Since you guys seem to give very structured and persistent help I'll let the other forum know to lock my thread.
Here's my OTL text:
OTL logfile created on: 9/6/2011 6:23:54 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\CED
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.98 Gb Total Physical Memory | 5.38 Gb Available Physical Memory | 67.42% Memory free
15.95 Gb Paging File | 13.30 Gb Available in Paging File | 83.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 174.66 Gb Total Space | 76.26 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
Drive D: | 502.49 Gb Total Space | 474.31 Gb Free Space | 94.39% Space Free | Partition Type: NTFS
Drive E: | 3.69 Gb Total Space | 0.32 Gb Free Space | 8.63% Space Free | Partition Type: FAT32
Computer Name: CED-PC | User Name: CED | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\CED\OTL.exe (OldTimer Tools)
PRC - C:\Users\CED\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe ()
PRC - C:\32788R22FWJFW\cmd.3XE ()
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\ExpressGateUtil\VAWinService.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\32788R22FWJFW\NirCmd.3XE ()
========== Modules (No Company Name) ==========
MOD - C:\Users\CED\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe ()
MOD - C:\32788R22FWJFW\cmd.3XE ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\32788R22FWJFW\NirCmd.3XE ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:
64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:
64bit: - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AntiVirWebService) – C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH)
SRV - (AntiVirMailService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (postgresql-8.4) – C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (VideAceWindowsService) – C:\ExpressGateUtil\VAWinService.exe ()
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKGFNEXSrv) – C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (OpenVPNService) – C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe ()
========== Driver Services (SafeList) ==========
DRV:
64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:
64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:
64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:
64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (FLxHCIc) Fresco Logic xHCI (USB3) – C:\Windows\SysNative\drivers\FLxHCIc.sys (Fresco Logic)
DRV:
64bit: - (FLxHCIh) Fresco Logic xHCI (USB3) – C:\Windows\SysNative\drivers\FLxHCIh.sys (Fresco Logic)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (RSUSBVSTOR) – C:\Windows\SysNative\drivers\rtsuvstor.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:
64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:
64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:
64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:
64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:
64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:
64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:
64bit: - (btusbflt) – C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:
64bit: - (MBfilt) – C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV:
64bit: - (kbfiltr) – C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (SiSGbeLH) – C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:
64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:
64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:
64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (ATKWMIACPIIO) – C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) – C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..keyword.URL: "
http://www.bing.com/search?pc=Z128&form;=ZGAADF&install;_date=20110826&q;="
FF - prefs.js..network.proxy.type: 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/03/29 12:57:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/03/29 12:57:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/29 12:57:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/01 10:10:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/12 05:40:13 | 000,000,000 | —D | M]
[2011/04/29 13:36:55 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Extensions
[2011/09/06 01:05:22 | 000,000,000 | —D | M] (No name found) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions
[2011/08/26 08:35:12 | 000,000,000 | —D | M] (StartNow Toolbar) – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/08/26 08:35:11 | 000,001,945 | —- | M] () – C:\Users\CED\AppData\Roaming\Mozilla\Firefox\Profiles\fym3ytju.default\searchplugins\bing-zugo.xml
[2011/05/01 01:21:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/08/20 22:37:24 | 000,000,000 | —D | M] (Click to call with Skype) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/04/30 12:46:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/01 10:10:14 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/30 12:46:28 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/12 05:40:12 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
