rgmiller
Topic Starter
I've been experiencing a lot of redirect warnings in Firefox. iexplore.exe is always running in the background. I can terminate the process, but something else just starts it up again. TDSSKiller will not run and I've just recently learned that I can no longer even reboot in safe mode.
Malwarebytes' Anti-Malware found a four issues and supposedly cleaned them:
Adware.DoubleD.Gen File
Malware.Trace File
Rogue.AntivirusSuite Registry Key
Trojan.Fraudpack Registry Key
Problems still persist, however. Any assistance would be greatly appreciated.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:42:12 PM, on 28/09/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32brsvc01a.exe
C:WINDOWSsystem32brss01a.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesSUPERAntiSpywareSASCORE.EXE
C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32FsUsbExService.Exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
c:Program FilesMicrosoft SQL Server90Sharedsqlwriter.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSsystem32SearchIndexer.exe
C:Program FilesTortoiseSVNbinTSVNCache.exe
C:WINDOWSCTHELPER.EXE
C:Program FilesCyberLinkPowerDVDDVDLauncher.exe
C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE
C:Program FilesCreativeShared FilesModule LoaderDLLML.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:WINDOWSSYSTEM32CTXFISPI.EXE
C:Program FilesMicrosoft Security Clientmsseces.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesPeerBlockpeerblock.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSsystem32taskmgr.exe
C:Program FilesiPodbiniPodService.exe
c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32notepad.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Program FilesTrend MicroHijackThisHiJackThis.exe
C:Documents and SettingsrlevereDesktopOTL.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.ca/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: CmjBrowserHelperObject Object - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:Program FilesMicrosoft Visual Studio 10.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderB
arBHO100.dll
O2 - BHO: Microsoft Web Test Recorder 9.0 Helper - {E31CE47F-C268-41ba-897B-B415E613947D} - C:Program FilesMicrosoft Visual Studio 9.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderBa
rBHO90.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM..Run: [DVDLauncher] "C:Program FilesCyberLinkPowerDVDDVDLauncher.exe"
O4 - HKLM..Run: [CTDVDDET] "C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE"
O4 - HKLM..Run: [VolPanel] "C:Program FilesCreativeSound Blaster X-FiVolume PanelVolPanel.exe" /r
O4 - HKLM..Run: [AudioDrvEmulator] "C:Program FilesCreativeShared FilesModule LoaderDLLML.exe" -1 AudioDrvEmulator "C:Program FilesCreativeShared FilesModule LoaderAudio EmulatorAudDrvEm.dll"
O4 - HKLM..Run: [ISUSPM Startup] "C:Program FilesCommon FilesInstallShieldUpdateServiceisuspm.exe" -startup
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [SignIn] "C:Program FilesMicrosoft Online ServicesSign InSignIn.exe" /autorun
O4 - HKLM..Run: [Communicator] "C:Program FilesMicrosoft Office Communicatorcommunicator.exe" /fromrunkey
O4 - HKLM..Run: [SetDefPrt] C:Program FilesBrotherBrmfl04aBrStDvPt.exe
O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe /autorun
O4 - HKLM..Run: [MSC] "c:Program FilesMicrosoft Security Clientmsseces.exe" -hide -runkey
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKCU..Run: [updateMgr] "C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [PeerBlock] C:Program FilesPeerBlockpeerblock.exe
O4 - HKCU..Run: [Google Update] "C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
O4 - HKUSS-1-5-18..RunOnce: [tscuninstall] %systemroot%system32tscupgrd.exe (User 'SYSTEM')
O4 - HKUS.DEFAULT..RunOnce: [tscuninstall] %systemroot%system32tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~4Office12EXCEL.EXE/3000
O8 - Extra context menu item: Edit with &XML; Spy - C:Program FilesAltovaxmlspyspy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~4Office12REFIEBAR.DLL
O9 - Extra button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSsystem32Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:Program FilesAltovaxmlspyspy.htm (HKCU)
O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:Program FilesAltovaxmlspyspy.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-30.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139683133703
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139683125296
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://pix.futureshop.ca/en/ImageUploader4.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.ca/downloads/BUM/B…_2/axofupld.cab
O16 - DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} (TWDownloader Class) - https://cpc.postecs.com/download/TWDownload.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} (ULcontrol Control) - https://pix.futureshop.ca/en/ulcontrolxp.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSoftware..Telephony: DomainName = fedgrid.local
O17 - HKLMSystemCS1ServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSystemCS3ServicesTcpipParameters: Domain = fedgrid.local
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O20 - Winlogon Notify: !SASWinLogon - C:Program FilesSUPERAntiSpywareSASWINLO.DLL
O20 - Winlogon Notify: GoToAssist - C:Program FilesCitrixGoToAssist516G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWSsystem32browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWSsystem32browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:Program FilesSUPERAntiSpywareSASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: ANTS Memory Profiler 5 Service - Red Gate Software Ltd. - C:Program FilesRed GateANTS Memory Profiler 5RedGate.Memory.IISService.exe
O23 - Service: ANTS Performance Profiler 5 Service - Red Gate Software Ltd. - C:Program FilesRed GateANTS Performance Profiler 5RedGate.Profiler.IISService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:WINDOWSsystem32Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:WINDOWSsystem32brsvc01a.exe
O23 - Service: FLEXlm License Manager - Unknown owner - C:Program FilesCommon FilesAlias Sharedlicensingetclmgrd.exe (file missing)
O23 - Service: FsUsbExService - Teruten - C:WINDOWSsystem32FsUsbExService.Exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:Program FilesCitrixGoToAssist516g2aservice.exe
O23 - Service: Groove Audit Service (GrooveAuditService) - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveAuditService.exe
O23 - Service: Groove Installer Service (GrooveInstallerService) - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveInstallerService.exe
O23 - Service: GrooveRunOnceInstaller - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveRunOnceInstaller.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:Program FilesLavasoftAd-AwareAAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: Tryst Lobby Service - Unknown owner - C:Documents and SettingsrlevereMy DocumentsVisual Studio 2005ProjectsTrystServerTrystLobbyServicebinDebugTrystLobbyService.exe
–
End of file - 14152 bytes
Ran OTL, as well. There's an awful lot of entries in the hosts file that shouldn't be there…
Here's OTL.txt (Extras.txt to follow):
OTL logfile created on: 28/09/2011 2:31:38 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:Documents and SettingsrlevereDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.23% Memory free
3.84 Gb Paging File | 2.76 Gb Available in Paging File | 71.82% Paging File free
Paging file location(s): c:pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.78 Gb Total Space | 60.11 Gb Free Space | 25.82% Space Free | Partition Type: NTFS
Computer Name: NEBULA | User Name: rlevere | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:Documents and SettingsrlevereDesktopOTL.exe (OldTimer Tools)
PRC - C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)
PRC - C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:Program FilesSUPERAntiSpywareSASCore.exe (SUPERAntiSpyware.com)
PRC - C:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
PRC - c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe (Microsoft Corporation)
PRC - C:Program FilesPeerBlockpeerblock.exe (PeerBlock, LLC)
PRC - C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
PRC - C:Program FilesTortoiseSVNbinTSVNCache.exe (http://tortoisesvn.net)
PRC - C:Program FilesTrend MicroHijackThisHiJackThis.exe (Trend Micro Inc.)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
PRC - C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe (Symantec Corporation)
PRC - C:WINDOWSsystem32CTXFISPI.EXE (Creative Technology Ltd)
PRC - C:WINDOWSCTHELPER.EXE (Creative Technology Ltd)
PRC - C:Program FilesCreativeShared FilesModule LoaderDLLML.exe (Creative Technology Ltd.)
PRC - C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10007.dll ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10006.dll ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSUIREPAIR.DLL ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10005.dll ()
MOD - C:Program FilesMozilla Firefoxmozjs.dll ()
MOD - C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll ()
MOD - C:WINDOWSsystem32quartz.dll ()
MOD - C:WINDOWSsystem32msdmo.dll ()
MOD - C:WINDOWSsystem32devenum.dll ()
MOD - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
MOD - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcnet.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (FLEXlm License Manager) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:Program FilesLavasoftAd-AwareAAWService.exe (Lavasoft Limited)
SRV - (!SASCORE) – C:Program FilesSUPERAntiSpywareSASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MsMpSvc) – c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe (Microsoft Corporation)
SRV - (FsUsbExService) – C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
SRV - (ANTS Performance Profiler 5 Service) – C:Program FilesRed GateANTS Performance Profiler 5RedGate.Profiler.IISService.exe (Red Gate Software Ltd.)
SRV - (ANTS Memory Profiler 5 Service) – C:Program FilesRed GateANTS Memory Profiler 5RedGate.Memory.IISService.exe (Red Gate Software Ltd.)
SRV - (msvsmon90) – C:Program FilesMicrosoft Visual Studio 9.0Common7IDERemote Debuggerx86msvsmon.exe (Microsoft Corporation)
SRV - (Tryst Lobby Service) – C:Documents and SettingsrlevereMy DocumentsVisual Studio 2005ProjectsTrystServerTrystLobbyServicebinDebugTrystLobbyService.exe ()
SRV - (GoToAssist) – C:Program FilesCitrixGoToAssist516g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Symantec Core LC) – C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe (Symantec Corporation)
SRV - (msvsmon80) – C:Program FilesMicrosoft Visual Studio 8Common7IDERemote Debuggerx86msvsmon.exe (Microsoft Corporation)
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe (Symantec Corporation)
SRV - (GrooveInstallerService) – C:Program FilesGroove NetworksGrooveBinGrooveInstallerService.exe (Groove Networks, Inc.)
SRV - (GrooveRunOnceInstaller) – C:Program FilesGroove NetworksGrooveBinGrooveRunOnceInstaller.exe (Groove Networks, Inc.)
SRV - (GrooveAuditService) – C:Program FilesGroove NetworksGrooveBinGrooveAuditService.exe (Groove Networks, Inc.)
SRV - (brmfrmps) – C:WINDOWSSystem32Brmfrmps.exe (Brother Industries, Ltd.)
========== Driver Services (SafeList) ==========
DRV - (MpKslae183b29) – c:Documents and SettingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{93AA71BB-DCFF-4AA3-88F8-87AD97F1BBE2}MpKslae183b29.sys (Microsoft Corporation)
DRV - (MpKsl6a050b33) – c:Documents and SettingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{93AA71BB-DCFF-4AA3-88F8-87AD97F1BBE2}MpKsl6a050b33.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:Program FilesSUPERAntiSpywaresasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:Program FilesSUPERAntiSpywareSASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:WINDOWSsystem32DRIVERSLbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:Program FilesLavasoftAd-Awarekernexplorer.sys ()
DRV - (VSPerfDrv100) – C:Program FilesMicrosoft Visual Studio 10.0Team ToolsPerformance ToolsVSPerfDrv100.sys (Microsoft Corporation)
DRV - (pbfilter) – C:Program FilesPeerBlockpbfilter.sys ()
DRV - (StarOpen) – C:WINDOWSSystem32driversStarOpen.sys ()
DRV - (FsUsbExDisk) – C:WINDOWSsystem32FsUsbExDisk.Sys ()
DRV - (ss_mdm) – C:WINDOWSsystem32driversss_mdm.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) – C:WINDOWSsystem32driversss_bus.sys (MCCI Corporation)
DRV - (ss_mdfl) – C:WINDOWSsystem32driversss_mdfl.sys (MCCI Corporation)
DRV - (RsFx0103) – C:WINDOWSsystem32driversRsFx0103.sys (Microsoft Corporation)
DRV - (VSPerfDrv90) – C:Program FilesMicrosoft Visual Studio 9.0Team ToolsPerformance ToolsVSPerfDrv90.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (DITOUSB) – C:WINDOWSsystem32driversDITOUSB.sys (Nintendo Co.,Ltd.)
DRV - (EXITOUSB) – C:WINDOWSsystem32driversEXITOUSB.sys (Nintendo Co., Ltd.)
DRV - (dtscsi) – C:WINDOWSSystem32Driversdtscsi.sys (DT Soft Ltd.)
DRV - (sptd) – C:WINDOWSSystem32Driverssptd.sys (Duplex Secure Ltd.)
DRV - (symlcbrd) – C:WINDOWSsystem32driverssymlcbrd.sys (Symantec Corporation)
DRV - (ASCTRM) – C:WINDOWSSystem32driversasctrm.sys (Windows ® 2000 DDK provider)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:WINDOWSsystem32driversctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:WINDOWSsystem32driversctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – C:WINDOWSsystem32driversha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:WINDOWSsystem32driversctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:WINDOWSsystem32driversctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:WINDOWSsystem32driversemupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:WINDOWSsystem32driversctac32k.sys (Creative Technology Ltd)
DRV - (nvnetbus) – C:WINDOWSsystem32driversnvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:WINDOWSsystem32driversNVENETFD.sys (NVIDIA Corporation)
DRV - (nvatabus) – C:WINDOWSsystem32driversnvatabus.sys (NVIDIA Corporation)
DRV - (ctdvda2k) – C:WINDOWSsystem32driversctdvda2k.sys (Creative Technology Ltd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = %SystemRoot%system32blank.htm
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar =
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page =
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.ca/
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.type: 0
FF - [removed]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/DivX Browser Plugin,version=1.0.0: C:Program FilesDivXDivX Web Playernpdivx32.dll (DivX,Inc.)
FF - [removed]/DivX Player Plugin,version=1.0.0: C:Program FilesDivXDivX PlayernpDivxPlayerPlugin.dll (DivX, Inc)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.0.60401.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/wpi,version=1.0: C:Program FilesMicrosoftWeb Platform Installernpwpidetector.dll ()
FF - [removed]/VMP: C:Program FilesViewpointViewpoint Experience TechnologynpViewpoint.dll ()
FF - [removed]/Google Update;version=3: C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 7.0extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/09/28 08:06:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 7.0extensionsPlugins: C:Program FilesMozilla Firefoxplugins
[2010/06/30 11:34:44 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsrlevereApplication DataMozillaExtensions
[2011/03/22 09:31:03 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsrlevereApplication DataMozillaFirefoxProfilesrwoyinyc.defaultextensions
[2010/07/02 08:27:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:Documents and SettingsrlevereApplication DataMozillaFirefoxProfilesrwoyinyc.defaultextensions{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/28 11:27:55 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2011/09/28 08:05:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2011/06/22 07:59:34 | 000,002,252 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsbing.xml
O1 HOSTS File: ([2010/06/29 16:16:49 | 000,408,553 | R— | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14129 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (CmjBrowserHelperObject Object) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll (Mindjet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll (Groove Networks, Inc.)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:Program FilesMicrosoft Visual Studio 10.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderB
arBHO100.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Web Test Recorder 9.0 Helper) - {E31CE47F-C268-41ba-897B-B415E613947D} - C:Program FilesMicrosoft Visual Studio 9.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderBa
rBHO90.dll (Microsoft Corporation)
O2 - BHO: (BhoMisc Class) - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O3 - HKLM..Toolbar: (TrendProtect) - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O3 - HKCU..ToolbarWebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU..ToolbarWebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..Run: [AudioDrvEmulator] C:Program FilesCreativeShared FilesModule LoaderDLLML.exe (Creative Technology Ltd.)
O4 - HKLM..Run: [Communicator] C:Program FilesMicrosoft Office Communicatorcommunicator.exe (Microsoft Corporation)
O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..Run: [CTDVDDET] C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [CTHelper] C:WINDOWSCTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [CTxfiHlp] C:WINDOWSSystem32CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [DAEMON Tools] C:Program FilesDAEMON Toolsdaemon.exe (DT Soft Ltd.)
O4 - HKLM..Run: [MSC] c:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..Run: [NPSStartup] File not found
O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..Run: [SetDefPrt] C:Program FilesBrotherBrmfl04aBrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..Run: [SignIn] C:Program FilesMicrosoft Online ServicesSign InSignIn.exe (Microsoft Corporation)
O4 - HKLM..Run: [Symantec PIF AlertEng] C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe (Symantec Corporation)
O4 - HKLM..Run: [VolPanel] C:Program FilesCreativeSound Blaster X-FiVolume PanelVolPanel.exe (Creative Technology Ltd)
O4 - HKCU..Run: [PeerBlock] C:Program FilesPeerBlockpeerblock.exe (PeerBlock, LLC)
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..Run: [updateMgr] C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe (Adobe Systems Incorporated)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O7 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRecovery present
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = -1
O8 - Extra context menu item: Edit with &XML; Spy - C:Program FilesAltovaxmlspyspy.htm ()
O9 - Extra Button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll (Mindjet)
O10 - NameSpace_Catalog5Catalog_Entries\000000000004 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O15 - HKLM..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU..Trusted Domains: livemeeting.com ([]https in Internet)
O15 - HKCU..Trusted Domains: microsoftonline.com ([]https in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB (TmHcmsX Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-30.cab (EPUImageControl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1139683133703 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1139683125296 (MUWebControl Class)
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} http://pix.futureshop.ca/en/ImageUploader4.cab (Image Uploader Control)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.ca/downloads/BUM/B…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} https://cpc.postecs.com/download/TWDownload.cab (TWDownloader Class)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab (DLC Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} https://pix.futureshop.ca/en/ulcontrolxp.cab (ULcontrol Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.20 192.168.1.50
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{1D7F33C9-9706-4280-9FBB-16D5D2D6A1D5}: DhcpNameServer = 192.168.1.20 192.168.1.50
O18 - ProtocolHandlertrendprotect {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) -C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - WinlogonNotify!SASWinLogon: DllName - (C:Program FilesSUPERAntiSpywareSASWINLO.DLL) - C:Program FilesSUPERAntiSpywareSASWINLO.DLL (SUPERAntiSpyware.com)
O20 - WinlogonNotifyGoToAssist: DllName - (C:Program FilesCitrixGoToAssist516G2AWinLogon.dll) - C:Program FilesCitrixGoToAssist516g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:Documents and SettingsrlevereLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsrlevereLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:Program FilesWindows Desktop SearchMSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:Program FilesSUPERAntiSpywareSASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll (Groove Networks, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/12 08:19:23 | 000,000,000 | —D | M] - C:Autodesk – [ NTFS ]
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | —- | M] () - C:AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}Shell - "" = AutoRun
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}ShellAutoRun - "" = Auto&Play;
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}ShellAutoRuncommand - "" = G:LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:WINDOWSSystem32ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:WINDOWSsystem32iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:WINDOWSSystem32lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:WINDOWSSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:WINDOWSSystem32ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:WINDOWSSystem32frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv41 - C:WINDOWSSystem32ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:WINDOWSSystem32ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:WINDOWSSystem32xvidvfw.dll ()
Drivers32: vidc.yv12 - C:WINDOWSSystem32yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/28 14:29:10 | 000,582,656 | —- | C] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 11:07:58 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataSUPERAntiSpyware.com
[2011/09/28 11:07:26 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsSUPERAntiSpyware
[2011/09/28 11:07:21 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.com
[2011/09/28 11:07:21 | 000,000,000 | —D | C] – C:Program FilesSUPERAntiSpyware
[2011/09/28 11:06:06 | 012,609,096 | —- | C] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
[2011/09/28 11:00:54 | 001,548,080 | —- | C] (Kaspersky Lab ZAO) – C:Documents and SettingsrlevereDesktoprkill2.scr
[2011/09/28 10:11:53 | 000,000,000 | —D | C] – C:rsit
[2011/09/28 09:23:21 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereStart MenuProgramsCleanUp!
[2011/09/28 09:23:13 | 000,000,000 | —D | C] – C:Program FilesCleanUp!
