OTL:
======================================
OTL logfile created on: 7/5/2011 10:23:24 PM - Run 1
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\shingy\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 39.54% Memory free
9.86 Gb Paging File | 7.49 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): e:\pagefile.sys 6000 6000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.90 Gb Total Space | 20.28 Gb Free Space | 36.27% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 111.21 Gb Free Space | 47.77% Space Free | Partition Type: NTFS
Drive E: | 29.82 Gb Total Space | 10.56 Gb Free Space | 35.42% Space Free | Partition Type: NTFS
Drive H: | 122.22 Mb Total Space | 122.21 Mb Free Space | 100.00% Space Free | Partition Type: FAT
Computer Name: DESKTOP | User Name: shingy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\shingy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
========== Modules (SafeList) ==========
MOD - C:\Users\shingy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV:
64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:
64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (sdCoreService) – C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (afcdpsrv) – C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (AcrSch2Svc) – C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:
64bit: - (pctplsg) – C:\Windows\SysNative\drivers\pctplsg64.sys (PC Tools)
DRV:
64bit: - (pctgntdi) – C:\Windows\SysNative\drivers\pctgntdi64.sys (PC Tools)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (PCTSD) – C:\Windows\SysNative\drivers\PCTSD64.sys (PC Tools)
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:
64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:
64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:
64bit: - (afcdp) – C:\Windows\SysNative\drivers\afcdp.sys (Acronis)
DRV:
64bit: - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\Windows\SysNative\drivers\tdrpm251.sys (Acronis)
DRV:
64bit: - (timounter) – C:\Windows\SysNative\drivers\timntr.sys (Acronis)
DRV:
64bit: - (snapman) – C:\Windows\SysNative\drivers\snapman.sys (Acronis)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (pctDS) – C:\Windows\SysNative\drivers\pctDS64.sys (PC Tools)
DRV:
64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:
64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:
64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:
64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:
64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV:
64bit: - (KeyScrambler) – C:\Windows\SysNative\drivers\keyscrambler.sys (QFX Software Corporation)
DRV:
64bit: - (HPFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 3E 90 39 36 39 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Applications\Internet\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\@worldwinner.com/Launcher2,version=1.9.0.23: C:\Program Files (x86)\WorldWinner.com, Inc\WorldWinner Games\npwwload.dll (WorldWinner.com, Inc.)
FF:
64bit: - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF:
64bit: - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\shingy\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/30 21:35:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKCU\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/30 21:35:50 | 000,000,000 | —D | M]
FF - HKCU\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/06/30 21:36:27 | 000,000,000 | —D | M] (No name found) – C:\Users\shingy\AppData\Roaming\Mozilla\Extensions
[2011/07/02 22:11:06 | 000,000,000 | —D | M] (No name found) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions
[2011/06/30 22:14:47 | 000,000,000 | —D | M] (IE Tab 2 (FF 3.6+)) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2011/06/30 22:14:47 | 000,000,000 | —D | M] (FEBE) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2011/07/01 18:43:30 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Users\shingy\AppData\Roaming\Mozilla\Firefox\Profiles\xx888xpl.default\extensions\[removed]
[2011/06/30 21:35:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{04426594-BCE6-4705-B811-BCDBA2FD9C7B}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{0FA2149E-BB2C-4AC2-A8D3-479599819475}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{35106BCA-6C78-48C7-AC28-56DF30B51D2A}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{35106BCA-6C78-48C7-AC28-56DF30B51D2C}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{582195F5-92E7-40A0-A127-DB71295901D7}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{987311C6-B504-4AA2-90BF-60CC49808D42}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{A76CD07B-F0D7-4EF9-9566-8FAEF6E290E4}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{EDA7B1D7-F793-4E03-B074-E6F303317FB0}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\{F645A8C9-E969-42D9-B3F3-F325537222FD}.XPI
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SHINGY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XX888XPL.DEFAULT\EXTENSIONS\[removed]
