Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7586
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
27/08/2011 8:47:34 PM
mbam-log-2011-08-27 (20-47-34).txt
Scan type: Quick scan
Objects scanned: 173564
Time elapsed: 22 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 27/08/2011 8:55:49 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.89% Memory free
3.84 Gb Paging File | 3.05 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 127.80 Gb Free Space | 42.88% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 325.91 Gb Free Space | 69.97% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.69 Gb Free Space | 5.45% Space Free | Partition Type: NTFS
Drive H: | 3.78 Gb Total Space | 3.17 Gb Free Space | 83.85% Space Free | Partition Type: FAT32
Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/08/27 17:31:02 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2010/11/30 02:23:44 | 001,029,480 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe
PRC - [2010/11/30 02:23:44 | 000,406,888 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe
PRC - [2010/02/26 10:21:50 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccsvchst.exe
PRC - [2009/10/23 19:34:36 | 000,827,904 | —- | M] () – C:\Program Files\dvd43\DVD43_Tray.exe
PRC - [2009/10/11 07:07:08 | 000,320,832 | —- | M] (BillP Studios) – C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2008/04/14 22:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/06/13 04:20:00 | 000,127,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\DLA\DLACTRLW.EXE
========== Modules (No Company Name) ==========
MOD - [2010/02/06 04:27:45 | 001,291,776 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2009/10/23 19:34:36 | 000,827,904 | —- | M] () – C:\Program Files\dvd43\DVD43_Tray.exe
MOD - [2009/09/15 08:36:08 | 000,506,711 | —- | M] () – C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll
MOD - [2008/04/14 22:00:00 | 000,192,512 | —- | M] () – C:\WINDOWS\system32\qcap.dll
MOD - [2008/04/14 22:00:00 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2008/04/14 22:00:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/11/30 02:23:56 | 001,037,672 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe – (SpeedDiskService)
SRV - [2010/11/30 02:23:44 | 001,029,480 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe – (DiskDoctorService)
SRV - [2010/03/04 22:38:00 | 000,071,096 | —- | M] () [Disabled | Stopped] – C:\Program Files\CDBurnerXP\NMSAccessU.exe – (NMSAccess)
SRV - [2010/02/26 10:21:50 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ccSvcHst.exe – (NAV)
SRV - [2008/01/29 16:09:02 | 000,394,704 | —- | M] (Symantec, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe – (Symantec RemoteAssist)
SRV - [2002/12/17 16:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 16:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)
========== Driver Services (SafeList) ==========
DRV - [2011/08/23 00:17:32 | 000,356,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\IPSDefs\20110826.030\IDSXpx86.sys – (IDSxpx86)
DRV - [2011/08/04 12:46:24 | 001,576,312 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110826.025\NAVEX15.SYS – (NAVEX15)
DRV - [2011/08/04 12:46:23 | 000,086,136 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\VirusDefs\20110826.025\NAVENG.SYS – (NAVENG)
DRV - [2011/07/28 09:00:04 | 000,374,392 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2011/07/28 09:00:04 | 000,105,592 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2011/07/23 10:27:23 | 000,815,736 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\Definitions\BASHDefs\20110812.001\BHDrvx86.sys – (BHDrvx86)
DRV - [2010/11/30 02:24:00 | 000,108,800 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymSpeedDisk.sys – (SYMSpeedDisk)
DRV - [2010/11/30 02:23:58 | 000,128,248 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymDSMon.sys – (SymDSMon)
DRV - [2010/08/19 20:38:35 | 000,124,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2010/05/06 14:01:59 | 000,361,904 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SYMTDI.SYS – (SYMTDI)
DRV - [2010/04/29 15:03:51 | 000,116,784 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\Ironx86.SYS – (SymIRON)
DRV - [2010/04/22 13:02:20 | 000,173,104 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMEFA.SYS – (SymEFA)
DRV - [2010/04/22 12:29:50 | 000,325,680 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\NAV\1108000.005\SRTSP.SYS – (SRTSP)
DRV - [2010/04/22 12:29:50 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SRTSPX.SYS – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/26 10:22:57 | 000,501,888 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\ccHPx86.sys – (ccHP)
DRV - [2010/02/04 11:40:47 | 000,328,752 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\NAV\1108000.005\SYMDS.SYS – (SymDS)
DRV - [2009/11/12 13:48:56 | 000,007,168 | —- | M] () [File_System | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\StarOpen.sys – (StarOpen)
DRV - [2008/04/13 23:16:24 | 000,015,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MPE.sys – (MPE)
DRV - [2008/03/11 21:37:00 | 000,036,864 | R— | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/03/06 20:42:16 | 000,530,944 | R— | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2008/02/14 16:12:02 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\monfilt.sys – (monfilt)