[2011/09/23 14:32:12 | 000,000,000 | —D | C] – C:CartBlanche-MonoGame-Samples-9f88fbf
[2011/09/23 10:24:29 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereLocal SettingsApplication DataXamarin
[2011/09/23 10:23:40 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereMy DocumentsProjects
[2011/09/23 09:53:22 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication Datastetic
[2011/09/23 09:52:49 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataMonoDevelop-2.6
[2011/09/23 09:52:37 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereLocal SettingsApplication DataMonoDevelop-2.6
[2011/09/23 09:52:31 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataMonoDevelop
[2011/09/22 14:56:29 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereStart MenuProgramsMonoDevelop
[2011/09/22 14:56:19 | 000,000,000 | —D | C] – C:Program FilesMonoDevelop
[2011/09/22 14:54:05 | 000,000,000 | —D | C] – C:Program FilesGtkSharp
[2011/09/22 13:10:32 | 000,000,000 | —D | C] – C:Documents and Settingsrlevere.android
[2011/09/22 13:10:20 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsAndroid SDK Tools
[2011/09/22 13:10:12 | 000,000,000 | —D | C] – C:Android
[2011/09/12 09:04:01 | 000,139,656 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcacherdpwd.sys
[2011/09/12 08:47:52 | 000,010,496 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachendistapi.sys
[2011/09/03 03:17:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachecrypt32.dll
[2006/03/07 16:50:52 | 000,380,928 | —- | C] ( ) – C:WINDOWSSystem32csgl.dll
[2006/02/01 01:50:04 | 000,033,792 | —- | C] ( ) – C:WINDOWSSystem32a3d.dll
[2006/02/01 01:50:04 | 000,009,216 | —- | C] ( ) – C:WINDOWSSystem32KILLAPPS.EXE
[55 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/28 14:37:35 | 000,002,451 | —- | M] () – C:Documents and SettingsrlevereDesktopHiJackThis.lnk
[2011/09/28 14:29:20 | 000,582,656 | —- | M] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 14:00:04 | 000,000,986 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-2509836690-573628217-1654637295-1006UA.job
[2011/09/28 13:38:38 | 000,000,424 | -H– | M] () – C:WINDOWStasksMP Scheduled Scan.job
[2011/09/28 12:52:30 | 000,029,204 | —- | M] () – C:WINDOWSSystem32nvapps.xml
[2011/09/28 12:52:24 | 000,013,668 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2011/09/28 12:51:24 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2011/09/28 12:51:21 | 2144,899,072 | -HS- | M] () – C:hiberfil.sys
[2011/09/28 12:48:06 | 000,064,988 | —- | M] () – C:WINDOWSSystem32DVCState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,054,672 | —- | M] () – C:WINDOWSSystem32BMXStateBkp-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,054,672 | —- | M] () – C:WINDOWSSystem32BMXState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,001,080 | —- | M] () – C:WINDOWSSystem32settingsbkup.sfm
[2011/09/28 12:48:06 | 000,001,080 | —- | M] () – C:WINDOWSSystem32settings.sfm
[2011/09/28 12:44:59 | 000,000,064 | —- | M] () – C:WINDOWSSystem32rp_stats.dat
[2011/09/28 12:44:59 | 000,000,044 | —- | M] () – C:WINDOWSSystem32rp_rules.dat
[2011/09/28 12:44:07 | 000,000,472 | —- | M] () – C:WINDOWStasksAd-Aware Update (Weekly).job
[2011/09/28 12:43:17 | 000,026,112 | —- | M] (Microsoft Corporation) – C:WINDOWSSystem32userinit.exe
[2011/09/28 11:56:59 | 000,000,815 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk
[2011/09/28 11:07:26 | 000,001,678 | —- | M] () – C:Documents and SettingsAll UsersDesktopSUPERAntiSpyware Free Edition.lnk
[2011/09/28 11:06:47 | 012,609,096 | —- | M] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
[2011/09/28 11:03:50 | 000,000,335 | —- | M] () – C:Documents and SettingsrlevereDesktopFixExe.reg
[2011/09/28 11:03:29 | 001,008,092 | —- | M] () – C:Documents and SettingsrlevereDesktoprkill.scr
[2011/09/28 11:01:17 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:Documents and SettingsrlevereDesktoprkill2.scr
[2011/09/28 09:37:25 | 000,039,965 | —- | M] () – C:Documents and SettingsrlevereDesktopDocument.rtf
[2011/09/28 09:07:57 | 000,377,919 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication Datacensus.cache
[2011/09/28 09:07:05 | 000,320,349 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication Dataars.cache
[2011/09/28 05:42:28 | 000,000,664 | —- | M] () – C:WINDOWSSystem32d3d9caps.dat
[2011/09/27 16:00:02 | 000,000,934 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-2509836690-573628217-1654637295-1006Core.job
[2011/09/23 10:22:05 | 000,000,218 | —- | M] () – C:Documents and Settingsrlevere.recently-used.xbel
[2011/09/20 16:01:56 | 000,002,300 | —- | M] () – C:Documents and SettingsrlevereDesktopGoogle Chrome.lnk
[2011/09/13 07:59:39 | 000,309,992 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2011/09/12 19:23:10 | 000,001,374 | —- | M] () – C:WINDOWSimsins.BAK
[2011/09/12 18:58:21 | 000,599,266 | —- | M] () – C:WINDOWSSystem32perfh009.dat
[2011/09/12 18:58:21 | 000,125,500 | —- | M] () – C:WINDOWSSystem32perfc009.dat
[2011/09/12 15:43:40 | 000,001,945 | —- | M] () – C:WINDOWSepplauncher.mif
[2011/09/12 10:52:37 | 000,000,038 | —- | M] () – C:WINDOWSavisplitter.INI
[2011/09/12 09:25:31 | 000,205,312 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/03 03:17:37 | 000,599,040 | —- | M] (Microsoft Corporation) – C:WINDOWSSystem32dllcachecrypt32.dll
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:WINDOWSSystem32driversmbam.sys
[55 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/28 11:07:26 | 000,001,678 | —- | C] () – C:Documents and SettingsAll UsersDesktopSUPERAntiSpyware Free Edition.lnk
[2011/09/28 11:03:50 | 000,000,335 | —- | C] () – C:Documents and SettingsrlevereDesktopFixExe.reg
[2011/09/28 11:03:26 | 001,008,092 | —- | C] () – C:Documents and SettingsrlevereDesktoprkill.scr
[2011/09/28 09:37:25 | 000,039,965 | —- | C] () – C:Documents and SettingsrlevereDesktopDocument.rtf
[2011/09/28 09:07:57 | 000,377,919 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datacensus.cache
[2011/09/28 09:07:05 | 000,320,349 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Dataars.cache
[2011/09/23 10:22:05 | 000,000,218 | —- | C] () – C:Documents and Settingsrlevere.recently-used.xbel
[2011/09/12 15:48:32 | 000,000,424 | -H– | C] () – C:WINDOWStasksMP Scheduled Scan.job
[2011/07/03 09:02:22 | 000,000,064 | —- | C] () – C:WINDOWSSystem32rp_stats.dat
[2011/07/03 09:02:22 | 000,000,044 | —- | C] () – C:WINDOWSSystem32rp_rules.dat
[2011/05/20 10:25:35 | 000,014,673 | —- | C] () – C:WINDOWSFace.INI
[2011/05/20 10:25:33 | 000,000,026 | —- | C] () – C:WINDOWSLayout2.INI
[2011/05/20 10:01:25 | 000,000,316 | —- | C] () – C:WINDOWSSoftWriting.ini
[2011/01/03 14:25:23 | 000,000,051 | —- | C] () – C:WINDOWSbrmx2001.ini
[2010/09/21 11:27:57 | 000,000,038 | —- | C] () – C:WINDOWSavisplitter.INI
[2010/08/23 14:38:25 | 000,000,034 | -H– | C] () – C:WINDOWSSystem32Converter_sysquict.dat
[2010/08/23 14:37:06 | 000,755,027 | —- | C] () – C:WINDOWSSystem32xvidcore.dll
[2010/08/23 14:37:05 | 000,159,839 | —- | C] () – C:WINDOWSSystem32xvidvfw.dll
[2010/08/23 14:37:04 | 000,007,680 | —- | C] () – C:WINDOWSSystem32ff_vfw.dll
[2010/08/23 09:55:00 | 000,036,608 | —- | C] () – C:WINDOWSSystem32FsUsbExDisk.Sys
[2010/08/23 09:54:59 | 000,110,592 | —- | C] () – C:WINDOWSSystem32FsUsbExDevice.Dll
[2010/08/23 09:54:39 | 000,002,528 | —- | C] () – C:Documents and SettingsrlevereApplication Data$_hpcst$.hpc
[2010/08/23 08:48:46 | 000,000,000 | —- | C] () – C:Documents and SettingsAll UsersApplication DataLauncherAccess.dt
[2010/08/23 08:38:51 | 000,005,632 | —- | C] () – C:WINDOWSSystem32driversStarOpen.sys
[2010/07/09 12:08:17 | 000,165,376 | —- | C] () – C:WINDOWSSystem32unrar.dll
[2010/07/08 14:50:43 | 003,525,264 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.0.0.dat
[2010/07/08 08:34:52 | 000,000,000 | —- | C] () – C:WINDOWSbrdfxspd.dat
[2010/07/02 17:00:42 | 000,000,036 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datahousecall.guid.cache
[2010/06/10 09:29:48 | 000,000,000 | —- | C] () – C:WINDOWSBrownie.ini
[2010/06/10 08:58:24 | 000,000,030 | —- | C] () – C:WINDOWSSystem32brss01a.ini
[2010/06/10 08:57:20 | 000,000,234 | —- | C] () – C:WINDOWSBrpfx04a.ini
[2010/06/10 08:57:20 | 000,000,092 | —- | C] () – C:WINDOWSbrpcfx.ini
[2010/06/10 08:57:20 | 000,000,050 | —- | C] () – C:WINDOWSSystem32BRIDF04A.dat
[2010/04/19 14:09:12 | 008,648,370 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-2509836690-573628217-1654637295-1006-0.dat
[2010/04/19 14:09:09 | 000,310,458 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-System.dat
[2010/04/02 18:17:34 | 000,179,091 | —- | C] () – C:WINDOWSSystem32xlive.dll.cat
[2009/07/02 11:54:55 | 000,000,212 | —- | C] () – C:WINDOWSildasmfnt.bin
[2008/09/16 12:16:45 | 000,000,034 | —- | C] () – C:WINDOWSSystem32BD7220.DAT
[2008/07/17 16:07:43 | 000,000,000 | —- | C] () – C:WINDOWSSAFEEDIT.INI
[2008/07/17 16:07:25 | 000,000,000 | —- | C] () – C:WINDOWSUBEEDIT.INI
[2008/04/11 15:56:00 | 000,119,503 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datadebuggee.mdmp
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:WINDOWSSystem32OGACheckControl.DLL
[2007/11/08 11:53:15 | 000,000,231 | —- | C] () – C:WINDOWSSystem323dsmax.ini
[2007/11/08 11:53:15 | 000,000,043 | —- | C] () – C:WINDOWSSystem32InstallSettings.ini
[2007/09/19 13:58:46 | 000,000,664 | —- | C] () – C:WINDOWSSystem32d3d9caps.dat
[2007/06/22 10:08:15 | 000,000,000 | —- | C] () – C:WINDOWSpcfriend.INI
[2007/06/20 08:35:02 | 000,077,312 | —- | C] () – C:WINDOWSua2.dll
[2007/06/01 12:44:57 | 000,000,000 | —- | C] () – C:WINDOWSZillions.INI
[2007/05/17 14:23:31 | 000,000,079 | —- | C] () – C:WINDOWSBRPP2KA.INI
[2007/05/17 08:40:54 | 000,000,419 | —- | C] () – C:WINDOWSBRWMARK.INI
[2007/03/06 12:21:25 | 000,016,384 | —- | C] () – C:WINDOWSSystem32FileOps.exe
[2006/12/04 12:46:59 | 000,060,236 | -H– | C] () – C:WINDOWSSystem32mlfcache.dat
[2006/11/22 11:55:52 | 000,000,221 | —- | C] () – C:WINDOWSSOFTEK.INI
[2006/11/22 11:53:18 | 000,050,176 | —- | C] () – C:WINDOWSSystem32annihilator.dll
[2006/11/22 11:53:18 | 000,046,592 | —- | C] () – C:WINDOWSSystem323dobuilder.dll
[2006/11/20 15:10:48 | 000,000,307 | —- | C] () – C:WINDOWSCaligari.ini
[2006/09/29 12:32:42 | 000,000,049 | —- | C] () – C:WINDOWSNeroDigital.ini
[2006/09/01 08:55:18 | 002,314,104 | —- | C] () – C:Program FilesPaint Shop Pro.zip
[2006/07/11 08:02:06 | 000,003,350 | -HS- | C] () – C:WINDOWSSystem32KGyGaAvL.sys
[2006/06/05 13:19:58 | 000,000,479 | —- | C] () – C:WINDOWSeReg.dat
[2006/05/18 08:15:19 | 000,000,754 | —- | C] () – C:WINDOWSWORDPAD.INI
[2006/05/17 12:01:21 | 000,004,103 | —- | C] () – C:WINDOWSPTMAYAIO.INI
[2006/05/17 11:59:26 | 000,000,263 | —- | C] () – C:WINDOWSui_bitmapviewer.ini
[2006/05/17 11:58:59 | 000,007,536 | —- | C] () – C:WINDOWSPOLYTRAN.INI
[2006/05/08 15:32:29 | 000,077,824 | —- | C] () – C:WINDOWSSystem32prtiutil.dll
[2006/05/08 15:32:29 | 000,028,672 | —- | C] () – C:WINDOWSSystem32hirestimer.dll
[2006/04/25 15:17:37 | 000,001,176 | —- | C] () – C:WINDOWS_ISENV31.INI
[2006/04/24 12:44:42 | 000,083,968 | —- | C] () – C:WINDOWSSystem32structuredqueryschema.bin
[2006/04/24 12:44:42 | 000,011,776 | —- | C] () – C:WINDOWSSystem32structuredqueryschematrivial.bin
[2006/04/18 15:48:14 | 000,020,714 | —- | C] () – C:WINDOWSSystem32idxcntrs.ini
[2006/04/18 15:47:46 | 000,037,532 | —- | C] () – C:WINDOWSSystem32gsrvctr.ini
[2006/04/18 15:47:40 | 000,031,698 | —- | C] () – C:WINDOWSSystem32gthrctr.ini
[2006/04/18 15:47:30 | 000,005,044 | —- | C] () – C:WINDOWSSystem32pqsperf.ini
[2006/04/18 15:30:56 | 003,596,288 | —- | C] () – C:WINDOWSSystem32qt-dx331.dll
[2006/04/18 15:30:13 | 000,536,576 | —- | C] () – C:WINDOWSSystem32DivXsm.exe
[2006/03/29 14:06:31 | 000,122,025 | —- | C] () – C:Documents and SettingsrlevereApplication Datadebuggee.mdmp
[2006/03/21 17:38:42 | 000,012,288 | —- | C] () – C:WINDOWSSystem32DivXWMPExtType.dll
[2006/03/11 13:10:51 | 001,280,640 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.51116.0.dat
[2006/03/07 16:50:52 | 000,021,504 | —- | C] () – C:WINDOWSSystem32csgl.native.dll
[2006/03/07 09:31:12 | 000,001,359 | —- | C] () – C:Documents and SettingsAll UsersApplication DataQTSBandwidthCache
[2006/03/02 14:00:11 | 000,000,002 | —- | C] () – C:WINDOWSmsoffice.ini
[2006/03/02 13:55:58 | 000,061,678 | —- | C] () – C:Documents and SettingsrlevereApplication DataPFP120JPR.{PB
[2006/03/02 13:55:58 | 000,012,358 | —- | C] () – C:Documents and SettingsrlevereApplication DataPFP120JCM.{PB
[2006/02/15 11:54:31 | 000,000,130 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datafusioncache.dat
[2006/02/14 13:45:40 | 000,000,056 | RHS- | C] () – C:WINDOWSSystem32\0D2D1C87A6.sys
[2006/02/14 09:09:42 | 000,205,312 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/02/11 11:13:40 | 000,000,520 | —- | C] () – C:WINDOWSODBC.INI
[2006/02/01 02:18:49 | 000,000,061 | —- | C] () – C:WINDOWSsmscfg.ini
[2006/02/01 02:10:03 | 000,149,504 | —- | C] () – C:WINDOWSUNWISE.EXE
[2006/02/01 02:07:24 | 000,000,138 | —- | C] () – C:WINDOWSwininit.ini
[2006/02/01 02:04:39 | 000,000,335 | —- | C] () – C:WINDOWSnsreg.dat
[2006/02/01 01:50:04 | 000,366,041 | —- | C] () – C:WINDOWSSystem32ctdlang.dat
[2006/02/01 01:50:04 | 000,313,207 | —- | C] () – C:WINDOWSSystem32ctstatic.dat
[2006/02/01 01:50:04 | 000,265,066 | —- | C] () – C:WINDOWSSystem32CTSBAS2W.DAT
[2006/02/01 01:50:04 | 000,231,821 | —- | C] () – C:WINDOWSSystem32CTSBASW.DAT
[2006/02/01 01:50:04 | 000,140,643 | —- | C] () – C:WINDOWSSystem32CTBAS2W.DAT
[2006/02/01 01:50:04 | 000,113,221 | —- | C] () – C:WINDOWSSystem32CTBASICW.DAT
[2006/02/01 01:50:04 | 000,053,932 | —- | C] () – C:WINDOWSSystem32ctdaught.dat
[2006/02/01 01:50:04 | 000,049,274 | —- | C] () – C:WINDOWSSystem32claptn32.ini
[2006/02/01 01:50:04 | 000,038,400 | —- | C] () – C:WINDOWSSystem32CTBURST.DLL
[2006/02/01 01:50:04 | 000,034,304 | —- | C] () – C:WINDOWSPSCONV.EXE
[2006/02/01 01:50:04 | 000,033,792 | —- | C] () – C:WINDOWSSystem32REGPLIB.EXE
[2006/02/01 01:50:04 | 000,000,194 | —- | C] () – C:WINDOWSSystem32KILL.INI
[2006/02/01 01:50:04 | 000,000,055 | —- | C] () – C:WINDOWSSystem32ctzapxx.ini
[2006/02/01 01:49:32 | 000,049,152 | —- | C] () – C:WINDOWSsetpwrcg.exe
[2006/02/01 01:49:20 | 000,000,292 | —- | C] () – C:WINDOWSSystem32OEMINFO.INI
[2005/12/06 03:35:32 | 000,417,792 | R— | C] () – C:WINDOWSSystem32XmlSpyLib.dll
[2005/06/18 08:00:52 | 000,070,018 | —- | C] () – C:WINDOWSSystem32akrip32.dll
[2005/06/14 10:01:48 | 000,241,664 | —- | C] () – C:WINDOWSSystem32freeglut.dll
[2005/04/14 20:57:02 | 000,037,376 | —- | C] () – C:WINDOWSSystem32glfw.dll
[2005/04/02 17:26:20 | 000,338,944 | —- | C] () – C:WINDOWSSystem32lffpx7.dll
[2005/04/02 17:26:20 | 000,118,784 | —- | C] () – C:WINDOWSSystem32lfkodak.dll
[2005/01/07 15:21:18 | 000,135,168 | —- | C] () – C:WINDOWSSystem32SDL_gfx.dll
[2004/12/15 23:15:10 | 000,348,160 | —- | C] () – C:WINDOWSSystem32SDL_ttf.dll
[2004/12/15 23:01:46 | 000,169,443 | —- | C] () – C:WINDOWSSystem32jpeg.dll
[2004/12/15 23:01:46 | 000,126,976 | —- | C] () – C:WINDOWSSystem32libpng13.dll
[2004/12/15 23:01:46 | 000,055,808 | —- | C] () – C:WINDOWSSystem32zlib1.dll
[2004/12/15 23:01:46 | 000,040,960 | —- | C] () – C:WINDOWSSystem32SDL_image.dll
[2004/12/15 22:05:56 | 000,315,392 | —- | C] () – C:WINDOWSSystem32SDL_mixer.dll
[2004/12/15 18:24:14 | 000,237,568 | —- | C] () – C:WINDOWSSystem32SDL.dll
[2004/12/01 19:34:46 | 000,000,716 | -H– | C] () – C:Documents and SettingsAll UsersApplication Datapb7msys.dat
[2004/08/10 12:12:05 | 000,000,780 | —- | C] () – C:WINDOWSorun32.ini
[2004/08/10 12:07:31 | 000,002,048 | –S- | C] () – C:WINDOWSbootstat.dat
[2004/08/10 12:02:15 | 000,023,348 | —- | C] () – C:WINDOWSSystem32emptyregdb.dat
[2004/08/10 12:01:18 | 000,001,793 | —- | C] () – C:WINDOWSSystem32fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | —- | C] () – C:WINDOWSODBCINST.INI
[2004/08/10 11:57:15 | 000,309,992 | —- | C] () – C:WINDOWSSystem32FNTCACHE.DAT
[2004/08/10 11:51:20 | 000,599,266 | —- | C] () – C:WINDOWSSystem32perfh009.dat
[2004/08/10 11:51:20 | 000,125,500 | —- | C] () – C:WINDOWSSystem32perfc009.dat
[2004/08/10 11:51:16 | 000,000,741 | —- | C] () – C:WINDOWSSystem32noise.dat
[2004/08/04 05:00:00 | 013,107,200 | —- | C] () – C:WINDOWSSystem32oembios.bin
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:WINDOWSSystem32mlang.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:WINDOWSSystem32perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:WINDOWSSystem32dssec.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:WINDOWSSystem32mib.bin
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:WINDOWSSystem32perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:WINDOWSSystem32secupd.dat
[2004/08/04 05:00:00 | 000,004,461 | —- | C] () – C:WINDOWSSystem32oembios.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:WINDOWSSystem32dcache.bin
[2004/05/29 12:39:02 | 000,405,504 | —- | C] () – C:WINDOWSSystem32ode.dll
[2003/07/08 14:49:24 | 000,282,624 | —- | C] () – C:WINDOWSSystem32tvimaging.dll
[2003/03/09 13:01:10 | 000,024,576 | —- | C] () – C:WINDOWSSystem32SDL_net.dll
[2003/02/10 02:13:10 | 000,000,416 | -H– | C] () – C:Documents and SettingsAll UsersApplication Datasystmsp2pb7
[2001/11/11 03:38:08 | 000,204,800 | —- | C] () – C:WINDOWSSystem32smpeg.dll
[1998/10/11 01:07:38 | 000,088,576 | —- | C] () – C:WINDOWSSystem32Iticheck.dll
========== LOP Check ==========
[2010/01/29 15:25:31 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataApplications
[2010/06/29 12:48:40 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAutodesk
[2008/06/30 14:16:23 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAzureus
[2006/02/14 13:08:25 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataBorland
[2006/05/10 07:47:21 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataGroove Networks
[2008/04/29 13:12:01 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataMindjet
[2010/08/23 10:10:49 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNCH Swift Sound
[2007/11/19 15:25:15 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNDoc.1.3
[2006/02/14 10:14:27 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataPreEmptive Solutions
