309-425B-9758-76473ED7022E}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{900E4DB0-0B91-40E0-B8AD-D03786C9167D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{92FDDDEE-FE8B-4035-A28C-DBE82C987B16}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{AAFF1CC7-9761-4BC2-AEFE-84A52ACDB4F0}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{AB414111-A1DD-4E50-A838-39F4AB1D9D73}" = protocol=6 | dir=in | app=c:\windows\system32\msra.exe |
"{B1259AE5-B78F-4EA8-870D-A659E70EF4B0}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{C58D2EFF-DC50-43AF-9082-1E69E2F31215}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{CE39721C-C88B-4C1E-8A21-95920ECC4B68}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{CE7F8CAB-39D7-4394-ADF9-C4BD8E401884}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version4\teamviewer.exe |
"{CED757FE-1101-4949-AE45-9494A37D0C77}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{D3E9F45C-F9EC-420B-B8DF-344A8DC6D739}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{D9F1AB76-0BAB-487D-A38B-DFE5CCE0F9FC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E10DE5AB-5133-480E-B8FB-43B7C28BF630}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F06EA45F-2429-43A9-9593-19227EBB1DF3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F31BFB5C-5C33-4BA9-992A-5D51549547EC}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FBB89990-7949-4269-9BB0-93E0B6EBE604}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"TCP Query User{2D2F86FB-7CE1-48D6-9EC4-5B0B90DBC5C1}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"TCP Query User{2F99119C-0327-4D99-872F-CD40CD30778A}C:\program files (x86)\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"TCP Query User{4A3A1E59-5D4B-4838-A771-D3202EE3CEC3}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"TCP Query User{5AB783C8-B14E-480F-9DB5-1790D9E6D3C3}C:\program files (x86)\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"TCP Query User{81D01731-F965-45C0-81FD-2C4443A5E98A}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"TCP Query User{A5CE5DAB-A99E-4D58-88CB-3836E4152C72}C:\games\proun beta\proun.exe" = protocol=6 | dir=in | app=c:\games\proun beta\proun.exe |
"TCP Query User{C45CB190-1BF3-4EF6-B00B-F73295A79BB0}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{C7B08DE9-3A84-470A-9FD5-43A9898F0081}C:\games\proun beta\proun.exe" = protocol=6 | dir=in | app=c:\games\proun beta\proun.exe |
"TCP Query User{D08C850F-1A12-40CD-9607-D51693ED03B0}C:\sierra\empire earth\empire earth.exe" = protocol=6 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"TCP Query User{E5EF7AE1-59FA-43B4-AE05-976F58553DFF}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{F2BAAD99-9FD7-460F-B967-EDCAD3DCB02C}C:\program files (x86)\deusty\mojo\mojo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\deusty\mojo\mojo.exe |
"UDP Query User{18545F1D-7223-4D5C-AB35-A966BA8CE694}C:\games\proun beta\proun.exe" = protocol=17 | dir=in | app=c:\games\proun beta\proun.exe |
"UDP Query User{2E03EBAB-F8BE-4B12-BB65-16BBFEEAB512}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{2F3D8845-A2EA-4128-88B4-413BBA3B9516}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{3F51A4A2-EE82-4E24-A3BD-D543A7B7E11E}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{746CA3F3-9E86-428B-B55B-E358E7775C00}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{98CA0011-6550-40C5-B741-9A081E894F3D}C:\games\proun beta\proun.exe" = protocol=17 | dir=in | app=c:\games\proun beta\proun.exe |
"UDP Query User{A26FB44B-88C0-4F09-B31B-880997BFAC1D}C:\sierra\empire earth\empire earth.exe" = protocol=17 | dir=in | app=c:\sierra\empire earth\empire earth.exe |
"UDP Query User{DBDFA360-E7C8-4F8F-BF1B-CE9D38ADC926}C:\program files (x86)\deusty\mojo\mojo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\deusty\mojo\mojo.exe |
"UDP Query User{EB108010-09B0-4FFF-A439-44B8E157E35B}C:\program files (x86)\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"UDP Query User{FFB999F5-26ED-46B8-AF55-E871C1B01905}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes
"{0F8B958D-3998-4FA3-B857-31B6E0BB9C98}" = ESET NOD32 Antivirus
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6CDA735E-D099-4ee8-94FC-2681BF33966C}" = SF_CDA_ToolboxIni64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{78F697ED-EC97-4D8D-881D-838984EA9855}" = 64 Bit HP CIO Components Installer
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{981DE354-9301-440f-AAFC-025AA2354A93}" = HP Deskjet & Photosmart Printer Driver Software 8.0.A
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Soft Data Fax Modem with SmartCP