O1 HOSTS File: ([2011/09/06 01:07:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - File not found
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2:
64bit: - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - File not found
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [Setwallpaper] File not found
O4:
64bit: - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe (ASUS)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [FLxHCIm] C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe (Windows ® Win 7 DDK provider)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()
O4 - HKCU..\Run: [2871788205] File not found
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe (Bodog)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72F31F6A-2D75-42AB-8A76-E388E026FF71}: DhcpNameServer = 4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1FEAF45-691C-4469-9A87-192658CDEE2D}: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
O18:
64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - File not found
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/06 18:24:07 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\CED\aswMBR.exe
[2011/09/06 18:22:28 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Users\CED\OTL.exe
[2011/09/06 11:42:17 | 001,402,672 | —- | C] (Kaspersky Lab ZAO) – C:\Users\CED\tdsskiller.exe
[2011/09/06 11:41:54 | 001,402,672 | —- | C] (Kaspersky Lab ZAO) – C:\Users\CED\Desktop\tdsskiller.exe.part
[2011/09/06 11:04:31 | 000,607,260 | R— | C] (Swearware) – C:\Users\CED\Desktop\dds.scr
[2011/09/06 10:08:06 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/09/06 09:50:25 | 004,197,762 | R— | C] (Swearware) – C:\Users\CED\Desktop\ComboFix.exe
[2011/09/06 09:49:31 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\CED\Desktop\ATF_Cleaner.exe
[2011/09/06 09:10:28 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/09/06 09:10:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/06 09:09:53 | 009,466,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-setup-1.51.1.1800.exe
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\REPORTS
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\LOGFILES
[2011/09/06 09:09:20 | 000,000,000 | —D | C] – C:\ProgramData\INFECTED
[2011/09/06 09:00:31 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\CrashDumps
[2011/09/06 09:00:13 | 000,425,984 | —- | C] (Microsoft Corporation) – C:\Users\CED\AppData\Local\rip.exe
[2011/09/06 01:34:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect Uninstaller
[2011/09/06 01:34:55 | 000,000,000 | —D | C] – C:\Program Files\Perfect Uninstaller
[2011/09/06 01:34:11 | 003,485,888 | —- | C] (www.PerfectUninstaller.net ) – C:\Users\CED\Desktop\PerfectUninstaller_Setup.exe
[2011/09/06 01:22:40 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2011/09/06 01:22:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2011/09/06 01:11:29 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/09/06 01:07:36 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/09/06 00:59:27 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/09/06 00:59:27 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/09/06 00:59:27 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/09/06 00:59:23 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/09/06 00:59:21 | 000,000,000 | —D | C] – C:\Qoobox
[2011/09/06 00:49:02 | 004,197,303 | R— | C] (Swearware) – C:\Users\CED\Desktop\Combo-Fix.exe
[2011/09/06 00:14:25 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\ElevatedDiagnostics
[2011/09/06 00:04:05 | 052,390,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MRT.exe
[2011/09/06 00:03:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/09/05 23:55:22 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/09/05 23:43:10 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Runscanner.net
[2011/09/05 23:20:44 | 007,748,456 | —- | C] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-rules.exe
[2011/09/05 23:11:12 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Local\NPE
[2011/09/05 23:11:12 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/09/05 20:22:17 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011/08/26 08:35:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy MP3 Alarm Clock
[2011/08/26 08:35:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Easy MP3 Alarm Clock
[2011/08/24 21:34:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2011/08/21 13:51:20 | 000,000,000 | —D | C] – C:\Iperpokerclub
[2011/08/20 22:37:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/08/19 19:42:47 | 000,000,000 | —D | C] – C:\Poker4X
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bodog Hand Grabber
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bodog Hand Grabber
[2011/08/16 19:04:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bodog Hand Grabber
[2011/08/15 19:18:53 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microgaming
[2011/08/13 18:51:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\24 Poker
[2011/08/13 18:50:27 | 000,000,000 | —D | C] – C:\Poker