[2011/06/16 00:17:34 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/07/03 16:18:35 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (CKeyScramblerBHO Object) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [CD Autorun] File not found
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AIM] File not found
O4 - Startup: C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\shingy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCANetwork = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAVolume = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCABattery = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: TaskbarNoThumbnail = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:
64bit: - Extra 'Tools' menuitem : &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Applications\Internet\AIM\aim.exe (America Online, Inc.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O18:
64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - Reg Error: Key error. File not found
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\SysWow64\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/07/05 18:23:13 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/07/05 12:45:08 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/07/05 11:45:34 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/07/05 11:45:34 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/07/05 11:44:27 | 000,000,000 | —D | C] – C:\ComboFix
[2011/07/05 11:42:19 | 000,000,000 | —D | C] – C:\Qoobox
[2011/07/05 11:34:02 | 004,132,182 | R— | C] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/03 23:21:48 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Local\Adobe
[2011/07/03 15:36:11 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/07/03 14:33:49 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Malwarebytes
[2011/07/03 14:33:41 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/03 14:11:29 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
[2011/07/03 14:11:28 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2011/07/03 14:11:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2011/07/03 12:29:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/07/03 12:27:35 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/07/03 12:23:11 | 000,000,000 | R–D | C] – C:\Users\shingy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/07/03 12:03:32 | 000,816,016 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2011/07/03 12:03:32 | 000,452,872 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2011/07/03 12:03:26 | 000,279,344 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2011/07/03 12:03:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011/07/03 11:51:42 | 000,334,976 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctgntdi64.sys
[2011/07/03 11:51:42 | 000,140,800 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2011/07/03 11:51:38 | 000,282,440 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTCore64.sys
[2011/07/03 11:51:37 | 000,092,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Doctor
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\PC Tools
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/07/03 11:51:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2011/07/03 11:51:25 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2011/07/03 11:49:44 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\GetRightToGo
[2011/07/03 11:03:31 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/07/03 11:03:25 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/07/02 21:49:24 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Weird_Al_Yankovic-Alpocalypse-2011-MTD
[2011/07/02 10:50:35 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:34 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe
[2011/07/02 02:59:20 | 001,925,512 | —- | C] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/06/30 21:36:24 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Mozilla
[2011/06/30 21:35:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/06/29 22:07:31 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Captivate Training
[2011/06/29 21:08:02 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\PDA lake pics
[2011/06/29 12:07:30 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2011/06/29 12:07:30 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2011/06/29 12:07:28 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011/06/29 12:07:28 | 002,228,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011/06/29 12:07:28 | 001,401,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011/06/29 12:07:27 | 001,553,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011/06/29 12:07:26 | 000,779,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011/06/29 12:07:26 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011/06/29 12:07:26 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011/06/29 12:07:26 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011/06/29 12:07:26 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011/06/29 12:07:26 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011/06/29 12:07:25 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011/06/29 12:07:25 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssphtb.dll