[2009/09/24 15:01:40 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataRed Gate
[2010/08/23 09:55:37 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataSamsung
[2009/11/13 09:36:11 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataTEMP
[2006/02/01 02:05:41 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataViewpoint
[2011/06/15 13:25:10 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataVS
[2011/07/27 08:32:39 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/02 11:31:35 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/05/16 09:52:58 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Data.bittorrent
[2009/10/21 16:09:21 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Data.myibay
[2010/05/12 08:45:08 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataAutodesk
[2011/04/05 10:56:06 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataAzureus
[2011/03/01 10:58:39 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBHOK IT Consulting
[2007/08/13 16:57:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBitTorrent
[2010/05/12 10:49:09 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBlender Foundation
[2006/02/14 13:08:25 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBorland
[2010/09/15 15:17:52 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataControlScenarios
[2007/05/28 16:39:33 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataDNA
[2011/09/23 10:22:01 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datagtk-2.0
[2009/03/27 21:13:10 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataHouseCall 6.6
[2010/07/08 15:58:31 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataHudson
[2009/02/24 12:07:12 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataIsolatedStorage
[2009/02/24 17:07:05 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataJetBrains
[2006/02/15 12:34:26 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataLeadertech
[2006/05/02 09:07:01 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMayaWebBrowser
[2011/09/23 09:52:31 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMonoDevelop
[2011/09/23 10:12:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMonoDevelop-2.6
[2009/03/27 15:50:18 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMy Games
[2010/08/23 10:09:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataNCH Swift Sound
[2011/05/25 11:53:14 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataNuGet
[2007/01/04 15:08:00 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataOfficeUpdate12
[2010/10/05 11:16:03 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataooVoo Details
[2009/08/10 11:59:06 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataOpera
[2007/08/07 13:50:37 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataPegasys Inc
[2007/11/08 10:50:54 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataPoser 7
[2010/08/23 13:27:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataRingtone
[2010/08/23 09:54:20 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSamsung
[2008/05/29 11:32:38 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSciTech
[2011/06/20 14:52:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSecondLife
[2010/08/23 10:49:44 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSonyEricsson
[2011/09/23 09:53:22 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datastetic
[2006/11/29 10:27:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSubversion
[2010/10/05 16:00:26 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataTangible Software Solutions Inc
[2011/05/10 07:56:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataTelerik
[2006/05/17 09:54:23 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datauk.co.planetside
[2008/01/24 16:15:35 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataWings3D
[2011/09/28 12:44:07 | 000,000,472 | —- | M] () – C:WINDOWSTasksAd-Aware Update (Weekly).job
[2011/09/28 13:38:38 | 000,000,424 | -H– | M] () – C:WINDOWSTasksMP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%*.* >
[2006/12/13 11:18:07 | 000,000,079 | —- | M] () – C:3doImporterSettings.txt
[2011/06/15 15:50:18 | 000,004,908 | —- | M] () – C:aaw7boot.log
[2006/03/03 10:14:36 | 000,005,632 | —- | M] () – C:ATestMap.ptm
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:AUTOEXEC.BAT
[2007/06/04 10:49:58 | 000,003,554 | —- | M] () – C:avatar.jpg
[2007/11/07 13:03:53 | 000,015,723 | —- | M] () – C:AvatarChest.3ds
[2007/08/03 13:53:17 | 817,865,708 | —- | M] () – C:AVSEQ01.mpg
[2006/02/10 18:08:28 | 000,000,210 | -HS- | M] () – C:boot.ini
[2007/05/28 09:25:39 | 000,000,248 | —- | M] () – C:Bryce Uninstall.log
[2007/10/23 08:53:26 | 025,251,654 | —- | M] () – C:CCI00000.bmp
[2007/11/08 15:43:58 | 000,019,329 | —- | M] () – C:chest.3ds
[2007/11/08 15:45:36 | 000,029,830 | —- | M] () – C:chest.xaml
[2007/11/08 15:45:36 | 000,029,830 | —- | M] () – C:chest.xml
[2010/08/23 08:51:04 | 000,000,074 | —- | M] () – C:CMLoader.log
[2006/11/20 12:04:23 | 007,138,920 | —- | M] () – C:COD_FORTRESS.tnt
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:CONFIG.SYS
[2007/05/29 10:35:32 | 001,049,654 | —- | M] () – C:Copy of heightmap.bmp
[2007/05/29 10:39:44 | 016,778,294 | —- | M] () – C:Copy of Untitled.bmp
[2006/02/01 01:52:18 | 000,005,648 | RH– | M] () – C:dell.sdr
[2008/01/04 12:53:12 | 000,010,036 | —- | M] () – C:Doxyfile
[2007/10/23 16:50:01 | 002,005,928 | —- | M] () – C:fmodapi375win.zip
[2007/07/16 10:41:22 | 000,009,750 | —- | M] () – C:hair_modified1.jpg
[2007/07/16 11:00:50 | 000,010,041 | —- | M] () – C:hair_modified2.jpg
[2007/05/29 10:42:30 | 016,778,294 | —- | M] () – C:heightmap.bmp
[2007/05/28 15:23:20 | 000,005,991 | —- | M] () – C:heightmap.jpg
[2006/02/17 14:12:49 | 000,034,958 | —- | M] () – C:Hexkit.xsd
[2006/02/17 14:12:49 | 000,034,958 | —- | M] () – C:Hexkit2.xsd
[2011/09/28 12:51:21 | 2144,899,072 | -HS- | M] () – C:hiberfil.sys
[2006/02/10 18:05:44 | 000,004,128 | —- | M] () – C:INFCACHE.1
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:IO.SYS
[2006/02/01 02:05:44 | 000,000,775 | -H– | M] () – C:IPH.PH
[2006/03/16 10:15:58 | 000,184,434 | —- | M] () – C:iso_map.jpg
[2007/01/22 15:20:04 | 000,000,989 | —- | M] () – C:magnetar.cer
[2007/01/22 14:42:04 | 000,004,542 | —- | M] () – C:magnetar.pfx
[2010/06/24 08:39:13 | 000,000,109 | —- | M] () – C:mbam-error.txt
[2006/11/17 14:39:48 | 000,000,043 | —- | M] () – C:ModelStats.txt
[2007/04/20 12:22:09 | 002,265,600 | —- | M] () – C:mr3pdemo.exe
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:MSDOS.SYS
[2007/01/19 14:47:46 | 000,002,697 | —- | M] () – C:mycert.spc
[2007/01/09 15:43:02 | 000,001,212 | —- | M] () – C:mykey.pvk
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2008/05/15 15:27:37 | 000,250,048 | RHS- | M] () – C:ntldr
[2009/01/12 11:20:19 | 000,344,123 | —- | M] () – C:Original.pcx
[2011/09/28 12:51:15 | 2145,386,496 | -HS- | M] () – C:pagefile.sys
[2006/11/20 13:29:48 | 012,717,832 | —- | M] () – C:PaintedDesertII.tnt
[2007/07/19 14:45:32 | 000,015,833 | —- | M] () – C:radar.jpg
[2011/02/01 16:06:11 | 000,477,572 | —- | M] () – C:RES.zip
[2003/01/01 13:00:42 | 000,452,488 | —- | M] () – C:return_notice.jpg
[2011/09/28 13:37:50 | 000,000,630 | —- | M] () – C:rkill.log
[2006/11/17 14:34:48 | 000,004,195 | —- | M] () – C:samktorp.3DO
[2006/11/17 14:34:44 | 000,011,764 | —- | M] () – C:SAMurai.3do
[2006/11/22 11:15:32 | 000,000,304 | —- | M] () – C:SAMurai.mtl
[2006/11/22 11:15:32 | 000,022,085 | —- | M] () – C:SAMurai.obj
[2006/11/21 16:10:07 | 000,008,985 | —- | M] () – C:SAMurai.wrl
[2006/08/03 14:38:45 | 000,001,016 | —- | M] () – C:Shortcut to EMT Demo.lnk
[2007/07/16 10:31:28 | 000,012,144 | —- | M] () – C:sides_modified.jpg
[2007/11/08 12:18:49 | 000,083,613 | —- | M] () – C:SL-Avata.png
[2007/05/28 15:27:59 | 000,002,777 | —- | M] () – C:ta.pal
[2008/07/17 15:50:54 | 000,001,971 | —- | M] () – C:TACTICS.CFG
[2007/02/09 16:06:54 | 109,672,314 | —- | M] () – C:ta_tileset.pcx
[2007/01/25 11:46:39 | 000,000,066 | —- | M] () – C:temp.txt
[2007/05/28 15:36:34 | 000,001,647 | —- | M] () – C:test.ota
[2007/05/28 15:36:34 | 001,130,585 | —- | M] () – C:test.tnt
[2007/05/29 10:51:05 | 000,970,269 | —- | M] () – C:test.ufo
[2007/11/01 12:50:58 | 000,068,980 | —- | M] () – C:test.xaml
[2007/07/18 14:21:13 | 000,004,175 | —- | M] () – C:testmap.xml
[2007/10/31 14:50:29 | 000,019,456 | -HS- | M] () – C:Thumbs.db
[2006/03/16 11:15:11 | 000,003,108 | —- | M] () – C:tv3d_debug.txt
[2007/05/29 10:41:53 | 268,436,534 | —- | M] () – C:Untitled.bmp
[2010/08/16 15:39:03 | 000,000,024 | —- | M] () – C:url_history.xml
[2009/07/16 14:53:08 | 001,104,410 | —- | M] () – C:V1.4.zip
[2007/08/27 11:12:50 | 000,137,097 | —- | M] () – C:wave1.jpg
[2007/08/27 11:12:54 | 000,133,860 | —- | M] () – C:wave2.jpg
[2009/01/12 11:26:15 | 000,073,749 | —- | M] () – C:WPF_Version.jpg
[2007/11/08 12:44:00 | 000,159,207 | —- | M] () – C:XAML.zip
[2007/05/18 10:45:11 | 000,000,010 | -H– | M] () – C:xrjmns.tce
< %systemroot%Fonts*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
< %systemroot%Fonts*.dll >
< %systemroot%Fonts*.ini >
[2006/02/10 18:10:42 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini
< %systemroot%Fonts*.ini2 >
< %systemroot%Fonts*.exe >
< %systemroot%system32spoolprtprocsw32x86*.* >
[2004/02/09 01:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:WINDOWSsystem32spoolprtprocsw32x86brmfpp1.dll
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2009/12/10 10:24:06 | 000,082,168 | —- | M] (Microsoft Corporation.) – C:WINDOWSsystem32spoolprtprocsw32x86lmdippr8.dll
[2006/04/28 01:51:40 | 000,029,968 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe
< %systemroot%REPAIR*.bak1 >
< %systemroot%REPAIR*.ini >
< %systemroot%system32*.jpg >
< %systemroot%*.jpg >
< %systemroot%*.png >
< %systemroot%*.scr >
< %systemroot%*._sy >
< %APPDATA%AdobeUpdate*.* >
< %ALLUSERSPROFILE%Favorites*.* >
< %APPDATA%Microsoft*.* >
[2009/01/29 16:35:48 | 000,016,952 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoft1eaadjc.dll
[2009/01/29 16:35:48 | 000,018,724 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftbass.dll
[2009/01/29 16:35:49 | 000,321,536 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftengine_vx.dll
[2009/01/29 16:35:48 | 000,014,392 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftkfgresk.dll
[2009/01/29 16:35:48 | 000,013,984 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftmjcriu.dll
[2009/01/29 16:35:48 | 000,010,808 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftpeaadje.dll
[2009/01/29 16:35:48 | 000,026,200 | —- | M] ((: JOBnik!
[Arthur Aminov, ISRAEL]) – C:Documents and SettingsrlevereApplication DataMicrosoftqwadjb.dll
[2009/01/29 16:35:48 | 000,015,416 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftrsaadjd.dll
[1 C:Documents and SettingsrlevereApplication DataMicrosoft*.tmp files -> C:Documents and SettingsrlevereApplication DataMicrosoft*.tmp -> ]
< %PROGRAMFILES%*.* >
[2006/09/01 08:55:19 | 002,314,104 | —- | M] () – C:Program FilesPaint Shop Pro.zip
< %APPDATA%Update*.* >
< %systemroot%*. /mp /s >
< %systemroot%System32config*.sav >
[2006/02/10 10:02:29 | 000,262,144 | —- | M] () – C:WINDOWSSystem32configdefault.sav
[2006/02/10 17:55:00 | 000,262,144 | —- | M] () – C:WINDOWSSystem32configsecurity.sav
[2006/02/10 10:02:29 | 017,825,792 | —- | M] () – C:WINDOWSSystem32configsoftware.sav
[2006/02/10 10:02:31 | 005,505,024 | —- | M] () – C:WINDOWSSystem32configsystem.sav
< %PROGRAMFILES%bak. /s >
< %systemroot%system32bak. /s >
< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2008/05/15 15:34:26 | 000,000,272 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini
< %systemroot%system32configsystemprofile*.dat /x >
< %systemroot%*.config >
< %systemroot%system32*.db >
< %PROGRAMFILES%Internet Explorer*.dat >
< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2006/02/10 16:13:52 | 000,000,119 | -HS- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2004/08/10 12:08:38 | 000,000,079 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf
< %USERPROFILE%Desktop*.exe >
[2011/09/28 14:29:20 | 000,582,656 | —- | M] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 11:06:47 | 012,609,096 | —- | M] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
< %PROGRAMFILES%Common Files*.* >
< %systemroot%*.src >
< %systemroot%install*.* >
< %systemroot%system32DLL*.* >
< %systemroot%system32HelpFiles*.* >
< %systemroot%system32rundll*.* >
< %systemroot%winn32*.* >
< %systemroot%Java*.* >
< %systemroot%system32test*.* >
< %systemroot%system32Rundll32*.* >
< %systemroot%AppPatchCustom*.* >
< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >
< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-09-13 16:12:56
========== Alternate Data Streams ==========
@Alternate Data Stream - 810 bytes -> C:Documents and SettingsrlevereMy DocumentsCodeFile.cs:Undo
@Alternate Data Stream - 8 bytes -> C:Documents and SettingsrlevereMy DocumentsCodeFile.cs:Bookmarks
@Alternate Data Stream - 8 bytes -> C:Documents and SettingsrlevereMy DocumentsClass.cs:Bookmarks
@Alternate Data Stream - 56 bytes -> C:Documents and SettingsrlevereMy DocumentsClass.cs:Undo
@Alternate Data Stream - 368 bytes -> C:Documents and SettingsrlevereLocal SettingsApplication Datadesktop.ini:722b2b1c349a06abf0e866180e5a7e63
< End of report >
Here's Extras.txt:
OTL Extras logfile created on: 28/09/2011 2:31:38 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:Documents and SettingsrlevereDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.23% Memory free
3.84 Gb Paging File | 2.76 Gb Available in Paging File | 71.82% Paging File free
Paging file location(s): c:pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.78 Gb Total Space | 60.11 Gb Free Space | 25.82% Space Free | Partition Type: NTFS
Computer Name: NEBULA | User Name: rlevere | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
.js [@ = JSFile] – Reg Error: Key error. File not found
.reg [@ = Regedit.Document] – c:WinntRegedit.exe %1
[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = FirefoxHTML] – C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewall]
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfile]
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfile]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4282:TCP" = 4282:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"37682:TCP" = 37682:TCP:*:Disabled:ooVoo TCP port 37682
"37682:UDP" = 37682:UDP:*:Disabled:ooVoo UDP port 37682
"37683:UDP" = 37683:UDP:*:Disabled:ooVoo UDP port 37683
"37686:TCP" = 37686:TCP:*:Disabled:ooVoo TCP port 37686
"37686:UDP" = 37686:UDP:*:Disabled:ooVoo UDP port 37686
"37687:UDP" = 37687:UDP:*:Disabled:ooVoo UDP port 37687
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 1
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"2799:UDP" = 2799:UDP:*:Enabled:Altova License Metering Port (UDP)
"2799:TCP" = 2799:TCP:*:Enabled:Altova License Metering Port (TCP)
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"C:Program FilesMicrosoft XNAXNA Game Studiov3.1BinXnaLiveProxy.exe" = C:Program FilesMicrosoft XNAXNA Game Studiov3.1BinXnaLiveProxy.exe:LocalSubNet:Enabled:XNA Framework Games for Windows - LIVE – (Microsoft Corporation)
"C:Program FilesAutodesk3ds Max 20113dsmax.exe" = C:Program FilesAutodesk3ds Max 20113dsmax.exe:*:Enabled:Autodesk 3ds Max 2011 32-bit
"C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32server.exe" = C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max 2011 32-bit
"C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32.exe" = C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max 2011 32-bit
"C:Program Filesmyibaymyibay.exe" = C:Program Filesmyibaymyibay.exe:*:Enabled:Myibay eBay bid sniper – ()
"C:Program FilesOperaopera.exe" = C:Program FilesOperaopera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:Program FilesMicrosoft Security Essentialsmsseces.exe" = C:Program FilesMicrosoft Security Essentialsmsseces.exe:*:Enabled:Microsoft Security Essentials
"C:Program FilesMicrosoft Visual Studio 9.0Common7IDEdevenv.exe" = C:Program FilesMicrosoft Visual Studio 9.0Common7IDEdevenv.exe:*:Enabled:Microsoft Visual Studio 2008 – (Microsoft Corporation)
"C:Program FilesMicrosoft Visual Studio 8Common7IDEdevenv.exe" = C:Program FilesMicrosoft Visual Studio 8Common7IDEdevenv.exe:*:Enabled:Microsoft Visual Studio 2005 – (Microsoft Corporation)
"C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.exe:*:Enabled: – ()
"C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.32BitLaunch.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.32BitLaunch.exe:*:Enabled:OpenSim.32BitLaunch – ()
"C:Program FilesSamsungSamsung New PC Studionpsasvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsasvr.exe:*:Enabled:KTF MUSIC AoD Server – (PeeringPortal)
"C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe:*:Enabled:KTF MUSIC VoD Server – (PeeringPortal)
"C:Program FilesTelerikRadControls for Silverlight Q2 2010 SP1DemosExamples.WebStartExamples.exe" = C:Program FilesTelerikRadControls for Silverlight Q2 2010 SP1DemosExamples.WebStartExamples.exe:*:Enabled:StartExamples
"C:Program FilesooVooooVoo.exe" = C:Program FilesooVooooVoo.exe:*:Enabled:ooVoo – (ooVoo LLC)
"C:Documents and Settingsrleveredownloads4dkreign17Dark Reign 1.7dkreign.exe" = C:Documents and Settingsrleveredownloads4dkreign17Dark Reign 1.7dkreign.exe:*:Enabled:dkreign – ()
"C:Documents and SettingsrlevereMy DocumentsDownloadseclipse-modeling-helios-SR2-incubation-win32eclipseeclipse.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadseclipse-modeling-helios-SR2-incubation-win32eclipseeclipse.exe:*:Disabled:eclipse – ()
"C:Program FilesTelerikRadControls for Silverlight Q3 2010 SP1DemosExamples.WebStartExamples.exe" = C:Program FilesTelerikRadControls for Silverlight Q3 2010 SP1DemosExamples.WebStartExamples.exe:*:Enabled:StartExamples
"C:Program FilesMicrosoft XNAXNA Game Studiov4.0BinXnaLiveProxy.exe" = C:Program FilesMicrosoft XNAXNA Game Studiov4.0BinXnaLiveProxy.exe:LocalSubNet:Enabled:XNA Framework Games for Windows - LIVE – (Microsoft Corporation)
"C:Program FilesSecondLifeViewer2SLVoice.exe" = C:Program FilesSecondLifeViewer2SLVoice.exe:*:Disabled:SLVoice – (Vivox Inc.)