[2011/08/13 18:50:19 | 000,000,000 | —D | C] – C:\Microgaming
[2011/08/13 18:50:13 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CarbonPoker
[2011/08/13 18:50:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\CarbonPoker
[2011/08/12 10:02:05 | 000,000,000 | —D | C] – C:\Users\CED\AppData\Roaming\Roxio Log Files
[2011/08/10 08:48:54 | 000,000,000 | —D | C] – C:\Windows\SysNative\SPReview
[2011/08/10 00:13:28 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/08/10 00:13:26 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2011/08/10 00:13:26 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2011/08/10 00:13:25 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2011/08/10 00:13:25 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2011/08/10 00:13:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2011/08/10 00:13:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2011/08/10 00:13:25 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2011/08/10 00:13:25 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2011/08/10 00:13:25 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2011/08/10 00:13:18 | 001,162,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2011/08/10 00:13:18 | 000,421,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2011/08/10 00:13:18 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2011/08/10 00:13:18 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2011/08/10 00:13:18 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/08/10 00:13:18 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/08/10 00:13:18 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/08/10 00:13:18 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2011/08/10 00:13:18 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/08/10 00:13:18 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2011/08/10 00:13:17 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/10 00:13:17 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 00:13:17 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/10 00:13:17 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 00:13:16 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/08/10 00:13:16 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 00:13:16 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 00:13:16 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/10 00:13:16 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/08/10 00:13:00 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/08/10 00:12:58 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/08/10 00:12:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/08/10 00:12:58 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/08/10 00:12:58 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/08/10 00:12:58 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/08/10 00:12:58 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/08/10 00:12:54 | 003,912,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/08/10 00:12:53 | 005,561,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/08/10 00:12:53 | 003,967,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[1 C:\Users\CED\AppData\Local\*.tmp files -> C:\Users\CED\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/06 18:24:16 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\CED\aswMBR.exe
[2011/09/06 18:22:28 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Users\CED\OTL.exe
[2011/09/06 18:05:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/06 11:42:17 | 001,402,672 | —- | M] (Kaspersky Lab ZAO) – C:\Users\CED\tdsskiller.exe
[2011/09/06 11:41:57 | 001,402,672 | —- | M] (Kaspersky Lab ZAO) – C:\Users\CED\Desktop\tdsskiller.exe.part
[2011/09/06 11:36:10 | 000,004,588 | —- | M] () – C:\Users\CED\Desktop\Attach.zip
[2011/09/06 11:05:47 | 000,294,216 | —- | M] () – C:\Users\CED\Desktop\gmer.zip
[2011/09/06 11:04:31 | 000,607,260 | R— | M] (Swearware) – C:\Users\CED\Desktop\dds.scr
[2011/09/06 10:17:01 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 10:17:01 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 10:13:49 | 000,727,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/06 10:13:49 | 000,624,622 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/09/06 10:13:49 | 000,106,708 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/09/06 10:09:56 | 000,000,408 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/06 10:09:18 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/06 10:09:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/06 10:09:12 | 2129,526,783 | -HS- | M] () – C:\hiberfil.sys
[2011/09/06 09:50:25 | 004,197,762 | R— | M] (Swearware) – C:\Users\CED\Desktop\ComboFix.exe
[2011/09/06 09:49:54 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\CED\Desktop\ATF_Cleaner.exe
[2011/09/06 09:20:12 | 004,104,900 | —- | M] () – C:\Users\CED\Desktop\RootkitBuster_5.00.1041.zip
[2011/09/06 09:10:05 | 009,466,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-setup-1.51.1.1800.exe