[2011/06/29 12:07:25 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011/06/29 12:07:25 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011/06/27 21:08:43 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Recipes
[2011/06/22 22:13:29 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Advanced Font Viewer
[2011/06/22 22:11:15 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\Free Font Renamer
[2011/06/19 13:55:34 | 000,000,000 | —D | C] – C:\Users\shingy\Desktop\Resume
[2011/06/18 18:01:44 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/18 18:01:44 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/18 18:01:43 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/18 18:01:43 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/18 18:01:43 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/18 18:01:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/18 18:01:42 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/18 18:01:42 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/18 18:01:42 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/18 18:01:42 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/18 18:01:41 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/18 18:01:41 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/18 18:01:41 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/18 18:01:41 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/18 18:01:29 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/18 18:01:28 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/06/18 18:01:24 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/11 18:11:16 | 000,000,000 | —D | C] – C:\Users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/07 17:57:56 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/06/07 17:57:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/07 17:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/06/07 17:57:46 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\shingy\AppData\Local\*.tmp files -> C:\Users\shingy\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/05 22:19:32 | 000,000,512 | —- | M] () – C:\Users\shingy\Desktop\MBR.dat
[2011/07/05 21:53:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/05 21:42:04 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000UA.job
[2011/07/05 18:30:18 | 000,013,664 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/05 18:30:18 | 000,013,664 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/05 18:28:30 | 000,747,550 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/07/05 18:28:30 | 000,637,934 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/07/05 18:28:30 | 000,112,408 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/07/05 18:23:12 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/05 18:23:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/05 11:34:05 | 004,132,182 | R— | M] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/03 16:18:35 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/07/03 14:11:29 | 000,002,260 | —- | M] () – C:\Users\shingy\Desktop\SpyHunter.lnk
[2011/07/03 12:03:26 | 000,002,051 | —- | M] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/07/03 01:51:12 | 000,000,000 | —- | M] () – C:\Users\shingy\AppData\Local\{9F4BA5F5-273D-486F-94B2-CA5E529BA41C}
[2011/07/03 01:49:09 | 000,129,024 | —- | M] () – C:\Windows\RegBootClean64.exe
[2011/07/03 01:45:17 | 006,675,798 | —- | M] () – C:\Users\shingy\AppData\Local\census.cache
[2011/07/03 01:43:58 | 000,070,078 | —- | M] () – C:\Users\shingy\AppData\Local\ars.cache
[2011/07/03 00:33:46 | 000,002,736 | —- | M] () – C:\Users\shingy\AppData\Roaming\2582.DB9
[2011/07/02 23:59:44 | 000,000,232 | —- | M] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | M] () – C:\ProgramData\~39444216r
[2011/07/02 19:49:45 | 000,069,547 | —- | M] () – C:\Users\shingy\Desktop\Products_ Phones, Wireless Devices, Gift Cards, Accessories - Verizon Wireless.pdf
[2011/07/02 10:50:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:44 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe
[2011/07/02 02:59:36 | 001,925,512 | —- | M] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/06/30 21:36:27 | 000,001,138 | —- | M] () – C:\Users\shingy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/30 21:05:15 | 016,853,784 | —- | M] () – C:\Users\shingy\Desktop\5b3e03h9.default.zip
[2011/06/30 07:18:44 | 005,049,816 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/29 22:42:45 | 000,002,368 | —- | M] () – C:\Users\shingy\Desktop\Google Chrome.lnk
[2011/06/29 19:13:34 | 000,002,194 | —- | M] () – C:\Users\shingy\Desktop\Google Earth.lnk
[2011/06/26 22:33:16 | 065,693,959 | —- | M] () – C:\Users\shingy\Desktop\Louis CK - 2005.12.29 Hoboken, NJ Bootleg (full recording).mp4
[2011/06/26 02:45:56 | 000,256,000 | —- | M] () – C:\Windows\PEV.exe
[2011/06/22 22:16:43 | 000,494,658 | —- | M] () – C:\Users\shingy\Desktop\KIEA_2011_report.pdf
[2011/06/22 21:49:43 | 001,818,056 | —- | M] () – C:\Users\shingy\Desktop\CougarLife BBB complaint.pdf
[2011/06/20 20:59:36 | 000,000,192 | —- | M] () – C:\Windows\winamp.ini