DRV - [2008/02/14 13:36:34 | 000,222,976 | R— | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2007/04/26 06:42:18 | 000,045,696 | R— | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2006/06/13 04:20:00 | 000,094,460 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/06/13 04:20:00 | 000,088,476 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/06/13 04:20:00 | 000,086,844 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/06/13 04:20:00 | 000,025,724 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/06/13 04:20:00 | 000,014,716 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/06/13 04:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/06/13 04:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2006/03/17 07:35:24 | 000,005,660 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/03/17 07:34:46 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2004/08/13 20:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2002/07/17 08:05:10 | 000,016,512 | —- | M] (Adaptec) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aspi32.sys – (ASPI32)
DRV - [2002/07/17 08:05:10 | 000,016,512 | —- | M] (Adaptec) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\aspi32.sys – (ASPI)
DRV - [1999/05/21 00:00:00 | 000,015,488 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\ScFBPNT2.sys – (ScFBPNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.abc.net.au/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@csi.business.gov.au/CsiPlugin: C:\Program Files\Common-Use Signing Interface\bin\npCsiPlugin.dll (Commonwealth Government of Australia)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.6.0.32\IPSFFPlgn\ [2011/07/20 12:42:39 | 000,000,000 | —D | M]
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/04/26 19:02:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions\[removed]
[2010/04/02 16:02:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\[removed]
O1 HOSTS File: ([2011/05/28 15:41:59 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.8.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dvd43] C:\Program Files\dvd43\DVD43_Tray.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/08/27 17:30:54 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/08/27 12:24:52 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2011/08/24 20:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/08/24 13:10:03 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/08/21 10:19:16 | 000,000,000 | —D | C] – C:\Program Files\Audacity
[2011/08/20 07:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/04/15 10:10:31 | 021,460,432 | —- | C] (Symantec Corporation ) – C:\Program Files\15.0.0.122RC5_NUesd_MUI.exe
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/27 20:56:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/27 19:32:10 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/08/27 17:48:09 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/27 17:37:20 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/08/27 17:36:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/27 17:31:02 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2011/08/27 17:30:37 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2011/08/26 23:04:31 | 000,005,288 | —- | M] () – C:\Documents and Settings\User\Desktop\attach.zip
[2011/08/24 13:10:08 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\dds.scr
[2011/08/21 10:19:18 | 000,000,630 | —- | M] () – C:\Documents and Settings\User\Desktop\Audacity.lnk
[2011/08/19 11:04:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/14 23:02:42 | 000,000,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/13 05:34:17 | 000,000,426 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/08/12 20:08:35 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/11 20:02:50 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/08/11 13:52:13 | 000,480,116 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/11 13:52:13 | 000,086,298 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/11 13:45:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/06 18:52:38 | 010,104,807 | —- | M] () – C:\Documents and Settings\User\Desktop\Jacks Run.mp4
[2011/08/06 14:49:29 | 000,010,713 | —- | M] () – C:\Documents and Settings\User\Desktop\all.png
[2 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\User\Desktop\*.tmp files -> C:\Documents and Settings\User\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/26 23:04:31 | 000,005,288 | —- | C] () – C:\Documents and Settings\User\Desktop\attach.zip
[2011/08/21 10:19:17 | 000,000,636 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Audacity.lnk
[2011/08/21 10:19:17 | 000,000,630 | —- | C] () – C:\Documents and Settings\User\Desktop\Audacity.lnk
[2011/08/20 07:41:41 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/08/06 18:50:55 | 010,104,807 | —- | C] () – C:\Documents and Settings\User\Desktop\Jacks Run.mp4
[2011/08/06 14:50:21 | 000,010,713 | —- | C] () – C:\Documents and Settings\User\Desktop\all.png
[2011/06/22 11:17:36 | 000,078,820 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/05/02 16:37:25 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/04/15 10:16:07 | 000,036,712 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2010/10/15 10:11:16 | 000,001,940 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/10/15 10:06:11 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/26 23:32:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/23 13:04:52 | 000,000,146 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2010/05/23 13:04:52 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2010/05/23 13:04:33 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2010/05/23 13:04:32 | 000,009,853 | —- | C] () – C:\WINDOWS\HL-2170W.INI
[2010/05/23 13:04:28 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/05/23 13:04:28 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD2170W.DAT
[2010/05/23 13:03:37 | 000,000,318 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,303,104 | —- | C] () – C:\WINDOWS\emunist.exe