[2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:21 | 000,000,988 | -HS- | M] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\wnkl.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\shbo.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\rplk.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\pycc.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\pbau.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\lhpw.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\jgnm.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | M] () – C:\ProgramData\huln.exe
[2011/09/06 09:00:13 | 000,425,984 | —- | M] (Microsoft Corporation) – C:\Users\CED\AppData\Local\rip.exe
[2011/09/06 01:34:58 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/09/06 01:34:11 | 003,485,888 | —- | M] (www.PerfectUninstaller.net ) – C:\Users\CED\Desktop\PerfectUninstaller_Setup.exe
[2011/09/06 01:22:29 | 002,086,240 | —- | M] () – C:\Users\CED\Desktop\SecurityTaskManager_Setup.exe
[2011/09/06 01:16:21 | 000,000,000 | —- | M] () – C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D}
[2011/09/06 01:07:29 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/09/06 00:58:59 | 004,197,303 | R— | M] (Swearware) – C:\Users\CED\Desktop\Combo-Fix.exe
[2011/09/05 23:45:36 | 000,230,767 | —- | M] () – C:\Users\CED\Desktop\runscanner.run
[2011/09/05 23:20:54 | 007,748,456 | —- | M] (Malwarebytes Corporation ) – C:\Users\CED\Desktop\mbam-rules.exe
[2011/09/05 23:20:38 | 000,035,229 | —- | M] () – C:\Users\CED\Desktop\3000-8022_4-10804572.html
[2011/09/05 20:25:27 | 001,803,670 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/09/05 20:21:14 | 000,512,992 | —- | M] () – C:\Users\CED\Desktop\sdsetup.exe
[2011/09/03 18:11:41 | 000,111,412 | —- | M] () – C:\Users\CED\Desktop\img0010cm.jpg
[2011/09/03 18:10:49 | 000,249,732 | —- | M] () – C:\Users\CED\Desktop\img0027v.jpg
[2011/09/01 10:10:20 | 000,002,050 | —- | M] () – C:\Users\CED\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/31 02:52:32 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/08/31 02:52:32 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/08/26 08:35:34 | 000,000,982 | —- | M] () – C:\Users\Public\Desktop\Easy MP3 Alarm Clock.lnk
[2011/08/25 18:13:29 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/08/21 13:51:45 | 000,001,492 | —- | M] () – C:\Users\CED\Desktop\Iperpokerclub.lnk
[2011/08/20 22:37:05 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/08/19 19:42:55 | 000,001,404 | —- | M] () – C:\Users\CED\Desktop\Poker4X.lnk
[2011/08/16 19:04:41 | 000,001,115 | —- | M] () – C:\Users\CED\Desktop\Bodog Hand Grabber.lnk
[2011/08/15 22:03:14 | 000,000,000 | —- | M] () – C:\Windows\HMHud.INI
[2011/08/14 20:29:38 | 000,000,114 | —- | M] () – C:\Windows\SysWow64\1744935990
[2011/08/13 18:51:17 | 000,000,895 | —- | M] () – C:\Users\Public\Desktop\24 Poker.lnk
[2011/08/13 18:50:30 | 000,000,695 | —- | M] () – C:\Users\CED\Desktop\Uncover.lnk
[2011/08/13 18:50:18 | 000,001,904 | —- | M] () – C:\Users\CED\Desktop\CarbonPoker.lnk
[2011/08/11 19:20:45 | 000,001,458 | —- | M] () – C:\Users\CED\Desktop\logs - Shortcut.lnk
[2011/08/11 17:46:28 | 1036,403,034 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/08/11 03:18:47 | 000,275,064 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/10 09:01:31 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msclmd.dll
[2011/08/10 09:01:30 | 000,175,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msclmd.dll
[1 C:\Users\CED\AppData\Local\*.tmp files -> C:\Users\CED\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/06 11:36:10 | 000,004,588 | —- | C] () – C:\Users\CED\Desktop\Attach.zip
[2011/09/06 11:05:38 | 000,294,216 | —- | C] () – C:\Users\CED\Desktop\gmer.zip
[2011/09/06 10:10:29 | 000,001,441 | —- | C] () – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/09/06 09:24:00 | 000,000,408 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/06 09:20:07 | 004,104,900 | —- | C] () – C:\Users\CED\Desktop\RootkitBuster_5.00.1041.zip
[2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\Users\CED\AppData\Local\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:21 | 000,000,988 | -HS- | C] () – C:\ProgramData\yu5jboqb8804xr78w5j35fawjm1if032n05240e676aa
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\wnkl.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\shbo.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\rplk.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\pycc.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\pbau.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\lhpw.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\jgnm.exe
[2011/09/06 09:00:20 | 000,000,000 | —- | C] () – C:\ProgramData\huln.exe
[2011/09/06 01:34:58 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\AK083E209605E394C.lie
[2011/09/06 01:22:29 | 002,086,240 | —- | C] () – C:\Users\CED\Desktop\SecurityTaskManager_Setup.exe
[2011/09/06 01:16:21 | 000,000,000 | —- | C] () – C:\Users\CED\AppData\Local\{8DD69FA3-6A02-4C59-B5F8-8C877F5EDC0D}