"C:Documents and SettingsrlevereMy DocumentsDownloadsSilverlightPlayground.UDPMulticastSilverlightPlayground.UDP
Multicast.PolicyServerbinDebugPolicyServer.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsSilverlightPlayground.UDPMulticastSilverlightPlayground.UDP
Multicast.PolicyServerbinDebugPolicyServer.exe:*:Enabled:PolicyServer – (Microsoft IT)
"C:Program FilesMicrosoft Silverlightsllauncher.exe" = C:Program FilesMicrosoft Silverlightsllauncher.exe:*:Enabled:Microsoft Silverlight Out-of-Browser Launcher – (Microsoft Corporation)
"C:Program FilesMicrosoft Office Communicatorcommunicator.exe" = C:Program FilesMicrosoft Office Communicatorcommunicator.exe:*:Enabled:Office Communicator – (Microsoft Corporation)
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"C:Program FilesFiraxis GamesSid Meier's Civilization 4Civilization4.exe" = C:Program FilesFiraxis GamesSid Meier's Civilization 4Civilization4.exe:*:Enabled:Sid Meier's Civilization 4
"C:Program FilesAtariNeverwinter Nights 2nwn2main.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main
"C:Program FilesAtariNeverwinter Nights 2nwn2main_amdxp.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD
"C:Program FilesAtariNeverwinter Nights 2nwupdate.exe" = C:Program FilesAtariNeverwinter Nights 2nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater
"C:Program FilesAtariNeverwinter Nights 2nwn2server.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server
"C:Program FilesTHQGas Powered GamesSupreme CommanderbinSupremeCommander.exe" = C:Program FilesTHQGas Powered GamesSupreme CommanderbinSupremeCommander.exe:*:Enabled:Supreme Commander
"C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe" = C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe:*:Enabled:GPGNet - Supreme Commander
"C:Program FilesMicrosoft XNAXNA Game Studio Expressv1.0BinXnaTrans.exe" = C:Program FilesMicrosoft XNAXNA Game Studio Expressv1.0BinXnaTrans.exe:LocalSubNet:Enabled:XNA Game Studio Transport – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{0028A6EE-4945-4233-8024-80A546F56A5C}" = JetBrains dotTrace 3.1
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{006DEADE-E12E-4DA0-AB65-134F0DE9AF9A}" = Swift 3D v4.50
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{030FF28D-42E3-44C1-BDC6-7451CB89B41D}" = Exception Hunter 2
"{05855322-BE43-41FE-B583-D3AE0C326D58}" = Microsoft Silverlight 4 SDK
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{06CB415E-F256-4097-95B2-7555EBD1DBC0}" = "WPF/E" Visual Studio 2005 Template CTP (Dec 2006)
"{070B87FB-CD1A-45AA-9E5E-484E5964C6ED}" = Microsoft XNA Game Studio 2.0 (ARP entry)
"{077C74E2-A2A8-11D5-8CD5-00104BB9CE36}" = Speech
"{07EF3970-F8E5-4A27-A5A3-230484D35026}" = Microsoft Expression Encoder 4
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{08D605B4-DCD1-451F-ABD7-52E6BB868E4E}" = Microsoft Expression Design 4
"{09C52940-A4D1-4409-A7CC-1AAE630CF578}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0BE273CD-AAB9-361B-8C32-D955EAC929E3}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D1CBBB9-F4A8-45B6-95E7-202BA61D7AF4}" = Microsoft Office Communicator 2007 R2
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{0FF406B0-98E3-4872-A743-6FBB0259BDF2}" = Composite UI Application Block December 2005 (C#)
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{11971FBC-7388-4D30-8D64-17741D2D665C}" = Microsoft Windows Software Development Kit Documentation (5536.0.2)
"{124533B3-5155-339B-A641-67BB84F39475}" = Visual C++ 2008 x64 Runtime - (v9.0.30428)
"{124533B3-5155-339B-A641-67BB84F39475}.vc_x64runtime_30428_01" = Visual C++ 2008 x64 Runtime - v9.0.30428.01
"{1287B0B4-0E89-4839-B552-809D5C0DC9F6}" = StudioTax 2010
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{152F8595-0D36-4BE4-9FBD-5AD87AC3D3E5}" = Microsoft XNA Game Studio Express 1.0 Refresh
"{170DE2A7-4768-370C-9671-D8D17826EFBF}" = Microsoft Visual Studio 2010 Performance Collection Tools SP1 - ENU
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}" = Sound Blaster X-Fi
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C997E1C-5CE9-4AF3-AAA9-DC65E6090827}" = Microsoft Expression Blend SDK for Silverlight 4
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F85CAAA-B786-4E5B-AADD-638856992EF3}" = Opera 10.53
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{213C85AC-6CB3-4B52-8420-AFFAEEF4DE75}" = Smoke - Game Technology Demo
"{21D8E686-2E8F-46F1-B997-209E4E0873A1}" = Microsoft Visual Studio 2005 Team Explorer - ENU
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729)
"{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01
"{23E5C72C-CC08-4EE0-9CC2-D925B232B331}" = Microsoft MSDN 2005 Express Edition - ENU
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{24C56EE0-76FC-42C7-BD42-78F2EEE63FCD}" = NDEV software
"{256E7DAC-9BE8-494E-8DE7-7857BF96B774}" = Microsoft Expression Blend 3 SDK
"{26119A24-8F74-4F62-A278-AB3984B12C04}" = Microsoft Web Platform Installer 2.0 RC
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2A42414B-1E07-454B-97C4-4789D8DBD338}" = Multiverse Tools
"{2A5A6D00-2B27-4E1A-8A33-E3A40DFDF3EB}" = Microsoft XNA Game Studio 2.0
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C057674-72BF-410E-820F-054F43293E65}" = WCF RIA Services V1.0 SP2 Preview (April 2011)
"{2C695618-6950-4C88-B836-A4FE7DD7FC9F}" = CuneiForm OpenOCR
"{2C97AA6D-8B10-46CA-B7A5-36DF71ACD1E0}" = GoSilverlight [removed]
"{2D514F36-DD72-4F2B-B10A-C5BC76585760}" = MagnetarTrystAddIn
"{2DDCCEA5-2AA4-4ABB-BCAD-41BB115A4333}" = Microsoft Silverlight 4 Toolkit April 2010
"{2DFDD440-A33C-42E4-A366-71E6CB4246A0}" = Microsoft Command Shell
"{2E402AA9-5C0E-45E7-8E70-C23FA0F265D5}" = Microsoft XNA Game Studio 3.1 (devenv)
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{302F9AB2-9165-4968-B482-11E2673B62D3}" = Mindjet MindManager Pro 7
"{310141DF-B0E2-428C-BE3B-25A5F9517F6E}" = MindManager Accelerator SDK
"{31EA6FCB-6C53-4BA7-BE88-9BA788899C2C}" = Microsoft XNA Game Studio 2.0 (Redists)
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{3432C2AA-BB3E-44B3-B5ED-EF36E0241100}" = Microsoft XNA Game Studio 2.0 (spacewar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{370BBA05-01E7-4BCC-9B38-E85DB8E13E11}" = Microsoft Silverlight 2 SDK
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{39970EE2-C8E3-3095-8B15-A7B99863527F}" = Visual C++ 2008 x64 Runtime - KB2465361 - (v9.0.30729.5570)
"{39970EE2-C8E3-3095-8B15-A7B99863527F}.vc_x64runtime_30729_5570" = Visual C++ 2008 x64 Runtime - v9.0.30729.5570
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B5A6E00-2B27-4E1A-8A33-E3A40DEFD4DC}" = Microsoft XNA Game Studio 2.0 Documentation
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.4148)
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}.vc_x64runtime_30729_4148" = Visual C++ 2008 x64 Runtime - v9.0.30729.4148
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB09FD2-DBF7-4BB1-8A68-1D48A9B22CEA}" = XNA Build System
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{3F8D9A47-9C50-3F46-8F12-B92DD5CA0A2E}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.6161)
"{3F8D9A47-9C50-3F46-8F12-B92DD5CA0A2E}.vc_x86runtime_30729_6161" = Visual C++ 2008 x86 Runtime - v9.0.30729.6161
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{4112625F-2D38-49EF-924F-48511BC5CD34}" = Microsoft SQL Server 2008 Database Engine Services
"{431FC52A-2963-4F92-A2FB-5E5C2EF9069F}" = Warplanner2
"{437AB8E0-FB69-4222-B280-A64F3DE22591}" = Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{44F7BA74-C11A-49FC-B2FC-1B827C491F74}" = Microsoft Expression Studio 3
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4723f199-fa64-4233-8e6e-9fccc95a18ee}" = Python 2.6.5
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4946979B-3624-3F97-997E-49F4CA0E3E90}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.6161)
"{4946979B-3624-3F97-997E-49F4CA0E3E90}.vc_i64runtime_30729_6161" = Visual C++ 2008 IA64 Runtime - v9.0.30729.6161
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4B4345D9-A3BF-409F-A392-3B45C4C3E067}" = tIDE v2.0.1
"{4B6A3B5E-D26E-4690-A061-F3E2FB10F0E5}" = TortoiseSVN 1.6.9.19725 (32 bit)
"{4C6D5779-A766-45DF-9938-D6F595A66F2B}" = Microsoft Expression Blend 4
"{4DE79189-E5DD-49A0-914F-E40919AAB597}" = Okino Plug-ins Installer (Demo Version)
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{51A6F9AE-AFF6-4A96-BEBA-217350BC3803}" = Infragistics NetAdvantage 2006 Vol. 1 for CLR 2.0
"{531B96B7-5126-4DC6-B51B-3DCDB0F93BA6}" = Microsoft® MechCommander® 2 Shared Source Release
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{550B72C4-F404-4812-971F-947E835A877E}" = Gtk# for .Net 2.12.10
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{558358E5-E4F3-4374-BA1D-26FF39EF87D9}" = Microsoft Silverlight 4 Tools for Visual Studio 2010
"{55979D54-FE44-4BCE-A2CF-9D29727F267D}" = Altova Enterprise XML Suite 2006
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57BB52B7-6B7B-31F3-89F4-4EE8FE5CEF6D}" = Microsoft Help Viewer 1.1
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5C741A01-05D6-4306-BA6A-DC8401285AE8}" = Debugging Tools for Windows
"{5D05CEB3-647F-4408-BC8C-B1247B107E61}" = Microsoft Silverlight 5 Beta SDK
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{5EE6E987-1B79-4A93-832B-27472C7D1579}" = WPF Toolkit February 2010 (Version 3.5.50211.1)
"{5F8D931D-B230-47F3-A9C0-0C8CA459A332}" = Microsoft Expression Web 4
"{60E2C8C9-6CF3-4B1A-9618-E304946C94E6}" = Python 2.4.4
"{60EEBD86-9EF0-444B-90ED-43AE78D09C7F}" = MonoDevelop 2.6
"{6201E1EB-DA64-4714-ADBB-852D74B1E5CC}" = Mono for Android 1.2.0.24718
"{62B002C5-1AB3-11D8-8092-00E018B21FC0}" = USB Mass Storage Toolbox
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6356A0A5-B9B8-4A9E-BEBC-8D3B73E8CF30}" = Torque X 2D 3.1
"{63B9D49E-6417-4BA7-AC6E-1654A853C2CD}" = .NET Memory Profiler 3.1
"{63FAC405-B376-4F24-A31C-321E904CFD38}" = Microsoft .NET Client Futures Code Name "Acropolis" CTP1
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{654EF90B-6DAD-4734-B6F0-F56AF7F2B1A0}" = Microsoft Visual Studio 2005 SDK April 2006
"{65BCF909-6AF7-4B01-8EB3-713CE2873DC8}" = Microsoft Expression Web 3
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{69F0982C-F08D-49E0-B8FB-FD636FD4DE40}" = XMLSPY 5 Professional Edition
"{6AFBA3EB-0BBC-4E7B-9410-D319B55B3794}" = Microsoft Windows Software Development Kit Compilers (5536.0.2)
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6ED37A91-7710-3183-BE50-AB043FF6689E}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{6FAE970B-73B6-4490-9A8E-74DFB09742D7}" = Microsoft Windows Software Development Kit Utilities for Win32 Development (5536.0.2)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7348C833-0030-4EAF-8EB2-085B3D5D2BFB}" = Microsoft Windows Software Development Kit Utilities for .NET Development (5536.0.2)
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{7451D88C-8A79-44C2-8528-8C952730B6B5}" = Nova Studio 2010
"{752E90AC-3F11-4EA3-88EA-96441047EC31}" = Microsoft Expression Web 3 SP1
"{766B3A7A-B5AE-33F5-9858-75E692799C84}" = Microsoft Visual Studio 2008 Team Explorer - ENU
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}" = Microsoft SQL Server 2008 R2 Management Objects
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A56D81D-6406-40E7-9184-8AC1769C4D69}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.4148)
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}.vc_x86runtime_30729_4148" = Visual C++ 2008 x86 Runtime - v9.0.30729.4148
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E7D7935-B0C8-4032-80BA-2CDC9E43C3B8}" = Microsoft Visual C# 2005 Express Edition - ENU
"{7EA88F86-024F-46B6-AE24-327001D6A9E1}" = ANTS Memory Profiler 5
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{7FEDF49B-01B3-3E2B-9C41-3A6F9583A040}" = Visual C++ 2008 IA64 Runtime - KB2465361 - (v9.0.30729.5570)
"{7FEDF49B-01B3-3E2B-9C41-3A6F9583A040}.vc_i64runtime_30729_5570" = Visual C++ 2008 IA64 Runtime - v9.0.30729.5570
"{80C06CCD-7D07-3DB6-86CD-B57B3F0614D8}" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"{80D4FD4C-A8B7-4924-94B9-079C657F0DFA}" = Microsoft Windows Software Development Kit (5536.0.2)
"{827990C7-4D30-3627-A2D1-5FFA09198BB2}" = Microsoft Visual Studio 2010 Office Developer Tools (x86)
"{828BC0F5-C51E-4037-9B33-3C108F92E0FC}" = WPF Performance Suite
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{846D9AAD-EA7D-4126-9177-F874FD389BE4}" = Microsoft FxCop 1.35
"{85195381-0426-4715-8D25-E21B9457FC00}" = Ad-Aware
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{877B76B2-F83F-4F5A-B28D-3F398641ADB6}" = Microsoft SQL Server System CLR Types
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{8E67940F-CFDB-4B01-A83A-4D75923FAFC1}" = Microsoft Silverlight 3 Tools for Visual Studio 2008 SP1 - ENU
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9660018B-2873-44BD-95E5-A06AC4F7FE62}" = NUnit 2.4 (Beta 1) for .Net 2.0
"{97CE8B73-AA5A-4987-A1BE-50DD1A187478}" = Microsoft Sync Framework SDK v1.0 SP1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4
"{9B96628C-8898-4FED-9612-25631C27AB13}" = Microsoft XNA Game Studio 2.0 (xnaliveproxy)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DDE6C99-1659-4355-B7E5-30D2B38E3224}" = Actipro Wizard v3.0.0129
"{9EE2C1FE-6A4D-4C9C-B10B-FCBFA5478753}" = Microsoft Windows Software Development Kit Common Utilities (5536.0.2)
"{A06FE62B-CEBC-4E94-AED8-92DCC33BC8EA}" = Microsoft Expression Studio 4
"{A1E28FCC-0BE8-3556-A851-669BCD314D02}" = Visual C++ 2008 IA64 Runtime - (v9.0.30428)
"{A1E28FCC-0BE8-3556-A851-669BCD314D02}.vc_i64runtime_30428_01" = Visual C++ 2008 IA64 Runtime - v9.0.30428.01
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2425E6C-8A37-3D63-A3A7-8ED5355FDF0B}" = Visual C++ 2008 x86 Runtime - KB2465361 - (v9.0.30729.5570)
"{A2425E6C-8A37-3D63-A3A7-8ED5355FDF0B}.vc_x86runtime_30729_5570" = Visual C++ 2008 x86 Runtime - v9.0.30729.5570
"{A24DDA75-14A2-479C-B281-5C78B3E472FC}" = ZAM 3D
"{A2FCFCB8-38BB-4DCE-BE85-EB921AEFCD9A}" = Nova 2010 SDK
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4394612-D02F-11DC-9BFF-D18556D89593}" = Microsoft ASP.NET MVC RC
"{A4FA40F1-B88C-4BDF-B291-ED34982CB48F}" = Microsoft Expression Blend 3
"{A5E08284-41D3-4ACB-804D-47FBE5976A59}" = Multiverse Client
"{A77CBE0F-1EB2-30B8-89FA-6F5E51AF82B7}" = Visual C++ 2008 x86 Runtime - (v9.0.30428)
"{A77CBE0F-1EB2-30B8-89FA-6F5E51AF82B7}.vc_x86runtime_30428_01" = Visual C++ 2008 x86 Runtime - v9.0.30428.01
"{A91E3887-5185-4091-AF33-AB0048444055}" = Microsoft Online Services Sign In
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAF71941-BF2F-48FD-A52C-BD819C33F0FB}" = "WPF/E" (codename) SDK CTP (Dec 2006)
"{ABCA0C33-0F35-497D-9D66-09E524051115}" = Zillions of Games Demo
"{AC1A9DFE-812F-4D47-A1EE-329CFA331E4B}" = Shader Build Task
"{AC388C78-2619-452C-BFBE-FABCC3194387}" = Microsoft Office Live Meeting 2007
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148)
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}.vc_i64runtime_30729_4148" = Visual C++ 2008 IA64 Runtime - v9.0.30729.4148
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3D1CFF9-C5DA-3590-894B-40821DDB67C5}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{B4DADED7-14DB-4FC0-BFAB-8549AD2191AE}" = Actipro Wizard v1.0.0305 for WPF
"{B5C9E5BD-7E70-4317-9779-22633C3BA1AF}" = Telerik RadControls for Silverlight Q1 2011
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8E9F8A1-9F4D-43D5-ABD6-1DF067FAA469}" = Microsoft SQL Server 2008 Database Engine Services
"{BA0C9AAF-1327-3F06-B49C-349B4BE8F740}" = Microsoft Visual Studio 2008 Shell (integrated mode) - ENU
"{BB4473CB-0CA3-4F4C-B4C7-427ECA3696BF}" = Microsoft Windows Software Development Kit Debug Symbols for .NET Development (5536.0.2)
"{BC0464FA-A0BA-3E38-85BF-DC5B3A401F48}" = Microsoft Visual Studio 2010 Ultimate - ENU
"{BC537AE0-88AF-47ED-B762-33B0D62B5188}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BF127B80-CFD5-4379-9752-E8AF1A5D0141}" = Microsoft Expression Encoder 4 Screen Capture Codec
"{C05344FF-448C-42FD-88D9-351BEC25C217}" = ANTS Performance Profiler 5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C18DA187-6C0D-4B8E-99AE-74D5C588AFB6}" = Microsoft XNA Game Studio 2.0 (shared components)
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C25EF637-BE7A-4761-9B45-9069989C319F}" = Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C6DD625F-4B61-4561-8286-87CA0275CEA1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86)
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{C7EA29FC-78F2-4680-9D9B-22CA8191E63C}" = Microsoft Visual SourceSafe 2005 - ENU
"{C8A7718A-FF6D-4DDC-AE36-BBF968D6799B}" = Visual Studio 2005 Extensions for Windows Workflow Foundation
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB979F2F-DB8C-495B-AE17-A00ABD083931}" = Mindjet MindManager 6 AddIn Project Template for Visual Studio 2005
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CD5DC4AA-7D62-48D9-B756-5925471001FE}" = Microsoft OLE DB Provider for Visual FoxPro
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D10EC365-8936-4B40-AE2E-FCDA61C326D3}" = Alias DirectConnect 2.0
"{D12775DE-6D75-47A7-8354-44EFBA97B131}" = Microsoft Platform SDK Codenamed 'Phoenix' (June 2008 CTP)
"{D1ED83D7-A98D-4071-B559-B50B899F8554}" = Microsoft Windows Software Development Kit Samples (5536.0.2)
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{D5462C8A-D08C-4163-8293-82F2E11A2760}" = Trend Micro TrendProtect for Internet Explorer
"{D6D42959-143F-456A-9941-A400FD7B25D8}" = Microsoft Visual Studio Code Name "Orcas" Community Technology Preview - Development Tools for .NET Framework 3.0
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DC3D6AFB-78B4-489F-81D7-30B66E0C2417}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x86)
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E7E58A3A-D9BD-3D4B-9475-AE757454AD82}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.6161)
"{E7E58A3A-D9BD-3D4B-9475-AE757454AD82}.vc_x64runtime_30729_6161" = Visual C++ 2008 x64 Runtime - v9.0.30729.6161
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9980014-BE11-4891-A5F4-0F2917B856BC}" = Microsoft Expression Design 3
"{EB3F5C2A-0754-38B8-8722-7B537006BF46}" = Microsoft Visual Studio 2008 Performance Collection Tools - ENU
"{ED780CA9-0687-3C12-B439-3369F224941F}" = Microsoft Visual Studio 2010 Service Pack 1
"{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}" = Adobe Stock Photos 1.0
"{F02D0CB9-C830-4B47-AA88-3125BE5E2E34}" = Groove
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F5993FCC-DF5D-4879-B70D-AA1F379C5C6B}" = Microsoft Expression Web 4 Service Pack 2
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F73340A9-8AA9-49C4-937E-E271B837056C}" = Microsoft Expression Encoder 3
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{F990B526-8F7C-46E0-B1F1-6C893A8B478F}" = Microsoft Sync Framework Services v1.0 SP1 (x86)
"{FAA106B4-2BBC-4ED3-9926-A003F2EAF18E}" = Microsoft DirectX SDK (February 2007)
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FB6ABA92-AF6A-4342-A7D4-D90A6CC66F6A}" = Microsoft Expression Blend 2 August Preview
"{FB8E4A2F-8D7D-4EF0-85FD-1F3D8817E573}" = Microsoft Silverlight PivotViewer
"{FC43B563-6D17-4A92-A314-E139D0D73A63}" = CodeWarrior for Wii V1.3
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FE0E06F7-209A-47BD-AC29-3B584166A627}" = Microsoft Windows Software Development Kit Headers and Libraries (5536.0.2)
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"AC3ACM" = AC-3 ACM Codec
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Flex Builder 2" = Adobe Flex Builder 2
"Adobe Shockwave Player" = Adobe Shockwave Player
"Android SDK Tools" = Android SDK Tools
"AOL Connectivity Services" = AOL Connectivity Services
"Blend_3.0.1927.0" = Microsoft Expression Blend 3
"Blend_4.0.20525.0" = Microsoft Expression Blend 4
"Borland JBuilder 2006 Enterprise" = Borland JBuilder 2006 Enterprise
"CleanUp!" = CleanUp!