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{12BE3579-A34B-47BD-A65C-82B1754E71E1}" = D4100
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{28780589-C504-4A32-B630-2F12546123A4}_is1" = Rubber Ninjas 1.05
"{2CB05D97-7301-455F-B2FE-857EB492CDBC}" = Mojo
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3C97C9C5-1AF3-41B0-B61C-185C06C75EE6}" = D4100_Help
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{58F33687-EE1F-FE06-AC2B-6858503C33F2}" = Quick Hit - Football
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5EECEB40-3EE2-4762-872D-264346A26B84}_is1" = Rubber Ninjas Demo 1.05
"{6009F2FC-EC56-4e28-B91C-0BA5104D6419}" = SF_CDA_Software
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{8427F2DB-5833-4DBB-AFE9-D5358B6DF32F}" = League of Legends
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90EC11E4-854E-4C0F-9B4C-76D6C7CF7C68}" = Linksys WUSB600N Dual-Band Wireless-N USB Network Adapter
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9718521B-A345-4ad9-A52B-74D1435FB708}" = SF_CDA_ProductContext
"{97ABD26A-3249-46CB-B2E2-F66E64B2E480}" = HP Demo
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B9AB88D8-3A09-4A4A-8993-0E2F6F9F294B}" = muvee autoProducer 6.1
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E1C256F5-58C6-44E9-939A-E1189C8126E2}" = Google SketchUp Pro 7
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AviSynth" = AviSynth 2.5
"conduitEngine" = Conduit Engine
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"ExpressBurn" = Express Burn Disc Burning Software
"InstallShield_{90EC11E4-854E-4C0F-9B4C-76D6C7CF7C68}" = Linksys Dual-Band Wireless-N USB Network Adapter
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MyWebSearch bar Uninstall" = My Web Search (MyWebFace)
"NCH_EN Toolbar" = NCH EN Toolbar
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Proun Beta" = Proun Beta
"quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1" = Quick Hit - Football
"Registry Mechanic_is1" = Registry Mechanic 9.0
"Search Toolbar" = Search Toolbar
"Sibelius Scorch Plugin_is1" = Sibelius Scorch Plugin [removed]
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"sp41119" = sp41119
"sp44626" = sp44626
"Switch" = Switch Sound File Converter
"TeamViewer 4" = TeamViewer 4
"UnityWebPlayer" = Unity Web Player
"WavePad" = WavePad Sound Editor
"WildTangent hp Master Uninstall" = My HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR archiver
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Move Media Player" = Move Media Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/11/2011 2:02:31 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/12/2011 2:02:35 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/12/2011 10:01:41 AM | Computer Name = HeinrichKids-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/12/2011 10:02:00 AM | Computer Name = HeinrichKids-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/13/2011 2:00:02 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/13/2011 7:43:48 PM | Computer Name = HeinrichKids-PC | Source = Application Error | ID = 1000
Description = Faulting application mDNSResponder.exe, version 2.0.4.0, time stamp
0x4cae1be1, faulting module mDNSResponder.exe, version 2.0.4.0, time stamp 0x4cae1be1,
exception code 0xc0000005, fault offset 0x0000110a, process id 0x8c0, application
start time 0x01cc27a248a75a02.
Error - 6/14/2011 2:02:36 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/14/2011 2:09:40 PM | Computer Name = HeinrichKids-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/15/2011 2:02:31 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
Error - 6/16/2011 2:02:33 AM | Computer Name = HeinrichKids-PC | Source = Windows Backup | ID = 4103
Description =
[ System Events ]
Error - 12/30/2008 5:38:39 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:43 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:47 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:51 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:38:56 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:39:00 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/30/2008 5:39:04 PM | Computer Name = HeinrichKids-PC | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 12/31/2008 1:20:12 PM | Computer Name = HeinrichKids-PC | Source = BROWSER | ID = 8032
Description =
Error - 1/1/2009 5:55:16 PM | Computer Name = HeinrichKids-PC | Source = HTTP | ID = 15016
Description =
Error - 1/1/2009 11:23:21 PM | Computer Name = HeinrichKids-PC | Source = HTTP | ID = 15016
Description =
< End of report >