[2011/09/06 00:59:27 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/09/06 00:59:27 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/09/06 00:59:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/09/06 00:59:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/09/06 00:59:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/09/05 23:45:35 | 000,230,767 | —- | C] () – C:\Users\CED\Desktop\runscanner.run
[2011/09/05 23:20:37 | 000,035,229 | —- | C] () – C:\Users\CED\Desktop\3000-8022_4-10804572.html
[2011/09/05 20:24:59 | 001,803,670 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/09/05 20:22:17 | 000,512,992 | —- | C] () – C:\Users\CED\Desktop\sdsetup.exe
[2011/09/03 18:11:40 | 000,111,412 | —- | C] () – C:\Users\CED\Desktop\img0010cm.jpg
[2011/09/03 18:10:48 | 000,249,732 | —- | C] () – C:\Users\CED\Desktop\img0027v.jpg
[2011/08/26 08:35:34 | 000,000,982 | —- | C] () – C:\Users\Public\Desktop\Easy MP3 Alarm Clock.lnk
[2011/08/24 21:34:44 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2011/08/21 13:51:45 | 000,001,492 | —- | C] () – C:\Users\CED\Desktop\Iperpokerclub.lnk
[2011/08/19 19:42:55 | 000,001,404 | —- | C] () – C:\Users\CED\Desktop\Poker4X.lnk
[2011/08/16 19:04:41 | 000,001,115 | —- | C] () – C:\Users\CED\Desktop\Bodog Hand Grabber.lnk
[2011/08/15 22:03:14 | 000,000,000 | —- | C] () – C:\Windows\HMHud.INI
[2011/08/13 18:51:17 | 000,000,895 | —- | C] () – C:\Users\Public\Desktop\24 Poker.lnk
[2011/08/13 18:50:30 | 000,000,725 | —- | C] () – C:\Users\CED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uncover.lnk
[2011/08/13 18:50:30 | 000,000,695 | —- | C] () – C:\Users\CED\Desktop\Uncover.lnk
[2011/08/13 18:50:18 | 000,001,904 | —- | C] () – C:\Users\CED\Desktop\CarbonPoker.lnk
[2011/08/11 19:20:45 | 000,001,458 | —- | C] () – C:\Users\CED\Desktop\logs - Shortcut.lnk
[2011/06/27 19:07:11 | 000,233,472 | —- | C] () – C:\Windows\SysWow64\lame_enc.dll
[2011/06/18 19:27:43 | 000,008,704 | —- | C] () – C:\Users\CED\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/18 02:52:03 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/06/18 02:52:03 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/06/13 13:45:08 | 000,000,060 | —- | C] () – C:\ProgramData\422f8c46
[2011/06/13 02:23:50 | 000,007,605 | —- | C] () – C:\Users\CED\AppData\Local\Resmon.ResmonCfg
[2011/05/18 19:13:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/01 14:28:21 | 000,743,738 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/29 13:35:02 | 000,001,200 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/03/29 13:35:02 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/03/29 13:35:02 | 000,001,099 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/03/29 13:35:01 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/03/29 13:35:01 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/03/29 13:22:18 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009/10/25 22:38:22 | 000,000,176 | —- | C] () – C:\Windows\explorer.exe.config
[2009/07/29 00:20:40 | 000,000,010 | —- | C] () – C:\Windows\SysWow64\ABLKSR.ini
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/09/06 09:22:20 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\.purple
[2011/04/29 13:34:20 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Asus WebStorage
[2011/06/27 01:02:03 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Audacity
[2011/06/18 19:13:53 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\GrabPro
[2011/08/26 20:38:34 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\gtk-2.0
[2011/08/26 20:12:45 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\HEM Data
[2011/09/04 18:47:05 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Microgaming
[2011/06/18 19:13:49 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\OpenCandy
[2011/06/18 19:24:11 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Orbit
[2011/06/18 19:13:57 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\ProgSense
[2011/09/05 23:43:10 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\Runscanner.net
[2011/09/01 22:20:26 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\SoftGrid Client
[2011/04/30 13:59:12 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\SystemRequirementsLab
[2011/05/01 14:29:02 | 000,000,000 | —D | M] – C:\Users\CED\AppData\Roaming\TP
[2011/09/06 10:09:56 | 000,000,408 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/14 00:08:49 | 000,027,874 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 81 bytes -> C:\Program Files (x86)\Cake Poker 2.0:MID
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >
Here's my extras.txt:
OTL Extras logfile created on: 9/6/2011 6:23:55 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\CED
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.98 Gb Total Physical Memory | 5.38 Gb Available Physical Memory | 67.42% Memory free
15.95 Gb Paging File | 13.30 Gb Available in Paging File | 83.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 174.66 Gb Total Space | 76.26 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