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Design_6.0.1739.0" = Microsoft Expression Design 3
"Design_7.0.20516.0" = Microsoft Expression Design 4
"doxygen_is1" = doxygen 1.7.1
"DVDInfoPro" = DVDInfoPro
"Encoder_3.0.1332.0" = Microsoft Expression Encoder 3
"Encoder_4.0.1639.0" = Microsoft Expression Encoder 4
"ExpressionStudio_3.0.1061.0" = Microsoft Expression Studio 3
"ExpressionStudio_4.0.20525.0" = Microsoft Expression Studio 4
"FBX Plugin 2006.11.1 for Max 2008" = FBX Plugin 2006.11.1 for Max 2008
"Fraps" = Fraps
"GOBLIN Graph Library_is1" = GOBLIN Rel. 2.7
"GoToAssist" = GoToAssist 8.0.0.516
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4DE79189-E5DD-49A0-914F-E40919AAB597}" = Okino Plug-ins Installer (Demo Version)
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MeshLab" = MeshLab 1.0.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft DirectX SDK (August 2009)" = Microsoft DirectX SDK (August 2009)
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft MSDN 2005 Express Edition - ENU" = Microsoft MSDN 2005 Express Edition - ENU
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual C# 2005 Express Edition - ENU" = Microsoft Visual C# 2005 Express Edition - ENU
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual SourceSafe 2005 - ENU" = Microsoft Visual SourceSafe 2005 - ENU
"Microsoft Visual Studio 2005 Professional Edition - ENU" = Microsoft Visual Studio 2005 Professional Edition - ENU
"Microsoft Visual Studio 2005 Team Explorer - ENU" = Microsoft Visual Studio 2005 Team Explorer - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Team Explorer - ENU" = Microsoft Visual Studio 2008 Team Explorer - ENU
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio 2010 Ultimate - ENU" = Microsoft Visual Studio 2010 Ultimate - ENU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Team System 2008 Team Suite - ENU" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"Microsoft XNA Game Studio 2.0" = Microsoft XNA Game Studio 2.0
"MilkShape 3D 1.7.10" = MilkShape 3D 1.7.10
"Mozilla Firefox 7.0 (x86 en-US)" = Mozilla Firefox 7.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"myibay eBay bid sniper_is1" = Myibay Auction bid sniper for eBay 1.0.43
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PCFriendly" = PCFriendly
"PeerGuardian_is1" = PeerGuardian 2.0
"PROR" = Microsoft Office Professional 2007
"pRTI 1516 LE v3.1.1" = pRTI 1516 LE v3.1.1
"PVK-Import" = Microsoft PVK Import (Remove only)
"RADVideo" = RAD Video Tools
"RealPlayer 6.0" = RealPlayer Basic
"ScriptEase_is1" = ScriptEase
"SDKSetup_6.0.5536.0" = Microsoft Windows Software Development Kit (5536.0.2)
"SecondLife" = SecondLife (remove only)
"SecondLifeViewer2" = SecondLifeViewer2 (remove only)
"SimpleOCR 3.1" = SimpleOCR 3.1
"ST5UNST #1" = 3DOBuilder+
"ST6UNST #2" = GAF Builder Pro 2.5
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TAE Version 1 beta 1" = TAE Version 1 beta 1
"Tao" = Tao 1.2.0
"TMPGEnc PLUS v2.57.41.146" = TMPGEnc PLUS v2.57.41.146
"Total Annihilation" = Total Annihilation
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"TrueVision3D 6.2_is1" = TrueVision3D 6.2
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"Visual Studio 2005 Extensions for Windows Workflow Foundation" = Visual Studio 2005 Extensions for Windows Workflow Foundation
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VTP Software_is1" = VTP Software 2006.04.16
"Web_3.0.3813.0" = Microsoft Expression Web 3
"Web_4.0.1303.0" = Microsoft Expression Web 4
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Creator v2.5+" = World Creator v2.5+
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"yFiles for Silverlight Complete 2.0_is1" = yFiles for Silverlight Complete 2.0.0.1 Evaluation
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"06735F25C3FC3976F627B13FE81EABF2F7752BDC" = Pivot Collection Tool for Microsoft Office Excel
"09d972fdeb31eaa0" = WPF TA unit
"0c1129c2013fbb69" = Total Annihilation Redux
"1851220018.localhost" = TA3DUnit Application
"309a46b1dc89b774" = Dell Driver Download Manager
"3dc17cdbaba1d704" = A World At War
"662641322.localhost" = DarkReignSilverlight Application
"7832512e0f25051d" = Shazzam
"943480793.localhost" = DarkReignSilverlight Application
"d68d21f7865d637e" = Zam3D Test
"e870fb5d023e06e6" = WpfApplication_test
"f407565ed1458231" = WPF Flash Integration
"Google Chrome" = Google Chrome
"yFiles for Silverlight Complete 2.0 Programming Samples_is1" = yFiles for Silverlight Complete 2.0.0.1 Evaluation Programming
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 28/09/2011 3:50:02 PM | Computer Name = NEBULA | Source = Windows Search Service | ID = 3102
Description = The per-user filter pool for session 0 could not be added. Details:
The
operation being requested was not performed because the user has not logged on
to the network. The specified service does not exist. (0x800704dd) For more information
visit http://www.microsoft.com/servers/redirect/…ntredirect2.asp
Error - 28/09/2011 3:50:12 PM | Computer Name = NEBULA | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 28/09/2011 3:50:29 PM | Computer Name = NEBULA | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 3:52:30 PM | Computer Name = NEBULA | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 28/09/2011 4:30:56 PM | Computer Name = NEBULA | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog For more information visit http://www.microsoft.com/servers/redirect/…ntredirect2.asp
Error - 28/09/2011 5:39:25 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 5:39:25 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
[ OSession Events ]
Error - 22/10/2009 4:26:26 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18469
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 03/03/2010 3:33:43 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15426
seconds with 1980 seconds of active time. This session ended with a crash.
Error - 15/03/2010 1:55:51 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 268545
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 26/04/2010 11:45:07 AM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1235
seconds with 300 seconds of active time. This session ended with a crash.
Error - 24/11/2010 7:00:34 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28226
seconds with 2760 seconds of active time. This session ended with a crash.
Error - 06/01/2011 3:43:49 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16236
seconds with 600 seconds of active time. This session ended with a crash.
Error - 18/02/2011 11:47:21 AM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1831
seconds with 360 seconds of active time. This session ended with a crash.
Error - 02/05/2011 6:35:39 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 28440
seconds with 2280 seconds of active time. This session ended with a crash.
Error - 13/06/2011 3:38:39 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 16193
seconds with 1500 seconds of active time. This session ended with a crash.
Error - 15/09/2011 3:29:49 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 15842
seconds with 900 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%1058
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
nvraid
Error - 28/09/2011 3:56:24 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 3:57:22 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7034
Description = The LiveUpdate service terminated unexpectedly. It has done this
1 time(s).
Error - 28/09/2011 3:57:32 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 3:59:35 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 4:33:07 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 28/09/2011 4:33:21 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Microsoft Antimalware Service
service, but this action failed with the following error: %%1056
Error - 28/09/2011 4:38:28 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7034
Description = The LiveUpdate Notice Service service terminated unexpectedly. It
has done this 1 time(s).
< End of report >
Malwarebytes' Anti-Malware found a four issues and supposedly cleaned them:
Adware.DoubleD.Gen File
Malware.Trace File
Rogue.AntivirusSuite Registry Key
Trojan.Fraudpack Registry Key
Problems still persist, however. Any assistance would be greatly appreciated.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:42:12 PM, on 28/09/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32brsvc01a.exe
C:WINDOWSsystem32brss01a.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesSUPERAntiSpywareSASCORE.EXE
C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32FsUsbExService.Exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
c:Program FilesMicrosoft SQL Server90Sharedsqlwriter.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSsystem32SearchIndexer.exe
C:Program FilesTortoiseSVNbinTSVNCache.exe
C:WINDOWSCTHELPER.EXE
C:Program FilesCyberLinkPowerDVDDVDLauncher.exe
C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE
C:Program FilesCreativeShared FilesModule LoaderDLLML.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:WINDOWSSYSTEM32CTXFISPI.EXE
C:Program FilesMicrosoft Security Clientmsseces.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesPeerBlockpeerblock.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSsystem32taskmgr.exe
C:Program FilesiPodbiniPodService.exe
c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32notepad.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Program FilesTrend MicroHijackThisHiJackThis.exe
C:Documents and SettingsrlevereDesktopOTL.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.ca/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: CmjBrowserHelperObject Object - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:Program FilesMicrosoft Visual Studio 10.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderB
arBHO100.dll
O2 - BHO: Microsoft Web Test Recorder 9.0 Helper - {E31CE47F-C268-41ba-897B-B415E613947D} - C:Program FilesMicrosoft Visual Studio 9.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderBa
rBHO90.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM..Run: [DVDLauncher] "C:Program FilesCyberLinkPowerDVDDVDLauncher.exe"
O4 - HKLM..Run: [CTDVDDET] "C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE"
O4 - HKLM..Run: [VolPanel] "C:Program FilesCreativeSound Blaster X-FiVolume PanelVolPanel.exe" /r
O4 - HKLM..Run: [AudioDrvEmulator] "C:Program FilesCreativeShared FilesModule LoaderDLLML.exe" -1 AudioDrvEmulator "C:Program FilesCreativeShared FilesModule LoaderAudio EmulatorAudDrvEm.dll"
O4 - HKLM..Run: [ISUSPM Startup] "C:Program FilesCommon FilesInstallShieldUpdateServiceisuspm.exe" -startup
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [SignIn] "C:Program FilesMicrosoft Online ServicesSign InSignIn.exe" /autorun
O4 - HKLM..Run: [Communicator] "C:Program FilesMicrosoft Office Communicatorcommunicator.exe" /fromrunkey
O4 - HKLM..Run: [SetDefPrt] C:Program FilesBrotherBrmfl04aBrStDvPt.exe
O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe /autorun
O4 - HKLM..Run: [MSC] "c:Program FilesMicrosoft Security Clientmsseces.exe" -hide -runkey
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKCU..Run: [updateMgr] "C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [PeerBlock] C:Program FilesPeerBlockpeerblock.exe
O4 - HKCU..Run: [Google Update] "C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
O4 - HKUSS-1-5-18..RunOnce: [tscuninstall] %systemroot%system32tscupgrd.exe (User 'SYSTEM')
O4 - HKUS.DEFAULT..RunOnce: [tscuninstall] %systemroot%system32tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~4Office12EXCEL.EXE/3000
O8 - Extra context menu item: Edit with &XML; Spy - C:Program FilesAltovaxmlspyspy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~4Office12REFIEBAR.DLL
O9 - Extra button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSsystem32Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra button: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:Program FilesAltovaxmlspyspy.htm (HKCU)
O9 - Extra 'Tools' menuitem: Edit with XML Spy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:Program FilesAltovaxmlspyspy.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-30.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139683133703
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139683125296
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://pix.futureshop.ca/en/ImageUploader4.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.ca/downloads/BUM/B…_2/axofupld.cab
O16 - DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} (TWDownloader Class) - https://cpc.postecs.com/download/TWDownload.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} (ULcontrol Control) - https://pix.futureshop.ca/en/ulcontrolxp.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSoftware..Telephony: DomainName = fedgrid.local
O17 - HKLMSystemCS1ServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSystemCS3ServicesTcpipParameters: Domain = fedgrid.local
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:Program FilesTrend MicroTrendProtectMSIEwrs.dll
O20 - Winlogon Notify: !SASWinLogon - C:Program FilesSUPERAntiSpywareSASWINLO.DLL
O20 - Winlogon Notify: GoToAssist - C:Program FilesCitrixGoToAssist516G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWSsystem32browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWSsystem32browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:Program FilesSUPERAntiSpywareSASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: ANTS Memory Profiler 5 Service - Red Gate Software Ltd. - C:Program FilesRed GateANTS Memory Profiler 5RedGate.Memory.IISService.exe
O23 - Service: ANTS Performance Profiler 5 Service - Red Gate Software Ltd. - C:Program FilesRed GateANTS Performance Profiler 5RedGate.Profiler.IISService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:WINDOWSsystem32Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:WINDOWSsystem32brsvc01a.exe
O23 - Service: FLEXlm License Manager - Unknown owner - C:Program FilesCommon FilesAlias Sharedlicensingetclmgrd.exe (file missing)
O23 - Service: FsUsbExService - Teruten - C:WINDOWSsystem32FsUsbExService.Exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:Program FilesCitrixGoToAssist516g2aservice.exe
O23 - Service: Groove Audit Service (GrooveAuditService) - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveAuditService.exe
O23 - Service: Groove Installer Service (GrooveInstallerService) - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveInstallerService.exe
O23 - Service: GrooveRunOnceInstaller - Groove Networks, Inc. - C:Program FilesGroove NetworksGrooveBinGrooveRunOnceInstaller.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:Program FilesLavasoftAd-AwareAAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: Tryst Lobby Service - Unknown owner - C:Documents and SettingsrlevereMy DocumentsVisual Studio 2005ProjectsTrystServerTrystLobbyServicebinDebugTrystLobbyService.exe
–
End of file - 14152 bytes
Ran OTL, as well. There's an awful lot of entries in the hosts file that shouldn't be there…
Here's OTL.txt (Extras.txt to follow):
OTL logfile created on: 28/09/2011 2:31:38 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:Documents and SettingsrlevereDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.23% Memory free
3.84 Gb Paging File | 2.76 Gb Available in Paging File | 71.82% Paging File free
Paging file location(s): c:pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.78 Gb Total Space | 60.11 Gb Free Space | 25.82% Space Free | Partition Type: NTFS
Computer Name: NEBULA | User Name: rlevere | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:Documents and SettingsrlevereDesktopOTL.exe (OldTimer Tools)
PRC - C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)
PRC - C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:Program FilesSUPERAntiSpywareSASCore.exe (SUPERAntiSpyware.com)
PRC - C:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
PRC - c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe (Microsoft Corporation)
PRC - C:Program FilesPeerBlockpeerblock.exe (PeerBlock, LLC)
PRC - C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
PRC - C:Program FilesTortoiseSVNbinTSVNCache.exe (http://tortoisesvn.net)
PRC - C:Program FilesTrend MicroHijackThisHiJackThis.exe (Trend Micro Inc.)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
PRC - C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe (Symantec Corporation)
PRC - C:WINDOWSsystem32CTXFISPI.EXE (Creative Technology Ltd)
PRC - C:WINDOWSCTHELPER.EXE (Creative Technology Ltd)
PRC - C:Program FilesCreativeShared FilesModule LoaderDLLML.exe (Creative Technology Ltd.)