[2011/06/11 03:42:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1333310377-3377235737-4070044975-1000Core.job
[2011/06/07 20:43:34 | 000,471,261 | —- | M] () – C:\Users\shingy\Desktop\MJCCA • A Page from the Book Festival presents Ben Mezrich.pdf
[2011/06/07 17:57:50 | 000,002,533 | —- | M] () – C:\Users\shingy\Desktop\Skype.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\shingy\AppData\Local\*.tmp files -> C:\Users\shingy\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/05 19:20:43 | 000,000,512 | —- | C] () – C:\Users\shingy\Desktop\MBR.dat
[2011/07/05 11:45:35 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/07/05 11:45:34 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/07/05 11:45:34 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/07/05 11:45:34 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/07/05 11:45:34 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/07/03 15:57:47 | 000,002,665 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toodledo Sync Tool.lnk
[2011/07/03 15:57:46 | 000,001,782 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Firefox.lnk
[2011/07/03 15:57:45 | 000,001,105 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Outlook.lnk
[2011/07/03 15:55:52 | 000,000,827 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinISO.lnk
[2011/07/03 15:55:51 | 000,001,266 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Update.lnk
[2011/07/03 15:55:50 | 000,001,174 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photoshop CS4.lnk
[2011/07/03 15:55:49 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero.lnk
[2011/07/03 15:55:48 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/07/03 15:55:47 | 000,002,627 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft ICE.lnk
[2011/07/03 15:55:46 | 000,002,447 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes.lnk
[2011/07/03 15:55:44 | 000,001,554 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Illustrator CS4.lnk
[2011/07/03 15:55:43 | 000,002,304 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
[2011/07/03 15:55:42 | 000,001,135 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dreamweaver CS4.lnk
[2011/07/03 15:55:41 | 000,001,621 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CuteFTP.lnk
[2011/07/03 15:55:40 | 000,000,973 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS5.lnk
[2011/07/03 15:55:39 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/07/03 15:55:38 | 000,001,179 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate Reviewer 2.0.lnk
[2011/07/03 15:55:37 | 000,001,267 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate Quiz Results Analyzer.lnk
[2011/07/03 15:55:35 | 000,000,999 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Captivate 5.lnk
[2011/07/03 15:55:34 | 000,001,265 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis True Image.lnk
[2011/07/03 14:11:29 | 000,002,260 | —- | C] () – C:\Users\shingy\Desktop\SpyHunter.lnk
[2011/07/03 12:03:26 | 000,002,051 | —- | C] () – C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011/07/03 11:51:42 | 000,007,357 | —- | C] () – C:\Windows\SysNative\drivers\pctgntdi64.cat
[2011/07/03 11:51:38 | 000,007,353 | —- | C] () – C:\Windows\SysNative\drivers\pctcore64.cat
[2011/07/03 11:51:37 | 000,007,353 | —- | C] () – C:\Windows\SysNative\drivers\pctplsg64.cat
[2011/07/03 01:51:12 | 000,000,000 | —- | C] () – C:\Users\shingy\AppData\Local\{9F4BA5F5-273D-486F-94B2-CA5E529BA41C}
[2011/07/03 01:49:00 | 000,129,024 | —- | C] () – C:\Windows\RegBootClean64.exe
[2011/07/03 01:45:17 | 006,675,798 | —- | C] () – C:\Users\shingy\AppData\Local\census.cache
[2011/07/03 01:43:58 | 000,070,078 | —- | C] () – C:\Users\shingy\AppData\Local\ars.cache
[2011/07/02 23:59:44 | 000,000,232 | —- | C] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | C] () – C:\ProgramData\~39444216r
[2011/07/02 23:45:59 | 000,002,736 | —- | C] () – C:\Users\shingy\AppData\Roaming\2582.DB9
[2011/07/02 19:49:45 | 000,069,547 | —- | C] () – C:\Users\shingy\Desktop\Products_ Phones, Wireless Devices, Gift Cards, Accessories - Verizon Wireless.pdf
[2011/06/30 21:36:16 | 000,001,138 | —- | C] () – C:\Users\shingy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/06/30 21:05:11 | 016,853,784 | —- | C] () – C:\Users\shingy\Desktop\5b3e03h9.default.zip
[2011/06/29 19:12:52 | 000,002,194 | —- | C] () – C:\Users\shingy\Desktop\Google Earth.lnk
[2011/06/26 22:06:48 | 065,693,959 | —- | C] () – C:\Users\shingy\Desktop\Louis CK - 2005.12.29 Hoboken, NJ Bootleg (full recording).mp4
[2011/06/21 18:50:39 | 001,818,056 | —- | C] () – C:\Users\shingy\Desktop\CougarLife BBB complaint.pdf
[2011/06/13 18:28:19 | 000,002,533 | —- | C] () – C:\Users\shingy\Desktop\Skype.lnk
[2011/06/07 20:43:34 | 000,471,261 | —- | C] () – C:\Users\shingy\Desktop\MJCCA • A Page from the Book Festival presents Ben Mezrich.pdf
[2011/05/14 11:11:26 | 000,083,968 | —- | C] () – C:\Windows\UnGins.exe
[2011/04/07 22:23:10 | 000,000,236 | —- | C] () – C:\Users\shingy\AppData\Roaming\Recorder.ini
[2011/02/13 13:34:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/02/01 20:58:03 | 000,000,036 | —- | C] () – C:\Windows\verypdf.ini