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/07/14 13:15:00 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,610 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:34:52 | 000,020,450 | —- | C] () – C:\WINDOWS\SICALIB2.DAT
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 19:19:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/04 10:50:07 | 000,000,323 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 23:50:47 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/01/19 23:49:51 | 000,331,480 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/19 20:22:52 | 000,115,200 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:08:54 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/01/19 14:05:27 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 22:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 22:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 22:00:00 | 000,480,116 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 22:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 22:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 22:00:00 | 000,086,298 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 22:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 22:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 22:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 22:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 22:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 22:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/02/09 13:46:30 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
========== LOP Check ==========
[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/05/18 09:57:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/09/21 12:31:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2010/04/14 12:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2011/07/21 19:40:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2010/11/09 15:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/08/11 13:02:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/09/27 10:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Socusoft
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2011/08/22 23:02:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/05/22 10:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2011/06/22 11:03:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2010/07/05 20:25:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\4Media
[2010/06/06 14:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Aura4You
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2011/05/02 16:37:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe Limited
[2011/04/06 18:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canon Easy-WebPrint EX
[2010/08/13 10:52:45 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CD-LabelPrint
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2010/07/28 16:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2011/05/02 16:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FrostWire
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2011/07/21 19:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\go
[2010/11/09 15:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MyHeritage
[2010/07/22 18:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2010/04/16 18:49:40 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Nvu
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/06/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2010/08/20 10:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tific
[2010/05/29 22:53:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2010/07/06 22:48:18 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Search
[2010/04/11 17:50:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinPatrol
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A96964
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96D0C06F
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D287FACF
OTL Extras logfile created on: 27/08/2011 8:55:49 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.89% Memory free
3.84 Gb Paging File | 3.05 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 127.80 Gb Free Space | 42.88% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 325.91 Gb Free Space | 69.97% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 12.69 Gb Free Space | 5.45% Space Free | Partition Type: NTFS
Drive H: | 3.78 Gb Total Space | 3.17 Gb Free Space | 83.85% Space Free | Partition Type: FAT32
Computer Name: OWNER-92DFBD76A | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1233:UDP" = 1233:UDP:*:Enabled:Windows Media Format SDK (svchost.exe)
"1232:UDP" = 1232:UDP:*:Enabled:Windows Media Format SDK (svchost.exe)
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Java\jre6\bin\rmiregistry.exe" = C:\Program Files\Java\jre6\bin\rmiregistry.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth – (Google)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{110E7958-3EE1-4684-9168-CD5D73A2CDDD}" = Mirar
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4700_series" = Canon iP4700 series Printer Driver
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic UDF Reader
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{251C3815-7A55-4607-A82D-C3B98F0FBAB8}" = Sony Vegas 7.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 26
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AE91C01-5906-11D5-A50C-006067797177}" = Cashflow Manager 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69352F8B-66AD-493C-9138-5FE0D300FB17}" = FIFA 09 Demo