Drive D: | 502.49 Gb Total Space | 474.31 Gb Free Space | 94.39% Space Free | Partition Type: NTFS
Drive E: | 3.69 Gb Total Space | 0.32 Gb Free Space | 8.63% Space Free | Partition Type: FAT32
Computer Name: CED-PC | User Name: CED | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
"{206BD2C5-DE08-4577-A0D7-D441A79D5A3A}" = Windows Live Remote Client Resources
"{289809B1-078A-49F3-83D0-7E51715B3915}" = Windows Live Family Safety
"{28D73032-5DAA-4F83-B154-85105DBCCB92}" = iTunes
"{3946328A-5B3A-434C-A22B-64CF6652FBAD}" = Windows Live Family Safety
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{401C50F6-B443-43EE-8F27-A80DB19B03FD}" = Windows Live Family Safety
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{45C1C61B-9DA9-4B61-8C89-C76B1746C3AA}" = Fresco Logic USB3.0 Host Controller
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{825C7D3F-D0B3-49D5-A42B-CBB0FBE85E99}" = Windows Live Remote Client Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{911519EB-BD75-4B3B-BD17-BA3747C9B854}" = Windows Live Family Safety
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AE91E0F3-C49A-4EF4-8B98-A07BD409EB90}" = Windows Live Remote Service Resources
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FAA3933C-6F0D-4350-B66B-9D7F7031343E}" = Windows Live Remote Service Resources
"{FE4BE0BD-1EDB-4D24-9614-847B3C472887}" = Windows Live Family Safety
"2AA10AB519DC7432D599A0E860206A7DDCC27764" = Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0)
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1" = Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405)
"7341A1B43E7FE58942EB1E820A17C18305DFBCE6" = Windows Driver Package - Broadcom Bluetooth (01/19/2010 6.2.0.1417)
"85CE3A3657FAE5FD305B143E90E6FC89BA53001C" = Windows Driver Package - Broadcom (BTHUSB) Bluetooth (02/25/2010 6.2.0.9419)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Perfect Uninstaller_is1" = Perfect Uninstaller v6.3.3.9
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000F2A10-9CDF-47BF-9CF2-9AC87567B433}" = Windows Live Photo Common
"{02EE09E7-958A-4E7F-80B6-8BA2D262BD04}" = ASUS AI Recovery
"{03241D8D-2217-42F7-9FCB-6A68D141C14D}" = Windows Live 软件包
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{09F56A49-A7B1-4AAB-95B9-D13094254AD1}" = Windows Live UX Platform Language Pack
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{21B49B4A-BBC3-4A09-9C68-6C3CC0B1EA01}" = Windows Live Messenger
"{23181592-0ECD-4A16-81C6-F0424D2DCABF}" = Windows Live UX Platform Language Pack
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29373E24-AC72-424E-8F2A-FB0F9436F21F}" = Windows Live Photo Common
"{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger
"{2C865FB0-051E-4D22-AC62-428E035AEAF0}" = Windows Live Mesh
"{317D56AC-0DB3-48F5-929A-42032DAC9AD7}" = Windows Live Writer
"{32C01DD0-3260-4D2B-BDB2-36CEC3E5B27A}" = Windows Live UX Platform Language Pack
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{341697D8-9923-445E-B42A-529E5A99CB7A}" = syncables desktop SE
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{3A09ED0F-8DDF-47BB-B53D-841AB9D1D3A7}" = Complemento Messenger
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{499DED08-6FA8-4749-8E94-8526CC9D1CA8}" = ExpressGate Cloud
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A275FD1-2F24-4274-8C01-813F5AD1A92D}" = Windows Live Messenger
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{588CE0C0-860B-49A8-AFCF-3C69465B345F}" = Windows Live Mesh
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{622DE1BE-9EDE-49D3-B349-29D64760342A}" = 適用遠端連線的 Windows Live Mesh ActiveX 控制項
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{63AE67AA-1AB1-4565-B4EF-ABBC5C841E8D}" = Windows Live Messenger
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6807427D-8D68-4D30-AF5B-0B38F8F948C8}" = Windows Live Writer Resources
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{685DEA21-3622-455A-A41B-89557A168DFD}" = Ad-Aware
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6CB36609-E3A6-446C-A3C1-C71E311D2B9C}" = Windows Live Movie Maker
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7115EEBC-DA7B-434C-B81C-EA5B26EA9A94}" = Windows Live Writer Resources
"{753F0A72-59C3-41CE-A36A-F2DF2079275C}" = Windows Live Mail
"{76046298-768C-492C-8C93-2983C9E3719E}" = Windows Live UX Platform Language Pack
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7B982EBD-D017-4527-BF1A-FC489EC6B100}" = Windows Live 照片库
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F061FA8-5A87-4758-876B-17EE28B358D0}" = Messenger 浏览器插件
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{903EDF14-4E28-4463-AA5E-4AEE71C0263B}" = Windows Live Movie Maker
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{939C80FA-96C9-44A6-B318-8E7D8BD8481B}" = Messenger Companion
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-00AF-0409-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0B91308-6666-4249-8FF6-1E11AFD75FE1}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B11AB9C8-18A6-41DC-98B4-4988CC030136}" = THX TruStudio