[2011/02/01 20:57:53 | 000,001,024 | —- | C] () – C:\Windows\SysWow64\pwdremover.dat
[2010/12/31 13:21:20 | 000,003,584 | —- | C] () – C:\Users\shingy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/15 15:33:32 | 000,002,975 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010/11/09 23:41:55 | 000,000,036 | —- | C] () – C:\Users\shingy\AppData\Local\housecall.guid.cache
[2010/11/06 10:30:20 | 000,219,868 | —- | C] () – C:\Windows\SysWow64\mlfcache.dat
[2010/10/23 12:55:11 | 000,962,560 | —- | C] () – C:\Windows\tesseract.exe
[2010/10/23 11:37:33 | 000,000,125 | —- | C] () – C:\Windows\BuzzTWCP.INI
[2010/10/23 11:37:33 | 000,000,101 | —- | C] () – C:\Windows\BUZZTWLC.INI
[2010/10/23 11:37:33 | 000,000,088 | —- | C] () – C:\Windows\BuzzTWSC.INI
[2010/10/16 22:32:42 | 000,134,078 | —- | C] () – C:\Windows\hppins06.dat.temp
[2010/10/16 22:32:42 | 000,001,247 | —- | C] () – C:\Windows\hppmdl06.dat.temp
[2010/10/16 22:31:39 | 000,000,094 | —- | C] () – C:\Users\shingy\AppData\Local\fusioncache.dat
[2010/10/16 22:24:09 | 000,000,120 | —- | C] () – C:\Windows\hpbvspst.ini
[2010/10/16 22:23:12 | 000,133,490 | —- | C] () – C:\Windows\hppins06.dat
[2010/10/16 22:23:12 | 000,001,247 | —- | C] () – C:\Windows\hppmdl06.dat
[2010/10/16 18:06:51 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2010/10/16 11:58:22 | 000,004,096 | —- | C] () – C:\Users\shingy\AppData\Local\keyfile3.drm
[2010/10/10 20:31:08 | 000,010,752 | —- | C] () – C:\Windows\SysWow64\BASSMOD.dll
[2010/10/10 19:25:38 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\pxhpinst.exe
[2010/10/10 19:25:37 | 000,000,192 | —- | C] () – C:\Windows\winamp.ini
[2010/10/10 19:24:48 | 000,168,448 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/10/10 19:24:47 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2010/10/10 19:24:47 | 002,255,360 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2010/10/10 19:24:47 | 000,795,648 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/10/10 19:24:47 | 000,130,048 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/10/10 19:24:46 | 000,067,584 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/10/10 14:55:26 | 000,007,606 | —- | C] () – C:\Users\shingy\AppData\Local\resmon.resmoncfg
[2010/10/10 13:29:14 | 000,000,442 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/10/10 11:40:34 | 000,760,544 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/10 10:01:35 | 000,000,056 | —- | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/10/10 09:59:58 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/10/10 09:33:26 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2010/10/16 16:58:37 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Acronis
[2011/06/22 22:13:30 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Advanced Font Viewer
[2010/10/10 18:46:31 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Aim
[2011/03/01 22:49:19 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Artisteer
[2011/06/11 18:11:16 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/05 18:23:24 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Dropbox
[2011/06/22 22:11:15 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Free Font Renamer
[2011/07/03 11:51:33 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\GetRightToGo
[2010/10/10 20:30:15 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\GlobalSCAPE
[2011/04/02 17:10:12 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\mjusbsp
[2011/01/29 18:58:07 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\MSNStockQuote
[2011/04/03 13:01:17 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\TaxCut
[2010/10/16 18:50:02 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\TweakNow PowerPack 2010
[2011/07/04 11:46:09 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\uTorrent
[2011/03/12 11:54:51 | 000,000,000 | —D | M] – C:\Users\shingy\AppData\Roaming\Worldwinner
[2011/04/05 07:12:59 | 000,032,650 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/10 19:23:22 | 000,001,024 | —- | M] () – C:\.rnd
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/10/10 00:04:10 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/11 18:22:46 | 000,000,000 | —- | M] () – C:\CaptivateLog.log
[2011/07/05 12:44:43 | 000,019,231 | —- | M] () – C:\ComboFix.txt
[2010/10/10 18:44:51 | 000,000,360 | —- | M] () – C:\IPH.PH
[2011/02/01 20:58:10 | 000,000,049 | —- | M] () – C:\pdfinfo.ini
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/09 20:33:26 | 000,000,221 | -HS- | M] () – C:\Users\shingy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/07/02 02:59:36 | 001,925,512 | —- | M] (AVAST Software) – C:\Users\shingy\Desktop\aswMBR.exe
[2011/07/05 11:34:05 | 004,132,182 | R— | M] (Swearware) – C:\Users\shingy\Desktop\ComboFix.exe
[2011/07/02 10:50:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\shingy\Desktop\HiJackThis.exe