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A41426-C7A4-4DCF-A9ED-C5B4B105ED1D}" = Sony Media Manager 2.2
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C897FCB3-2F8B-4185-8035-79E2AF3A92A4}" = iTunes
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DD1E824B-0A7E-4777-B684-D09330E85C7A}" = Brother HL-2170W
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FB3BE405-6BF0-490A-84B3-00611385EA0D}" = Common-Use Signing Interface
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4Media DVD Creator 6" = 4Media DVD Creator 6
"4Videosoft DVD to QuickTime Converter_is1" = 4Videosoft DVD to QuickTime Converter
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere 6.5" = Adobe Premiere 6.5
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"Audacity_is1" = Audacity 1.2.6
"Burn4Free CD & DVD_is1" = Burn4Free CD & DVD [removed]
"CanoCraft CS-P 3.7" = Canon CanoCraft CS-P 3.7
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Common-Use Signing Interface" = Common-Use Signing Interface
"Creative Mass Storage Drivers" = Creative Mass Storage Drivers
"DoremiSoft MPG to FLV Converter" = DoremiSoft MPG to FLV Converter 1.0
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD43_is1" = DVD43 v4.6.0
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"Ewisoft Website Builder (include eCommerce Builder)_is1" = Ewisoft Website Builder (include eCommerce Builder) Version 5
"Flash Slideshow Maker Pro" = Flash Slideshow Maker Pro 5.00
"Freecorder4.02" = Freecorder 4.02 Application
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MuVo Driver" = Creative Mass Storage Drivers
"NAV" = Norton AntiVirus
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Norton Utilities 15_is1" = Norton Utilities 15
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3
"SmartDraw VP" = SmartDraw VP
"SMPlayer" = SMPlayer 0.6.7
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"Speccy" = Speccy
"SpywareBlaster_is1" = SpywareBlaster 4.3
"SysInfo" = Creative System Information
"TVEpaDrv" = Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
"Ulead Photo Express 2.0 SE" = Ulead Photo Express 2.0 SE
"Ultra QuickTime Converter_is1" = Ultra QuickTime Converter 3.2.0104
"Uninstall_is1" = Uninstall 1.0.0.1
"VobSub" = VobSub v2.23 (Remove Only)
"WavePad" = WavePad Sound Editor
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinPatrol" = WinPatrol 2009
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Audio Maker" = Xilisoft Audio Maker
"Xvid_is1" = Xvid 1.2.2 final uninstall
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 21/08/2011 9:31:26 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 21/08/2011 3:38:09 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)
Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)
Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application
Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)
Error - 22/08/2011 8:53:14 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)
Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)
Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application
Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)
Error - 23/08/2011 8:09:44 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
[ Application Events ]
Error - 21/08/2011 9:31:26 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 21/08/2011 3:38:09 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)
Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)
Error - 21/08/2011 3:38:33 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application
Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)
Error - 22/08/2011 8:53:14 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3038
Description = The gatherer is unable to read the registry DocIdMapFile. Context:
Application, SystemIndex Catalog Details: The system cannot find the file specified.
(0x80070002)
Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3028
Description = The gatherer object cannot be initialized. Context: Windows Application,
SystemIndex Catalog Details: The registry value cannot be read because the configuration
is invalid. Recreate the content index configuration by removing the content index.
(0x80040d03)
Error - 22/08/2011 8:53:58 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3058
Description = The application cannot be initialized. Context: Windows Application
Details:
The
registry value cannot be read because the configuration is invalid. Recreate the
content index configuration by removing the content index. (0x80040d03)
Error - 23/08/2011 8:09:44 AM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application msimn.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 24/08/2011 6:03:05 PM | Computer Name = OWNER-92DFBD76A | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
[ System Events ]
Error - 26/08/2011 5:05:05 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NAV service.
Error - 26/08/2011 5:05:35 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NAV service.
Error - 26/08/2011 9:54:46 PM | Computer Name = OWNER-92DFBD76A | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022156E075E has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 26/08/2011 9:56:10 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 26/08/2011 9:56:10 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).
Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Creative Service for CDROM Access service terminated unexpectedly.
It has done this 1 time(s).
Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 27/08/2011 3:31:55 AM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7034
Description = The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly.
It has done this 1 time(s).
< End of report >
< End of report >