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF088261-BC81-4FB9-9BA0-7B5B9602D01A}" = Messenger 分享元件
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
"{E62E0550-C098-43A2-B54B-03FB1E634483}" = Windows Live Writer
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{ED86C4AB-D1E5-42CF-BFA3-56BAAE617D4E}" = Windows Live UX Platform Language Pack
"{EEF99142-3357-402C-B298-DEC303E12D92}" = Windows Live 影像中心
"{EF7EAB13-46FC-49DD-8E3C-AAF8A286C5BB}" = Windows Live 程式集
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F992409C-9D10-4AE2-BAEB-B5409AD3785E}" = 用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文)
"{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"5F4EE0CB-CAB9-426E-B314-F3F7B5C79BC2" = Iperpokerclub
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ares" = Ares 2.1.7
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage
"Asus_G73_Screensaver" = Asus_G73_Screensaver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira AntiVir Premium
"Bodog Hand Grabber" = Bodog Hand Grabber 1.17
"Bodog Poker_is1" = Bodog Poker
"C36BCFC5-25CB-4677-8451-3D9B7E4EFE0C" = Poker4X
"Cake Poker 2.0" = Cake Poker 2.0
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HoldemManager" = Holdem Manager
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{499DED08-6FA8-4749-8E94-8526CC9D1CA8}" = ExpressGate Cloud
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Mozilla Firefox 6.0.1 (x86 en-US)" = Mozilla Firefox 6.0.1 (x86 en-US)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"OpenVPN" = OpenVPN 2.1_rc15
"Pidgin" = Pidgin
"PokerStars" = PokerStars
"PostgreSQL 8.4" = PostgreSQL 8.4
"Security Task Manager" = Security Task Manager 1.8d
"StartNow Toolbar" = StartNow Toolbar
"SystemRequirementsLab" = System Requirements Lab
"Winamp" = Winamp (remove only)
"WinLiveSuite" = Windows Live Essentials
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CarbonPoker" = CarbonPoker
"Sportsbook.com" = Sportsbook.com
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/6/2011 4:20:42 AM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error - 9/6/2011 10:00:28 AM | Computer Name = CED-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Update.exe_Microsoft® Windows® Operating
System, version: 6.1.7601.17514, time stamp: 0x4ce78ecc Faulting module name: ntdll.dll,
version: 6.1.7601.17514, time stamp: 0x4ce7ba58 Exception code: 0xc0000374 Fault
offset: 0x000ce653 Faulting process id: 0x1dc0 Faulting application start time: 0x01cc6c9d4d9bb7dd
Faulting
application path: C:\windows\syswow64\sysprep\Update.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report
Id: 92efa996-d890-11e0-93e2-74f06dc60eba
Error - 9/6/2011 10:04:41 AM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\CED\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error - 9/6/2011 10:23:38 AM | Computer Name = CED-PC | Source = Avira AntiVir | ID = 4112
Description = An error occurred during a resource request to the Windows NT system.
The resource has not been allocated. This could be due to an out-of-memory
error or any other system failure. Returned error code: 0x424
Error - 9/6/2011 10:23:39 AM | Computer Name = CED-PC | Source = PostgreSQL | ID = 0
Description = 2011-09-06 09:23:39 CDTFATAL: the database system is starting up
Error - 9/6/2011 11:09:20 AM | Computer Name = CED-PC | Source = Avira AntiVir | ID = 4112
Description = An error occurred during a resource request to the Windows NT system.
The resource has not been allocated. This could be due to an out-of-memory
error or any other system failure. Returned error code: 0x424
Error - 9/6/2011 11:09:22 AM | Computer Name = CED-PC | Source = PostgreSQL | ID = 0
Description = 2011-09-06 10:09:22 CDTFATAL: the database system is starting up
Error - 9/6/2011 11:11:59 AM | Computer Name = CED-PC | Source = MBAMService | ID = 131073
Description =
Error - 9/6/2011 11:11:59 AM | Computer Name = CED-PC | Source = MBAMService | ID = 131073
Description =
Error - 9/6/2011 7:22:49 PM | Computer Name = CED-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\CED\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
[ System Events ]
Error - 9/3/2011 1:16:13 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:14 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:15 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:16 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:17 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:18 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:19 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/3/2011 1:16:20 PM | Computer Name = CED-PC | Source = cdrom | ID = 262159
Description = The device, \Device\CdRom0, is not ready for access yet.
Error - 9/4/2011 12:02:39 PM | Computer Name = CED-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:45:33 AM on ?9/?4/?2011 was unexpected.
Error - 9/4/2011 7:42:42 PM | Computer Name = CED-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{13512C70-9DF7-49A1-BDF7-6E10E0F66A14}
because another computer on the network has the same name. The server could not
start.
< End of report >