[2011/07/02 02:59:44 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\shingy\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\ADDINS\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/10/11 18:52:57 | 000,000,402 | -HS- | M] () – C:\Users\shingy\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2010/10/16 22:32:52 | 000,004,465 | —- | M] () – C:\ProgramData\hpzinstall.log
[2010/10/16 22:27:54 | 000,000,442 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2011/07/02 23:59:44 | 000,000,232 | —- | M] () – C:\ProgramData\~39444216
[2011/07/02 23:59:44 | 000,000,176 | —- | M] () – C:\ProgramData\~39444216r
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
=====================================
OTL Extras logfile created on: 7/5/2011 10:23:24 PM - Run 1
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\shingy\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 39.54% Memory free
9.86 Gb Paging File | 7.49 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): e:\pagefile.sys 6000 6000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 55.90 Gb Total Space | 20.28 Gb Free Space | 36.27% Space Free | Partition Type: NTFS
Drive D: | 232.79 Gb Total Space | 111.21 Gb Free Space | 47.77% Space Free | Partition Type: NTFS
Drive E: | 29.82 Gb Total Space | 10.56 Gb Free Space | 35.42% Space Free | Partition Type: NTFS
Drive H: | 122.22 Mb Total Space | 122.21 Mb Free Space | 100.00% Space Free | Partition Type: FAT
Computer Name: DESKTOP | User Name: shingy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %* File not found
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" && icacls "%1" /grant administrators:F (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Applications\Other\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Applications\Other\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Applications\Other\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" && icacls "%1" /grant administrators:F (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Applications\Other\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Applications\Other\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Applications\Other\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{108A39BF-4ED1-4293-B11A-06BD521FB8F7}" = FreeOCR 3.0
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3CDE6FFC-99E4-4035-8B9A-2A7A77FBE11D}" = Google Apps Migration For Microsoft Outlook® [removed]
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{4ACA6F0A-97D9-4CD0-9F66-2CFB30A97E3C}" = Microsoft Image Composite Editor
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{73BA9A8F-6B40-BF79-541E-464156FBA764}" = ccc-utility64
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8AE3EC14-EAF8-4064-958A-C340C66EDD44}" = SpyHunter
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AC76BA86-1033-0000-0064-0003D0000004}" = Adobe Acrobat 9 Pro Extended 64-bit Add-On
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B361F88B-D513-9D45-E7F2-871B61C46D32}" = WMV9/VC-1 Video Playback
"{B6EFD9A5-2ECE-4C22-BAEC-D16E73EA2013}" = iTunes
"{C5970161-E13E-6661-BBDA-A08268313C83}" = ATI Catalyst Install Manager
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E77543EE-6FB5-4FF6-AB70-635392C8C756}" = Microsoft Security Client
"{EE269999-1AB7-7B39-7944-513CF3426CB8}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FDD06F32-C9C8-429C-A7B0-915D8A5AD406}" = 64 Bit HP CIO Components Installer
"HP Color LaserJet CM1015_CM1017" = HP Color LaserJet CM1015/CM1017 MFP 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"Office14.SingleImage" = Microsoft Office Professional 2010
"Speccy" = Speccy
"Unlocker" = Unlocker 1.9.0-x64
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{10964A8F-21C1-45EA-BC2D-F84B505C3848}" = H&R; Block Deluxe + Efile + State 2010
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{230B9098-A165-491F-B499-8F41AA7139F6}" = WorldWinner Games
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{281D28EC-1357-4778-B2D7-DEA56D70EF96}" = Logitech High Quality Video
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{33EFDAD7-1686-465A-AE0A-26F22E380315}" = Product_Min_QFolder
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39B975A6-93A3-4C71-9EAD-7BE9F9DF3D22}" = Product_Full_QFolder
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{41712893-452C-46E1-8530-584BBB790868}" = Google Apps Migration For Microsoft® Exchange 2.2.685.1005
"{477F4441-5BF5-4F1A-A4AA-358A66BAEB5A}" = hppFonts
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F0BC3F7-5583-48D1-8A08-ECD99EE14456}" = hpzTLBXFX
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57DA304D-27B0-40D1-A796-92CEFF20FA32}" = hppIOFiles
"{5BE17922-9A31-461F-9CEB-D053181A1E30}" = hppScanTo
"{5D112C61-C8D0-4718-8DD7-B9115EB9AF90}" = LogMeIn
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{6331C6C0-3754-E910-7113-5013355C8E47}" = CCC Help English
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{66A36166-A0A0-4AD2-AF46-29548DFA0EBF}" = hppCLJCM1017
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69B6B9E1-A5DF-3177-2B1D-3B672F29EF86}" = Adobe Captivate Quiz Results Analyzer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7B4174E8-FE92-4269-808A-3B8D116D9538}" = Advanced Security for Outlook
"{7D0C60CD-F5FF-4758-8A96-247D0DA74C52}" = Toodledo Sync Application
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8432FFD1-6F4D-F9B8-D641-5932E60359A2}" = Adobe Captivate Reviewer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8E355243-1A34-4EE8-A743-C166E68CF5C0}" = Adobe Captivate 5
"{91F34319-08DE-457a-99C0-0BCDFAC145B9}" = CuteFTP 8 Professional
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95C3927C-C899-C5D8-0EA7-67895FC979B2}" = ccc-core-static
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A99C1048-A569-4B65-A3DD-3584B0A4AA69}" = Microsoft MSN MoneyCentral Stock Quotes Add-In for Excel
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AE751709-EA28-4148-96D5-A524BBB08F05}" = hppusgCM1017
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0DE7025-6319-4FCD-8364-095B8774BC33}" = H&R; Block Georgia 2010
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C2F1F96A-057E-5819-B52E-FEA1D1D2933B}" = Acronis True Image Home
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6EC2466-7463-4C90-97D6-5077A223F0FE}" = hppTLBXFXCM1017
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Premium
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D710ECA1-820E-4EAD-9640-B2E3AD9E95CB}" = hppscanCM1017
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{ED4B50B7-C06B-57FE-7985-AA83DDBEEEF5}" = Catalyst Control Center Graphics Previews Common
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F01A9563-2A27-6ABC-2E04-03B7873DF7E0}" = Catalyst Control Center InstallProxy
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F8815B8B-3404-4B58-9FF3-46642E331FD8}" = hppManualsCM1017
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Accent OFFICE Password Recovery" = Accent OFFICE Password Recovery 2.60
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"AdobeCaptivateReviewer2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Reviewer
"AIM Ad Hack_is1" = AIM Ad Hack
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"AOL Instant Messenger" = AOL Instant Messenger
"Artisteer 2" = Artisteer 2
"AutoHotkey" = AutoHotkey 1.0.97.01
"AutoMacroRecorder_is1" = Auto Macro Recorder V5.7 (Pro V5.2) Trial Version
"Business Functions_is1" = Business Functions
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ESET Online Scanner" = ESET Online Scanner v3
"KeyScrambler" = KeyScrambler
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.7.0
"Mozilla Firefox 5.0 (x86 en-US)" = Mozilla Firefox 5.0 (x86 en-US)
"OpenAL" = OpenAL
"OpenRA" = OpenRA
"PDF Password Remover v2.2_is1" = PDF Password Remover v2.2
"QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Quiz Results Analyzer
"ReaJpeg 1.1" = ReaJpeg 1.1
"Spyware Doctor" = Spyware Doctor 8.0
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"UT2004" = Unreal Tournament 2004
"uTorrent" = µTorrent
"UZTool_is1" = UZTool 1.1.0
"vShare" = vShare Plugin
"Winamp" = Winamp (remove only)
"WinISO_is1" = WinISO 5.3
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"magicJack" = magicJack
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/1/2011 8:55:33 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 4/2/2011 4:29:43 PM | Computer Name = Desktop | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_stisvc, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7b325 Exception code: 0xc0000005 Fault offset: 0x000000000004ca16
Faulting
process id: 0x8e4 Faulting application start time: 0x01cbf1529da97696 Faulting application
path: C:\Windows\system32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: f0c37e4c-5d67-11e0-bb96-0024e821f2d0
Error - 4/2/2011 8:11:06 PM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 4/3/2011 12:12:10 PM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 304: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 308: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/3/2011 2:34:34 PM | Computer Name = Desktop | Source = Bonjour Service | ID = 100
Description = 440: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)
Error - 4/4/2011 8:07:35 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 4/5/2011 8:48:31 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 4/6/2011 7:59:53 AM | Computer Name = Desktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
[ System Events ]
Error - 7/5/2011 7:15:18 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 7/5/2011 7:15:18 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 7/5/2011 7:15:20 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 7/5/2011 11:41:49 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7034
Description = The hpqcxs08 service terminated unexpectedly. It has done this 1
time(s).
Error - 7/5/2011 11:41:49 AM | Computer Name = Desktop | Source = Service Control Manager | ID = 7034
Description = The HP CUE DeviceDiscovery Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 7/5/2011 12:07:39 PM | Computer Name = Desktop | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 7/5/2011 12:25:33 PM | Computer Name = Desktop | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.
Error - 7/5/2011 6:40:54 PM | Computer Name = Desktop | Source = BROWSER | ID = 8032
Description =
< End of report >