PRC - C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10007.dll ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10006.dll ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSUIREPAIR.DLL ()
MOD - C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.comSUPERAntiSpywareSDDLLSSD10005.dll ()
MOD - C:Program FilesMozilla Firefoxmozjs.dll ()
MOD - C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
MOD - C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll ()
MOD - C:WINDOWSsystem32quartz.dll ()
MOD - C:WINDOWSsystem32msdmo.dll ()
MOD - C:WINDOWSsystem32devenum.dll ()
MOD - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
MOD - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcnet.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (FLEXlm License Manager) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:Program FilesLavasoftAd-AwareAAWService.exe (Lavasoft Limited)
SRV - (!SASCORE) – C:Program FilesSUPERAntiSpywareSASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MsMpSvc) – c:Program FilesMicrosoft Security ClientAntimalwareMsMpEng.exe (Microsoft Corporation)
SRV - (FsUsbExService) – C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
SRV - (ANTS Performance Profiler 5 Service) – C:Program FilesRed GateANTS Performance Profiler 5RedGate.Profiler.IISService.exe (Red Gate Software Ltd.)
SRV - (ANTS Memory Profiler 5 Service) – C:Program FilesRed GateANTS Memory Profiler 5RedGate.Memory.IISService.exe (Red Gate Software Ltd.)
SRV - (msvsmon90) – C:Program FilesMicrosoft Visual Studio 9.0Common7IDERemote Debuggerx86msvsmon.exe (Microsoft Corporation)
SRV - (Tryst Lobby Service) – C:Documents and SettingsrlevereMy DocumentsVisual Studio 2005ProjectsTrystServerTrystLobbyServicebinDebugTrystLobbyService.exe ()
SRV - (GoToAssist) – C:Program FilesCitrixGoToAssist516g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (Symantec Core LC) – C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe (Symantec Corporation)
SRV - (msvsmon80) – C:Program FilesMicrosoft Visual Studio 8Common7IDERemote Debuggerx86msvsmon.exe (Microsoft Corporation)
SRV - (LiveUpdate) – C:Program FilesSymantecLiveUpdateLuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe (Symantec Corporation)
SRV - (GrooveInstallerService) – C:Program FilesGroove NetworksGrooveBinGrooveInstallerService.exe (Groove Networks, Inc.)
SRV - (GrooveRunOnceInstaller) – C:Program FilesGroove NetworksGrooveBinGrooveRunOnceInstaller.exe (Groove Networks, Inc.)
SRV - (GrooveAuditService) – C:Program FilesGroove NetworksGrooveBinGrooveAuditService.exe (Groove Networks, Inc.)
SRV - (brmfrmps) – C:WINDOWSSystem32Brmfrmps.exe (Brother Industries, Ltd.)
========== Driver Services (SafeList) ==========
DRV - (MpKslae183b29) – c:Documents and SettingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{93AA71BB-DCFF-4AA3-88F8-87AD97F1BBE2}MpKslae183b29.sys (Microsoft Corporation)
DRV - (MpKsl6a050b33) – c:Documents and SettingsAll UsersApplication DataMicrosoftMicrosoft AntimalwareDefinition Updates{93AA71BB-DCFF-4AA3-88F8-87AD97F1BBE2}MpKsl6a050b33.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:Program FilesSUPERAntiSpywaresasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:Program FilesSUPERAntiSpywareSASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:WINDOWSsystem32DRIVERSLbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:Program FilesLavasoftAd-Awarekernexplorer.sys ()
DRV - (VSPerfDrv100) – C:Program FilesMicrosoft Visual Studio 10.0Team ToolsPerformance ToolsVSPerfDrv100.sys (Microsoft Corporation)
DRV - (pbfilter) – C:Program FilesPeerBlockpbfilter.sys ()
DRV - (StarOpen) – C:WINDOWSSystem32driversStarOpen.sys ()
DRV - (FsUsbExDisk) – C:WINDOWSsystem32FsUsbExDisk.Sys ()
DRV - (ss_mdm) – C:WINDOWSsystem32driversss_mdm.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) – C:WINDOWSsystem32driversss_bus.sys (MCCI Corporation)
DRV - (ss_mdfl) – C:WINDOWSsystem32driversss_mdfl.sys (MCCI Corporation)
DRV - (RsFx0103) – C:WINDOWSsystem32driversRsFx0103.sys (Microsoft Corporation)
DRV - (VSPerfDrv90) – C:Program FilesMicrosoft Visual Studio 9.0Team ToolsPerformance ToolsVSPerfDrv90.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (DITOUSB) – C:WINDOWSsystem32driversDITOUSB.sys (Nintendo Co.,Ltd.)
DRV - (EXITOUSB) – C:WINDOWSsystem32driversEXITOUSB.sys (Nintendo Co., Ltd.)
DRV - (dtscsi) – C:WINDOWSSystem32Driversdtscsi.sys (DT Soft Ltd.)
DRV - (sptd) – C:WINDOWSSystem32Driverssptd.sys (Duplex Secure Ltd.)
DRV - (symlcbrd) – C:WINDOWSsystem32driverssymlcbrd.sys (Symantec Corporation)
DRV - (ASCTRM) – C:WINDOWSSystem32driversasctrm.sys (Windows ® 2000 DDK provider)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:WINDOWSsystem32driversctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:WINDOWSsystem32driversctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – C:WINDOWSsystem32driversha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:WINDOWSsystem32driversctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:WINDOWSsystem32driversctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:WINDOWSsystem32driversemupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:WINDOWSsystem32driversctac32k.sys (Creative Technology Ltd)
DRV - (nvnetbus) – C:WINDOWSsystem32driversnvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:WINDOWSsystem32driversNVENETFD.sys (NVIDIA Corporation)
DRV - (nvatabus) – C:WINDOWSsystem32driversnvatabus.sys (NVIDIA Corporation)
DRV - (ctdvda2k) – C:WINDOWSsystem32driversctdvda2k.sys (Creative Technology Ltd)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = %SystemRoot%system32blank.htm
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar =
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page =
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.ca/
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.type: 0
FF - [removed]/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/iTunes,version=: File not found
FF - [removed]/iTunes,version=1.0: C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()
FF - [removed]/DivX Browser Plugin,version=1.0.0: C:Program FilesDivXDivX Web Playernpdivx32.dll (DivX,Inc.)
FF - [removed]/DivX Player Plugin,version=1.0.0: C:Program FilesDivXDivX PlayernpDivxPlayerPlugin.dll (DivX, Inc)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.0.60401.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/wpi,version=1.0: C:Program FilesMicrosoftWeb Platform Installernpwpidetector.dll ()
FF - [removed]/VMP: C:Program FilesViewpointViewpoint Experience TechnologynpViewpoint.dll ()
FF - [removed]/Google Update;version=3: C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Documents and SettingsrlevereLocal SettingsApplication DataGoogleUpdate1.3.21.69npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 7.0extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/09/28 08:06:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 7.0extensionsPlugins: C:Program FilesMozilla Firefoxplugins
[2010/06/30 11:34:44 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsrlevereApplication DataMozillaExtensions
[2011/03/22 09:31:03 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsrlevereApplication DataMozillaFirefoxProfilesrwoyinyc.defaultextensions
[2010/07/02 08:27:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:Documents and SettingsrlevereApplication DataMozillaFirefoxProfilesrwoyinyc.defaultextensions{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/28 11:27:55 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2011/09/28 08:05:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2011/06/22 07:59:34 | 000,002,252 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsbing.xml
O1 HOSTS File: ([2010/06/29 16:16:49 | 000,408,553 | R— | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14129 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (CmjBrowserHelperObject Object) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll (Mindjet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll (Groove Networks, Inc.)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:Program FilesMicrosoft Visual Studio 10.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderB
arBHO100.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Web Test Recorder 9.0 Helper) - {E31CE47F-C268-41ba-897B-B415E613947D} - C:Program FilesMicrosoft Visual Studio 9.0Common7IDEPrivateAssembliesMicrosoft.VisualStudio.QualityTools.RecorderBa
rBHO90.dll (Microsoft Corporation)
O2 - BHO: (BhoMisc Class) - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O3 - HKLM..Toolbar: (TrendProtect) - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O3 - HKCU..ToolbarWebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU..ToolbarWebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..Run: [AudioDrvEmulator] C:Program FilesCreativeShared FilesModule LoaderDLLML.exe (Creative Technology Ltd.)
O4 - HKLM..Run: [Communicator] C:Program FilesMicrosoft Office Communicatorcommunicator.exe (Microsoft Corporation)
O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..Run: [CTDVDDET] C:Program FilesCreativeSound Blaster X-FiDVDAudioCTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [CTHelper] C:WINDOWSCTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [CTxfiHlp] C:WINDOWSSystem32CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..Run: [DAEMON Tools] C:Program FilesDAEMON Toolsdaemon.exe (DT Soft Ltd.)
O4 - HKLM..Run: [MSC] c:Program FilesMicrosoft Security Clientmsseces.exe (Microsoft Corporation)
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..Run: [NPSStartup] File not found
O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..Run: [SetDefPrt] C:Program FilesBrotherBrmfl04aBrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..Run: [SignIn] C:Program FilesMicrosoft Online ServicesSign InSignIn.exe (Microsoft Corporation)
O4 - HKLM..Run: [Symantec PIF AlertEng] C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe (Symantec Corporation)
O4 - HKLM..Run: [VolPanel] C:Program FilesCreativeSound Blaster X-FiVolume PanelVolPanel.exe (Creative Technology Ltd)
O4 - HKCU..Run: [PeerBlock] C:Program FilesPeerBlockpeerblock.exe (PeerBlock, LLC)
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..Run: [updateMgr] C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe (Adobe Systems Incorporated)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O7 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRecovery present
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = -1
O8 - Extra context menu item: Edit with &XML; Spy - C:Program FilesAltovaxmlspyspy.htm ()
O9 - Extra Button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:Program FilesMindjetMindManager 7Mm7InternetExplorer.dll (Mindjet)
O10 - NameSpace_Catalog5Catalog_Entries\000000000004 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O15 - HKLM..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU..Trusted Domains: livemeeting.com ([]https in Internet)
O15 - HKCU..Trusted Domains: microsoftonline.com ([]https in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB (TmHcmsX Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-30.cab (EPUImageControl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1139683133703 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1139683125296 (MUWebControl Class)
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} http://pix.futureshop.ca/en/ImageUploader4.cab (Image Uploader Control)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.ca/downloads/BUM/B…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} https://cpc.postecs.com/download/TWDownload.cab (TWDownloader Class)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab (DLC Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} https://pix.futureshop.ca/en/ulcontrolxp.cab (ULcontrol Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.20 192.168.1.50
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = fedgrid.local
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{1D7F33C9-9706-4280-9FBB-16D5D2D6A1D5}: DhcpNameServer = 192.168.1.20 192.168.1.50
O18 - ProtocolHandlertrendprotect {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:Program FilesTrend MicroTrendProtectMSIEWRS.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) -C:WINDOWSsystem32userinit.exe (Microsoft Corporation)
O20 - WinlogonNotify!SASWinLogon: DllName - (C:Program FilesSUPERAntiSpywareSASWINLO.DLL) - C:Program FilesSUPERAntiSpywareSASWINLO.DLL (SUPERAntiSpyware.com)
O20 - WinlogonNotifyGoToAssist: DllName - (C:Program FilesCitrixGoToAssist516G2AWinLogon.dll) - C:Program FilesCitrixGoToAssist516g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:Documents and SettingsrlevereLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsrlevereLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:Program FilesWindows Desktop SearchMSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:Program FilesSUPERAntiSpywareSASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesGroove NetworksGrooveBinGrooveShellExtensions.dll (Groove Networks, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/12 08:19:23 | 000,000,000 | —D | M] - C:Autodesk – [ NTFS ]
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | —- | M] () - C:AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}Shell - "" = AutoRun
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}ShellAutoRun - "" = Auto&Play;
O33 - MountPoints2{9618b421-f8cb-11db-b024-00142246cdcf}ShellAutoRuncommand - "" = G:LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:WINDOWSSystem32ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:WINDOWSsystem32iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:WINDOWSSystem32lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:WINDOWSSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:WINDOWSSystem32DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:WINDOWSSystem32ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:WINDOWSSystem32frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv41 - C:WINDOWSSystem32ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:WINDOWSSystem32ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:WINDOWSSystem32xvidvfw.dll ()
Drivers32: vidc.yv12 - C:WINDOWSSystem32yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/28 14:29:10 | 000,582,656 | —- | C] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 11:07:58 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataSUPERAntiSpyware.com
[2011/09/28 11:07:26 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsSUPERAntiSpyware
[2011/09/28 11:07:21 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.com
[2011/09/28 11:07:21 | 000,000,000 | —D | C] – C:Program FilesSUPERAntiSpyware
[2011/09/28 11:06:06 | 012,609,096 | —- | C] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
[2011/09/28 11:00:54 | 001,548,080 | —- | C] (Kaspersky Lab ZAO) – C:Documents and SettingsrlevereDesktoprkill2.scr
[2011/09/28 10:11:53 | 000,000,000 | —D | C] – C:rsit
[2011/09/28 09:23:21 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereStart MenuProgramsCleanUp!
[2011/09/28 09:23:13 | 000,000,000 | —D | C] – C:Program FilesCleanUp!
[2011/09/23 14:32:12 | 000,000,000 | —D | C] – C:CartBlanche-MonoGame-Samples-9f88fbf
[2011/09/23 10:24:29 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereLocal SettingsApplication DataXamarin
[2011/09/23 10:23:40 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereMy DocumentsProjects
[2011/09/23 09:53:22 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication Datastetic
[2011/09/23 09:52:49 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataMonoDevelop-2.6
[2011/09/23 09:52:37 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereLocal SettingsApplication DataMonoDevelop-2.6
[2011/09/23 09:52:31 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereApplication DataMonoDevelop
[2011/09/22 14:56:29 | 000,000,000 | —D | C] – C:Documents and SettingsrlevereStart MenuProgramsMonoDevelop
[2011/09/22 14:56:19 | 000,000,000 | —D | C] – C:Program FilesMonoDevelop
[2011/09/22 14:54:05 | 000,000,000 | —D | C] – C:Program FilesGtkSharp
[2011/09/22 13:10:32 | 000,000,000 | —D | C] – C:Documents and Settingsrlevere.android
[2011/09/22 13:10:20 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsAndroid SDK Tools
[2011/09/22 13:10:12 | 000,000,000 | —D | C] – C:Android
[2011/09/12 09:04:01 | 000,139,656 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcacherdpwd.sys
[2011/09/12 08:47:52 | 000,010,496 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachendistapi.sys
[2011/09/03 03:17:37 | 000,599,040 | —- | C] (Microsoft Corporation) – C:WINDOWSSystem32dllcachecrypt32.dll
[2006/03/07 16:50:52 | 000,380,928 | —- | C] ( ) – C:WINDOWSSystem32csgl.dll
[2006/02/01 01:50:04 | 000,033,792 | —- | C] ( ) – C:WINDOWSSystem32a3d.dll
[2006/02/01 01:50:04 | 000,009,216 | —- | C] ( ) – C:WINDOWSSystem32KILLAPPS.EXE
[55 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/28 14:37:35 | 000,002,451 | —- | M] () – C:Documents and SettingsrlevereDesktopHiJackThis.lnk
[2011/09/28 14:29:20 | 000,582,656 | —- | M] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 14:00:04 | 000,000,986 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-2509836690-573628217-1654637295-1006UA.job
[2011/09/28 13:38:38 | 000,000,424 | -H– | M] () – C:WINDOWStasksMP Scheduled Scan.job
[2011/09/28 12:52:30 | 000,029,204 | —- | M] () – C:WINDOWSSystem32nvapps.xml
[2011/09/28 12:52:24 | 000,013,668 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2011/09/28 12:51:24 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2011/09/28 12:51:21 | 2144,899,072 | -HS- | M] () – C:hiberfil.sys
[2011/09/28 12:48:06 | 000,064,988 | —- | M] () – C:WINDOWSSystem32DVCState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,054,672 | —- | M] () – C:WINDOWSSystem32BMXStateBkp-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,054,672 | —- | M] () – C:WINDOWSSystem32BMXState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx
[2011/09/28 12:48:06 | 000,001,080 | —- | M] () – C:WINDOWSSystem32settingsbkup.sfm
[2011/09/28 12:48:06 | 000,001,080 | —- | M] () – C:WINDOWSSystem32settings.sfm
[2011/09/28 12:44:59 | 000,000,064 | —- | M] () – C:WINDOWSSystem32rp_stats.dat
[2011/09/28 12:44:59 | 000,000,044 | —- | M] () – C:WINDOWSSystem32rp_rules.dat
[2011/09/28 12:44:07 | 000,000,472 | —- | M] () – C:WINDOWStasksAd-Aware Update (Weekly).job
[2011/09/28 12:43:17 | 000,026,112 | —- | M] (Microsoft Corporation) – C:WINDOWSSystem32userinit.exe
[2011/09/28 11:56:59 | 000,000,815 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Internet Explorer Browser.lnk
[2011/09/28 11:07:26 | 000,001,678 | —- | M] () – C:Documents and SettingsAll UsersDesktopSUPERAntiSpyware Free Edition.lnk
[2011/09/28 11:06:47 | 012,609,096 | —- | M] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
[2011/09/28 11:03:50 | 000,000,335 | —- | M] () – C:Documents and SettingsrlevereDesktopFixExe.reg
[2011/09/28 11:03:29 | 001,008,092 | —- | M] () – C:Documents and SettingsrlevereDesktoprkill.scr
[2011/09/28 11:01:17 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:Documents and SettingsrlevereDesktoprkill2.scr
[2011/09/28 09:37:25 | 000,039,965 | —- | M] () – C:Documents and SettingsrlevereDesktopDocument.rtf
[2011/09/28 09:07:57 | 000,377,919 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication Datacensus.cache
[2011/09/28 09:07:05 | 000,320,349 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication Dataars.cache
[2011/09/28 05:42:28 | 000,000,664 | —- | M] () – C:WINDOWSSystem32d3d9caps.dat
[2011/09/27 16:00:02 | 000,000,934 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskUserS-1-5-21-2509836690-573628217-1654637295-1006Core.job
[2011/09/23 10:22:05 | 000,000,218 | —- | M] () – C:Documents and Settingsrlevere.recently-used.xbel
[2011/09/20 16:01:56 | 000,002,300 | —- | M] () – C:Documents and SettingsrlevereDesktopGoogle Chrome.lnk
[2011/09/13 07:59:39 | 000,309,992 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2011/09/12 19:23:10 | 000,001,374 | —- | M] () – C:WINDOWSimsins.BAK
[2011/09/12 18:58:21 | 000,599,266 | —- | M] () – C:WINDOWSSystem32perfh009.dat
[2011/09/12 18:58:21 | 000,125,500 | —- | M] () – C:WINDOWSSystem32perfc009.dat
[2011/09/12 15:43:40 | 000,001,945 | —- | M] () – C:WINDOWSepplauncher.mif
[2011/09/12 10:52:37 | 000,000,038 | —- | M] () – C:WINDOWSavisplitter.INI
[2011/09/12 09:25:31 | 000,205,312 | —- | M] () – C:Documents and SettingsrlevereLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/03 03:17:37 | 000,599,040 | —- | M] (Microsoft Corporation) – C:WINDOWSSystem32dllcachecrypt32.dll
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:WINDOWSSystem32driversmbam.sys
[55 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/28 11:07:26 | 000,001,678 | —- | C] () – C:Documents and SettingsAll UsersDesktopSUPERAntiSpyware Free Edition.lnk
[2011/09/28 11:03:50 | 000,000,335 | —- | C] () – C:Documents and SettingsrlevereDesktopFixExe.reg
[2011/09/28 11:03:26 | 001,008,092 | —- | C] () – C:Documents and SettingsrlevereDesktoprkill.scr
[2011/09/28 09:37:25 | 000,039,965 | —- | C] () – C:Documents and SettingsrlevereDesktopDocument.rtf
[2011/09/28 09:07:57 | 000,377,919 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datacensus.cache
[2011/09/28 09:07:05 | 000,320,349 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Dataars.cache
[2011/09/23 10:22:05 | 000,000,218 | —- | C] () – C:Documents and Settingsrlevere.recently-used.xbel
[2011/09/12 15:48:32 | 000,000,424 | -H– | C] () – C:WINDOWStasksMP Scheduled Scan.job
[2011/07/03 09:02:22 | 000,000,064 | —- | C] () – C:WINDOWSSystem32rp_stats.dat
[2011/07/03 09:02:22 | 000,000,044 | —- | C] () – C:WINDOWSSystem32rp_rules.dat
[2011/05/20 10:25:35 | 000,014,673 | —- | C] () – C:WINDOWSFace.INI
[2011/05/20 10:25:33 | 000,000,026 | —- | C] () – C:WINDOWSLayout2.INI
[2011/05/20 10:01:25 | 000,000,316 | —- | C] () – C:WINDOWSSoftWriting.ini
[2011/01/03 14:25:23 | 000,000,051 | —- | C] () – C:WINDOWSbrmx2001.ini
[2010/09/21 11:27:57 | 000,000,038 | —- | C] () – C:WINDOWSavisplitter.INI
[2010/08/23 14:38:25 | 000,000,034 | -H– | C] () – C:WINDOWSSystem32Converter_sysquict.dat
[2010/08/23 14:37:06 | 000,755,027 | —- | C] () – C:WINDOWSSystem32xvidcore.dll
[2010/08/23 14:37:05 | 000,159,839 | —- | C] () – C:WINDOWSSystem32xvidvfw.dll
[2010/08/23 14:37:04 | 000,007,680 | —- | C] () – C:WINDOWSSystem32ff_vfw.dll
[2010/08/23 09:55:00 | 000,036,608 | —- | C] () – C:WINDOWSSystem32FsUsbExDisk.Sys
[2010/08/23 09:54:59 | 000,110,592 | —- | C] () – C:WINDOWSSystem32FsUsbExDevice.Dll
[2010/08/23 09:54:39 | 000,002,528 | —- | C] () – C:Documents and SettingsrlevereApplication Data$_hpcst$.hpc
[2010/08/23 08:48:46 | 000,000,000 | —- | C] () – C:Documents and SettingsAll UsersApplication DataLauncherAccess.dt
[2010/08/23 08:38:51 | 000,005,632 | —- | C] () – C:WINDOWSSystem32driversStarOpen.sys
[2010/07/09 12:08:17 | 000,165,376 | —- | C] () – C:WINDOWSSystem32unrar.dll
[2010/07/08 14:50:43 | 003,525,264 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.0.0.dat
[2010/07/08 08:34:52 | 000,000,000 | —- | C] () – C:WINDOWSbrdfxspd.dat
[2010/07/02 17:00:42 | 000,000,036 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datahousecall.guid.cache
[2010/06/10 09:29:48 | 000,000,000 | —- | C] () – C:WINDOWSBrownie.ini
[2010/06/10 08:58:24 | 000,000,030 | —- | C] () – C:WINDOWSSystem32brss01a.ini
[2010/06/10 08:57:20 | 000,000,234 | —- | C] () – C:WINDOWSBrpfx04a.ini
[2010/06/10 08:57:20 | 000,000,092 | —- | C] () – C:WINDOWSbrpcfx.ini
[2010/06/10 08:57:20 | 000,000,050 | —- | C] () – C:WINDOWSSystem32BRIDF04A.dat
[2010/04/19 14:09:12 | 008,648,370 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-2509836690-573628217-1654637295-1006-0.dat
[2010/04/19 14:09:09 | 000,310,458 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-System.dat
[2010/04/02 18:17:34 | 000,179,091 | —- | C] () – C:WINDOWSSystem32xlive.dll.cat
[2009/07/02 11:54:55 | 000,000,212 | —- | C] () – C:WINDOWSildasmfnt.bin
[2008/09/16 12:16:45 | 000,000,034 | —- | C] () – C:WINDOWSSystem32BD7220.DAT
[2008/07/17 16:07:43 | 000,000,000 | —- | C] () – C:WINDOWSSAFEEDIT.INI
[2008/07/17 16:07:25 | 000,000,000 | —- | C] () – C:WINDOWSUBEEDIT.INI
[2008/04/11 15:56:00 | 000,119,503 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datadebuggee.mdmp
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:WINDOWSSystem32OGACheckControl.DLL
[2007/11/08 11:53:15 | 000,000,231 | —- | C] () – C:WINDOWSSystem323dsmax.ini
[2007/11/08 11:53:15 | 000,000,043 | —- | C] () – C:WINDOWSSystem32InstallSettings.ini
[2007/09/19 13:58:46 | 000,000,664 | —- | C] () – C:WINDOWSSystem32d3d9caps.dat
[2007/06/22 10:08:15 | 000,000,000 | —- | C] () – C:WINDOWSpcfriend.INI
[2007/06/20 08:35:02 | 000,077,312 | —- | C] () – C:WINDOWSua2.dll
[2007/06/01 12:44:57 | 000,000,000 | —- | C] () – C:WINDOWSZillions.INI
[2007/05/17 14:23:31 | 000,000,079 | —- | C] () – C:WINDOWSBRPP2KA.INI
[2007/05/17 08:40:54 | 000,000,419 | —- | C] () – C:WINDOWSBRWMARK.INI
[2007/03/06 12:21:25 | 000,016,384 | —- | C] () – C:WINDOWSSystem32FileOps.exe
[2006/12/04 12:46:59 | 000,060,236 | -H– | C] () – C:WINDOWSSystem32mlfcache.dat
[2006/11/22 11:55:52 | 000,000,221 | —- | C] () – C:WINDOWSSOFTEK.INI
[2006/11/22 11:53:18 | 000,050,176 | —- | C] () – C:WINDOWSSystem32annihilator.dll
[2006/11/22 11:53:18 | 000,046,592 | —- | C] () – C:WINDOWSSystem323dobuilder.dll
[2006/11/20 15:10:48 | 000,000,307 | —- | C] () – C:WINDOWSCaligari.ini
[2006/09/29 12:32:42 | 000,000,049 | —- | C] () – C:WINDOWSNeroDigital.ini
[2006/09/01 08:55:18 | 002,314,104 | —- | C] () – C:Program FilesPaint Shop Pro.zip
[2006/07/11 08:02:06 | 000,003,350 | -HS- | C] () – C:WINDOWSSystem32KGyGaAvL.sys
[2006/06/05 13:19:58 | 000,000,479 | —- | C] () – C:WINDOWSeReg.dat
[2006/05/18 08:15:19 | 000,000,754 | —- | C] () – C:WINDOWSWORDPAD.INI
[2006/05/17 12:01:21 | 000,004,103 | —- | C] () – C:WINDOWSPTMAYAIO.INI
[2006/05/17 11:59:26 | 000,000,263 | —- | C] () – C:WINDOWSui_bitmapviewer.ini
[2006/05/17 11:58:59 | 000,007,536 | —- | C] () – C:WINDOWSPOLYTRAN.INI
[2006/05/08 15:32:29 | 000,077,824 | —- | C] () – C:WINDOWSSystem32prtiutil.dll
[2006/05/08 15:32:29 | 000,028,672 | —- | C] () – C:WINDOWSSystem32hirestimer.dll
[2006/04/25 15:17:37 | 000,001,176 | —- | C] () – C:WINDOWS_ISENV31.INI
[2006/04/24 12:44:42 | 000,083,968 | —- | C] () – C:WINDOWSSystem32structuredqueryschema.bin
[2006/04/24 12:44:42 | 000,011,776 | —- | C] () – C:WINDOWSSystem32structuredqueryschematrivial.bin
[2006/04/18 15:48:14 | 000,020,714 | —- | C] () – C:WINDOWSSystem32idxcntrs.ini
[2006/04/18 15:47:46 | 000,037,532 | —- | C] () – C:WINDOWSSystem32gsrvctr.ini
[2006/04/18 15:47:40 | 000,031,698 | —- | C] () – C:WINDOWSSystem32gthrctr.ini
[2006/04/18 15:47:30 | 000,005,044 | —- | C] () – C:WINDOWSSystem32pqsperf.ini
[2006/04/18 15:30:56 | 003,596,288 | —- | C] () – C:WINDOWSSystem32qt-dx331.dll
[2006/04/18 15:30:13 | 000,536,576 | —- | C] () – C:WINDOWSSystem32DivXsm.exe
[2006/03/29 14:06:31 | 000,122,025 | —- | C] () – C:Documents and SettingsrlevereApplication Datadebuggee.mdmp
[2006/03/21 17:38:42 | 000,012,288 | —- | C] () – C:WINDOWSSystem32DivXWMPExtType.dll
[2006/03/11 13:10:51 | 001,280,640 | —- | C] () – C:Documents and SettingsLocalServiceLocal SettingsApplication DataFontCache3.0.51116.0.dat
[2006/03/07 16:50:52 | 000,021,504 | —- | C] () – C:WINDOWSSystem32csgl.native.dll
[2006/03/07 09:31:12 | 000,001,359 | —- | C] () – C:Documents and SettingsAll UsersApplication DataQTSBandwidthCache
[2006/03/02 14:00:11 | 000,000,002 | —- | C] () – C:WINDOWSmsoffice.ini
[2006/03/02 13:55:58 | 000,061,678 | —- | C] () – C:Documents and SettingsrlevereApplication DataPFP120JPR.{PB
[2006/03/02 13:55:58 | 000,012,358 | —- | C] () – C:Documents and SettingsrlevereApplication DataPFP120JCM.{PB
[2006/02/15 11:54:31 | 000,000,130 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication Datafusioncache.dat
[2006/02/14 13:45:40 | 000,000,056 | RHS- | C] () – C:WINDOWSSystem32\0D2D1C87A6.sys
[2006/02/14 09:09:42 | 000,205,312 | —- | C] () – C:Documents and SettingsrlevereLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/02/11 11:13:40 | 000,000,520 | —- | C] () – C:WINDOWSODBC.INI
[2006/02/01 02:18:49 | 000,000,061 | —- | C] () – C:WINDOWSsmscfg.ini
[2006/02/01 02:10:03 | 000,149,504 | —- | C] () – C:WINDOWSUNWISE.EXE
[2006/02/01 02:07:24 | 000,000,138 | —- | C] () – C:WINDOWSwininit.ini
[2006/02/01 02:04:39 | 000,000,335 | —- | C] () – C:WINDOWSnsreg.dat
[2006/02/01 01:50:04 | 000,366,041 | —- | C] () – C:WINDOWSSystem32ctdlang.dat
[2006/02/01 01:50:04 | 000,313,207 | —- | C] () – C:WINDOWSSystem32ctstatic.dat
[2006/02/01 01:50:04 | 000,265,066 | —- | C] () – C:WINDOWSSystem32CTSBAS2W.DAT
[2006/02/01 01:50:04 | 000,231,821 | —- | C] () – C:WINDOWSSystem32CTSBASW.DAT
[2006/02/01 01:50:04 | 000,140,643 | —- | C] () – C:WINDOWSSystem32CTBAS2W.DAT
[2006/02/01 01:50:04 | 000,113,221 | —- | C] () – C:WINDOWSSystem32CTBASICW.DAT
[2006/02/01 01:50:04 | 000,053,932 | —- | C] () – C:WINDOWSSystem32ctdaught.dat
[2006/02/01 01:50:04 | 000,049,274 | —- | C] () – C:WINDOWSSystem32claptn32.ini
[2006/02/01 01:50:04 | 000,038,400 | —- | C] () – C:WINDOWSSystem32CTBURST.DLL
[2006/02/01 01:50:04 | 000,034,304 | —- | C] () – C:WINDOWSPSCONV.EXE
[2006/02/01 01:50:04 | 000,033,792 | —- | C] () – C:WINDOWSSystem32REGPLIB.EXE
[2006/02/01 01:50:04 | 000,000,194 | —- | C] () – C:WINDOWSSystem32KILL.INI
[2006/02/01 01:50:04 | 000,000,055 | —- | C] () – C:WINDOWSSystem32ctzapxx.ini
[2006/02/01 01:49:32 | 000,049,152 | —- | C] () – C:WINDOWSsetpwrcg.exe
[2006/02/01 01:49:20 | 000,000,292 | —- | C] () – C:WINDOWSSystem32OEMINFO.INI
[2005/12/06 03:35:32 | 000,417,792 | R— | C] () – C:WINDOWSSystem32XmlSpyLib.dll
[2005/06/18 08:00:52 | 000,070,018 | —- | C] () – C:WINDOWSSystem32akrip32.dll
[2005/06/14 10:01:48 | 000,241,664 | —- | C] () – C:WINDOWSSystem32freeglut.dll
[2005/04/14 20:57:02 | 000,037,376 | —- | C] () – C:WINDOWSSystem32glfw.dll
[2005/04/02 17:26:20 | 000,338,944 | —- | C] () – C:WINDOWSSystem32lffpx7.dll
[2005/04/02 17:26:20 | 000,118,784 | —- | C] () – C:WINDOWSSystem32lfkodak.dll
[2005/01/07 15:21:18 | 000,135,168 | —- | C] () – C:WINDOWSSystem32SDL_gfx.dll
[2004/12/15 23:15:10 | 000,348,160 | —- | C] () – C:WINDOWSSystem32SDL_ttf.dll
[2004/12/15 23:01:46 | 000,169,443 | —- | C] () – C:WINDOWSSystem32jpeg.dll
[2004/12/15 23:01:46 | 000,126,976 | —- | C] () – C:WINDOWSSystem32libpng13.dll
[2004/12/15 23:01:46 | 000,055,808 | —- | C] () – C:WINDOWSSystem32zlib1.dll
[2004/12/15 23:01:46 | 000,040,960 | —- | C] () – C:WINDOWSSystem32SDL_image.dll
[2004/12/15 22:05:56 | 000,315,392 | —- | C] () – C:WINDOWSSystem32SDL_mixer.dll
[2004/12/15 18:24:14 | 000,237,568 | —- | C] () – C:WINDOWSSystem32SDL.dll
[2004/12/01 19:34:46 | 000,000,716 | -H– | C] () – C:Documents and SettingsAll UsersApplication Datapb7msys.dat
[2004/08/10 12:12:05 | 000,000,780 | —- | C] () – C:WINDOWSorun32.ini
[2004/08/10 12:07:31 | 000,002,048 | –S- | C] () – C:WINDOWSbootstat.dat
[2004/08/10 12:02:15 | 000,023,348 | —- | C] () – C:WINDOWSSystem32emptyregdb.dat
[2004/08/10 12:01:18 | 000,001,793 | —- | C] () – C:WINDOWSSystem32fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | —- | C] () – C:WINDOWSODBCINST.INI
[2004/08/10 11:57:15 | 000,309,992 | —- | C] () – C:WINDOWSSystem32FNTCACHE.DAT
[2004/08/10 11:51:20 | 000,599,266 | —- | C] () – C:WINDOWSSystem32perfh009.dat
[2004/08/10 11:51:20 | 000,125,500 | —- | C] () – C:WINDOWSSystem32perfc009.dat
[2004/08/10 11:51:16 | 000,000,741 | —- | C] () – C:WINDOWSSystem32noise.dat
[2004/08/04 05:00:00 | 013,107,200 | —- | C] () – C:WINDOWSSystem32oembios.bin
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:WINDOWSSystem32mlang.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:WINDOWSSystem32perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:WINDOWSSystem32dssec.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:WINDOWSSystem32mib.bin
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:WINDOWSSystem32perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:WINDOWSSystem32secupd.dat
[2004/08/04 05:00:00 | 000,004,461 | —- | C] () – C:WINDOWSSystem32oembios.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:WINDOWSSystem32dcache.bin
[2004/05/29 12:39:02 | 000,405,504 | —- | C] () – C:WINDOWSSystem32ode.dll
[2003/07/08 14:49:24 | 000,282,624 | —- | C] () – C:WINDOWSSystem32tvimaging.dll
[2003/03/09 13:01:10 | 000,024,576 | —- | C] () – C:WINDOWSSystem32SDL_net.dll
[2003/02/10 02:13:10 | 000,000,416 | -H– | C] () – C:Documents and SettingsAll UsersApplication Datasystmsp2pb7
[2001/11/11 03:38:08 | 000,204,800 | —- | C] () – C:WINDOWSSystem32smpeg.dll
[1998/10/11 01:07:38 | 000,088,576 | —- | C] () – C:WINDOWSSystem32Iticheck.dll
========== LOP Check ==========
[2010/01/29 15:25:31 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataApplications
[2010/06/29 12:48:40 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAutodesk
[2008/06/30 14:16:23 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataAzureus
[2006/02/14 13:08:25 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataBorland
[2006/05/10 07:47:21 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataGroove Networks
[2008/04/29 13:12:01 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataMindjet
[2010/08/23 10:10:49 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNCH Swift Sound
[2007/11/19 15:25:15 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNDoc.1.3
[2006/02/14 10:14:27 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataPreEmptive Solutions
[2009/09/24 15:01:40 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataRed Gate
[2010/08/23 09:55:37 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataSamsung
[2009/11/13 09:36:11 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataTEMP
[2006/02/01 02:05:41 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataViewpoint
[2011/06/15 13:25:10 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataVS
[2011/07/27 08:32:39 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/02 11:31:35 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication Data{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/05/16 09:52:58 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Data.bittorrent
[2009/10/21 16:09:21 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Data.myibay
[2010/05/12 08:45:08 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataAutodesk
[2011/04/05 10:56:06 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataAzureus
[2011/03/01 10:58:39 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBHOK IT Consulting
[2007/08/13 16:57:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBitTorrent
[2010/05/12 10:49:09 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBlender Foundation
[2006/02/14 13:08:25 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataBorland
[2010/09/15 15:17:52 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataControlScenarios
[2007/05/28 16:39:33 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataDNA
[2011/09/23 10:22:01 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datagtk-2.0
[2009/03/27 21:13:10 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataHouseCall 6.6
[2010/07/08 15:58:31 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataHudson
[2009/02/24 12:07:12 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataIsolatedStorage
[2009/02/24 17:07:05 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataJetBrains
[2006/02/15 12:34:26 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataLeadertech
[2006/05/02 09:07:01 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMayaWebBrowser
[2011/09/23 09:52:31 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMonoDevelop
[2011/09/23 10:12:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMonoDevelop-2.6
[2009/03/27 15:50:18 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataMy Games
[2010/08/23 10:09:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataNCH Swift Sound
[2011/05/25 11:53:14 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataNuGet
[2007/01/04 15:08:00 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataOfficeUpdate12
[2010/10/05 11:16:03 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataooVoo Details
[2009/08/10 11:59:06 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataOpera
[2007/08/07 13:50:37 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataPegasys Inc
[2007/11/08 10:50:54 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataPoser 7
[2010/08/23 13:27:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataRingtone
[2010/08/23 09:54:20 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSamsung
[2008/05/29 11:32:38 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSciTech
[2011/06/20 14:52:30 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSecondLife
[2010/08/23 10:49:44 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSonyEricsson
[2011/09/23 09:53:22 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datastetic
[2006/11/29 10:27:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataSubversion
[2010/10/05 16:00:26 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataTangible Software Solutions Inc
[2011/05/10 07:56:13 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataTelerik
[2006/05/17 09:54:23 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication Datauk.co.planetside
[2008/01/24 16:15:35 | 000,000,000 | —D | M] – C:Documents and SettingsrlevereApplication DataWings3D
[2011/09/28 12:44:07 | 000,000,472 | —- | M] () – C:WINDOWSTasksAd-Aware Update (Weekly).job
[2011/09/28 13:38:38 | 000,000,424 | -H– | M] () – C:WINDOWSTasksMP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%*.* >
[2006/12/13 11:18:07 | 000,000,079 | —- | M] () – C:3doImporterSettings.txt
[2011/06/15 15:50:18 | 000,004,908 | —- | M] () – C:aaw7boot.log
[2006/03/03 10:14:36 | 000,005,632 | —- | M] () – C:ATestMap.ptm
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:AUTOEXEC.BAT
[2007/06/04 10:49:58 | 000,003,554 | —- | M] () – C:avatar.jpg
[2007/11/07 13:03:53 | 000,015,723 | —- | M] () – C:AvatarChest.3ds
[2007/08/03 13:53:17 | 817,865,708 | —- | M] () – C:AVSEQ01.mpg
[2006/02/10 18:08:28 | 000,000,210 | -HS- | M] () – C:boot.ini
[2007/05/28 09:25:39 | 000,000,248 | —- | M] () – C:Bryce Uninstall.log
[2007/10/23 08:53:26 | 025,251,654 | —- | M] () – C:CCI00000.bmp
[2007/11/08 15:43:58 | 000,019,329 | —- | M] () – C:chest.3ds
[2007/11/08 15:45:36 | 000,029,830 | —- | M] () – C:chest.xaml
[2007/11/08 15:45:36 | 000,029,830 | —- | M] () – C:chest.xml
[2010/08/23 08:51:04 | 000,000,074 | —- | M] () – C:CMLoader.log
[2006/11/20 12:04:23 | 007,138,920 | —- | M] () – C:COD_FORTRESS.tnt
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:CONFIG.SYS
[2007/05/29 10:35:32 | 001,049,654 | —- | M] () – C:Copy of heightmap.bmp
[2007/05/29 10:39:44 | 016,778,294 | —- | M] () – C:Copy of Untitled.bmp
[2006/02/01 01:52:18 | 000,005,648 | RH– | M] () – C:dell.sdr
[2008/01/04 12:53:12 | 000,010,036 | —- | M] () – C:Doxyfile
[2007/10/23 16:50:01 | 002,005,928 | —- | M] () – C:fmodapi375win.zip
[2007/07/16 10:41:22 | 000,009,750 | —- | M] () – C:hair_modified1.jpg
[2007/07/16 11:00:50 | 000,010,041 | —- | M] () – C:hair_modified2.jpg
[2007/05/29 10:42:30 | 016,778,294 | —- | M] () – C:heightmap.bmp
[2007/05/28 15:23:20 | 000,005,991 | —- | M] () – C:heightmap.jpg
[2006/02/17 14:12:49 | 000,034,958 | —- | M] () – C:Hexkit.xsd
[2006/02/17 14:12:49 | 000,034,958 | —- | M] () – C:Hexkit2.xsd
[2011/09/28 12:51:21 | 2144,899,072 | -HS- | M] () – C:hiberfil.sys
[2006/02/10 18:05:44 | 000,004,128 | —- | M] () – C:INFCACHE.1
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:IO.SYS
[2006/02/01 02:05:44 | 000,000,775 | -H– | M] () – C:IPH.PH
[2006/03/16 10:15:58 | 000,184,434 | —- | M] () – C:iso_map.jpg
[2007/01/22 15:20:04 | 000,000,989 | —- | M] () – C:magnetar.cer
[2007/01/22 14:42:04 | 000,004,542 | —- | M] () – C:magnetar.pfx
[2010/06/24 08:39:13 | 000,000,109 | —- | M] () – C:mbam-error.txt
[2006/11/17 14:39:48 | 000,000,043 | —- | M] () – C:ModelStats.txt
[2007/04/20 12:22:09 | 002,265,600 | —- | M] () – C:mr3pdemo.exe
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:MSDOS.SYS
[2007/01/19 14:47:46 | 000,002,697 | —- | M] () – C:mycert.spc
[2007/01/09 15:43:02 | 000,001,212 | —- | M] () – C:mykey.pvk
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2008/05/15 15:27:37 | 000,250,048 | RHS- | M] () – C:ntldr
[2009/01/12 11:20:19 | 000,344,123 | —- | M] () – C:Original.pcx
[2011/09/28 12:51:15 | 2145,386,496 | -HS- | M] () – C:pagefile.sys
[2006/11/20 13:29:48 | 012,717,832 | —- | M] () – C:PaintedDesertII.tnt
[2007/07/19 14:45:32 | 000,015,833 | —- | M] () – C:radar.jpg
[2011/02/01 16:06:11 | 000,477,572 | —- | M] () – C:RES.zip
[2003/01/01 13:00:42 | 000,452,488 | —- | M] () – C:return_notice.jpg
[2011/09/28 13:37:50 | 000,000,630 | —- | M] () – C:rkill.log
[2006/11/17 14:34:48 | 000,004,195 | —- | M] () – C:samktorp.3DO
[2006/11/17 14:34:44 | 000,011,764 | —- | M] () – C:SAMurai.3do
[2006/11/22 11:15:32 | 000,000,304 | —- | M] () – C:SAMurai.mtl
[2006/11/22 11:15:32 | 000,022,085 | —- | M] () – C:SAMurai.obj
[2006/11/21 16:10:07 | 000,008,985 | —- | M] () – C:SAMurai.wrl
[2006/08/03 14:38:45 | 000,001,016 | —- | M] () – C:Shortcut to EMT Demo.lnk
[2007/07/16 10:31:28 | 000,012,144 | —- | M] () – C:sides_modified.jpg
[2007/11/08 12:18:49 | 000,083,613 | —- | M] () – C:SL-Avata.png
[2007/05/28 15:27:59 | 000,002,777 | —- | M] () – C:ta.pal
[2008/07/17 15:50:54 | 000,001,971 | —- | M] () – C:TACTICS.CFG
[2007/02/09 16:06:54 | 109,672,314 | —- | M] () – C:ta_tileset.pcx
[2007/01/25 11:46:39 | 000,000,066 | —- | M] () – C:temp.txt
[2007/05/28 15:36:34 | 000,001,647 | —- | M] () – C:test.ota
[2007/05/28 15:36:34 | 001,130,585 | —- | M] () – C:test.tnt
[2007/05/29 10:51:05 | 000,970,269 | —- | M] () – C:test.ufo
[2007/11/01 12:50:58 | 000,068,980 | —- | M] () – C:test.xaml
[2007/07/18 14:21:13 | 000,004,175 | —- | M] () – C:testmap.xml
[2007/10/31 14:50:29 | 000,019,456 | -HS- | M] () – C:Thumbs.db
[2006/03/16 11:15:11 | 000,003,108 | —- | M] () – C:tv3d_debug.txt
[2007/05/29 10:41:53 | 268,436,534 | —- | M] () – C:Untitled.bmp
[2010/08/16 15:39:03 | 000,000,024 | —- | M] () – C:url_history.xml
[2009/07/16 14:53:08 | 001,104,410 | —- | M] () – C:V1.4.zip
[2007/08/27 11:12:50 | 000,137,097 | —- | M] () – C:wave1.jpg
[2007/08/27 11:12:54 | 000,133,860 | —- | M] () – C:wave2.jpg
[2009/01/12 11:26:15 | 000,073,749 | —- | M] () – C:WPF_Version.jpg
[2007/11/08 12:44:00 | 000,159,207 | —- | M] () – C:XAML.zip
[2007/05/18 10:45:11 | 000,000,010 | -H– | M] () – C:xrjmns.tce
< %systemroot%Fonts*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
< %systemroot%Fonts*.dll >
< %systemroot%Fonts*.ini >
[2006/02/10 18:10:42 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini
< %systemroot%Fonts*.ini2 >
< %systemroot%Fonts*.exe >
< %systemroot%system32spoolprtprocsw32x86*.* >
[2004/02/09 01:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:WINDOWSsystem32spoolprtprocsw32x86brmfpp1.dll
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2009/12/10 10:24:06 | 000,082,168 | —- | M] (Microsoft Corporation.) – C:WINDOWSsystem32spoolprtprocsw32x86lmdippr8.dll
[2006/04/28 01:51:40 | 000,029,968 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe
< %systemroot%REPAIR*.bak1 >
< %systemroot%REPAIR*.ini >
< %systemroot%system32*.jpg >
< %systemroot%*.jpg >
< %systemroot%*.png >
< %systemroot%*.scr >
< %systemroot%*._sy >
< %APPDATA%AdobeUpdate*.* >
< %ALLUSERSPROFILE%Favorites*.* >
< %APPDATA%Microsoft*.* >
[2009/01/29 16:35:48 | 000,016,952 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoft1eaadjc.dll
[2009/01/29 16:35:48 | 000,018,724 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftbass.dll
[2009/01/29 16:35:49 | 000,321,536 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftengine_vx.dll
[2009/01/29 16:35:48 | 000,014,392 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftkfgresk.dll
[2009/01/29 16:35:48 | 000,013,984 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftmjcriu.dll
[2009/01/29 16:35:48 | 000,010,808 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftpeaadje.dll
[2009/01/29 16:35:48 | 000,026,200 | —- | M] ((: JOBnik!
[2009/01/29 16:35:48 | 000,015,416 | —- | M] (Un4seen Developments) – C:Documents and SettingsrlevereApplication DataMicrosoftrsaadjd.dll
[1 C:Documents and SettingsrlevereApplication DataMicrosoft*.tmp files -> C:Documents and SettingsrlevereApplication DataMicrosoft*.tmp -> ]
< %PROGRAMFILES%*.* >
[2006/09/01 08:55:19 | 002,314,104 | —- | M] () – C:Program FilesPaint Shop Pro.zip
< %APPDATA%Update*.* >
< %systemroot%*. /mp /s >
< %systemroot%System32config*.sav >
[2006/02/10 10:02:29 | 000,262,144 | —- | M] () – C:WINDOWSSystem32configdefault.sav
[2006/02/10 17:55:00 | 000,262,144 | —- | M] () – C:WINDOWSSystem32configsecurity.sav
[2006/02/10 10:02:29 | 017,825,792 | —- | M] () – C:WINDOWSSystem32configsoftware.sav
[2006/02/10 10:02:31 | 005,505,024 | —- | M] () – C:WINDOWSSystem32configsystem.sav
< %PROGRAMFILES%bak. /s >
< %systemroot%system32bak. /s >
< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2008/05/15 15:34:26 | 000,000,272 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini
< %systemroot%system32configsystemprofile*.dat /x >
< %systemroot%*.config >
< %systemroot%system32*.db >
< %PROGRAMFILES%Internet Explorer*.dat >
< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2006/02/10 16:13:52 | 000,000,119 | -HS- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2004/08/10 12:08:38 | 000,000,079 | —- | M] () – C:Documents and SettingsrlevereApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf
< %USERPROFILE%Desktop*.exe >
[2011/09/28 14:29:20 | 000,582,656 | —- | M] (OldTimer Tools) – C:Documents and SettingsrlevereDesktopOTL.exe
[2011/09/28 11:06:47 | 012,609,096 | —- | M] (SUPERAntiSpyware.com) – C:Documents and SettingsrlevereDesktopSUPERAntiSpyware.exe
< %PROGRAMFILES%Common Files*.* >
< %systemroot%*.src >
< %systemroot%install*.* >
< %systemroot%system32DLL*.* >
< %systemroot%system32HelpFiles*.* >
< %systemroot%system32rundll*.* >
< %systemroot%winn32*.* >
< %systemroot%Java*.* >
< %systemroot%system32test*.* >
< %systemroot%system32Rundll32*.* >
< %systemroot%AppPatchCustom*.* >
< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >
< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-09-13 16:12:56
========== Alternate Data Streams ==========
@Alternate Data Stream - 810 bytes -> C:Documents and SettingsrlevereMy DocumentsCodeFile.cs:Undo
@Alternate Data Stream - 8 bytes -> C:Documents and SettingsrlevereMy DocumentsCodeFile.cs:Bookmarks
@Alternate Data Stream - 8 bytes -> C:Documents and SettingsrlevereMy DocumentsClass.cs:Bookmarks
@Alternate Data Stream - 56 bytes -> C:Documents and SettingsrlevereMy DocumentsClass.cs:Undo
@Alternate Data Stream - 368 bytes -> C:Documents and SettingsrlevereLocal SettingsApplication Datadesktop.ini:722b2b1c349a06abf0e866180e5a7e63
< End of report >
Here's Extras.txt:
OTL Extras logfile created on: 28/09/2011 2:31:38 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:Documents and SettingsrlevereDesktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.23% Memory free
3.84 Gb Paging File | 2.76 Gb Available in Paging File | 71.82% Paging File free
Paging file location(s): c:pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 232.78 Gb Total Space | 60.11 Gb Free Space | 25.82% Space Free | Partition Type: NTFS
Computer Name: NEBULA | User Name: rlevere | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
.js [@ = JSFile] – Reg Error: Key error. File not found
.reg [@ = Regedit.Document] – c:WinntRegedit.exe %1
[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = FirefoxHTML] – C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewall]
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfile]
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfile]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4282:TCP" = 4282:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"37682:TCP" = 37682:TCP:*:Disabled:ooVoo TCP port 37682
"37682:UDP" = 37682:UDP:*:Disabled:ooVoo UDP port 37682
"37683:UDP" = 37683:UDP:*:Disabled:ooVoo UDP port 37683
"37686:TCP" = 37686:TCP:*:Disabled:ooVoo TCP port 37686
"37686:UDP" = 37686:UDP:*:Disabled:ooVoo UDP port 37686
"37687:UDP" = 37687:UDP:*:Disabled:ooVoo UDP port 37687
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 1
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"2799:UDP" = 2799:UDP:*:Enabled:Altova License Metering Port (UDP)
"2799:TCP" = 2799:TCP:*:Enabled:Altova License Metering Port (TCP)
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"C:Program FilesMicrosoft XNAXNA Game Studiov3.1BinXnaLiveProxy.exe" = C:Program FilesMicrosoft XNAXNA Game Studiov3.1BinXnaLiveProxy.exe:LocalSubNet:Enabled:XNA Framework Games for Windows - LIVE – (Microsoft Corporation)
"C:Program FilesAutodesk3ds Max 20113dsmax.exe" = C:Program FilesAutodesk3ds Max 20113dsmax.exe:*:Enabled:Autodesk 3ds Max 2011 32-bit
"C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32server.exe" = C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max 2011 32-bit
"C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32.exe" = C:Program FilesAutodesk3ds Max 2011mentalimagessatelliteraysat_3dsmax2011_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max 2011 32-bit
"C:Program Filesmyibaymyibay.exe" = C:Program Filesmyibaymyibay.exe:*:Enabled:Myibay eBay bid sniper – ()
"C:Program FilesOperaopera.exe" = C:Program FilesOperaopera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:Program FilesMicrosoft Security Essentialsmsseces.exe" = C:Program FilesMicrosoft Security Essentialsmsseces.exe:*:Enabled:Microsoft Security Essentials
"C:Program FilesMicrosoft Visual Studio 9.0Common7IDEdevenv.exe" = C:Program FilesMicrosoft Visual Studio 9.0Common7IDEdevenv.exe:*:Enabled:Microsoft Visual Studio 2008 – (Microsoft Corporation)
"C:Program FilesMicrosoft Visual Studio 8Common7IDEdevenv.exe" = C:Program FilesMicrosoft Visual Studio 8Common7IDEdevenv.exe:*:Enabled:Microsoft Visual Studio 2005 – (Microsoft Corporation)
"C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.exe:*:Enabled: – ()
"C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.32BitLaunch.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsopensim-0.7.0.1-binopensim-0.7.0.1-binbinOpenSim.32BitLaunch.exe:*:Enabled:OpenSim.32BitLaunch – ()
"C:Program FilesSamsungSamsung New PC Studionpsasvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsasvr.exe:*:Enabled:KTF MUSIC AoD Server – (PeeringPortal)
"C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe:*:Enabled:KTF MUSIC VoD Server – (PeeringPortal)
"C:Program FilesTelerikRadControls for Silverlight Q2 2010 SP1DemosExamples.WebStartExamples.exe" = C:Program FilesTelerikRadControls for Silverlight Q2 2010 SP1DemosExamples.WebStartExamples.exe:*:Enabled:StartExamples
"C:Program FilesooVooooVoo.exe" = C:Program FilesooVooooVoo.exe:*:Enabled:ooVoo – (ooVoo LLC)
"C:Documents and Settingsrleveredownloads4dkreign17Dark Reign 1.7dkreign.exe" = C:Documents and Settingsrleveredownloads4dkreign17Dark Reign 1.7dkreign.exe:*:Enabled:dkreign – ()
"C:Documents and SettingsrlevereMy DocumentsDownloadseclipse-modeling-helios-SR2-incubation-win32eclipseeclipse.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadseclipse-modeling-helios-SR2-incubation-win32eclipseeclipse.exe:*:Disabled:eclipse – ()
"C:Program FilesTelerikRadControls for Silverlight Q3 2010 SP1DemosExamples.WebStartExamples.exe" = C:Program FilesTelerikRadControls for Silverlight Q3 2010 SP1DemosExamples.WebStartExamples.exe:*:Enabled:StartExamples
"C:Program FilesMicrosoft XNAXNA Game Studiov4.0BinXnaLiveProxy.exe" = C:Program FilesMicrosoft XNAXNA Game Studiov4.0BinXnaLiveProxy.exe:LocalSubNet:Enabled:XNA Framework Games for Windows - LIVE – (Microsoft Corporation)
"C:Program FilesSecondLifeViewer2SLVoice.exe" = C:Program FilesSecondLifeViewer2SLVoice.exe:*:Disabled:SLVoice – (Vivox Inc.)
"C:Documents and SettingsrlevereMy DocumentsDownloadsSilverlightPlayground.UDPMulticastSilverlightPlayground.UDP
Multicast.PolicyServerbinDebugPolicyServer.exe" = C:Documents and SettingsrlevereMy DocumentsDownloadsSilverlightPlayground.UDPMulticastSilverlightPlayground.UDP
Multicast.PolicyServerbinDebugPolicyServer.exe:*:Enabled:PolicyServer – (Microsoft IT)
"C:Program FilesMicrosoft Silverlightsllauncher.exe" = C:Program FilesMicrosoft Silverlightsllauncher.exe:*:Enabled:Microsoft Silverlight Out-of-Browser Launcher – (Microsoft Corporation)
"C:Program FilesMicrosoft Office Communicatorcommunicator.exe" = C:Program FilesMicrosoft Office Communicatorcommunicator.exe:*:Enabled:Office Communicator – (Microsoft Corporation)
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"C:Program FilesFiraxis GamesSid Meier's Civilization 4Civilization4.exe" = C:Program FilesFiraxis GamesSid Meier's Civilization 4Civilization4.exe:*:Enabled:Sid Meier's Civilization 4
"C:Program FilesAtariNeverwinter Nights 2nwn2main.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main
"C:Program FilesAtariNeverwinter Nights 2nwn2main_amdxp.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD
"C:Program FilesAtariNeverwinter Nights 2nwupdate.exe" = C:Program FilesAtariNeverwinter Nights 2nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater
"C:Program FilesAtariNeverwinter Nights 2nwn2server.exe" = C:Program FilesAtariNeverwinter Nights 2nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server
"C:Program FilesTHQGas Powered GamesSupreme CommanderbinSupremeCommander.exe" = C:Program FilesTHQGas Powered GamesSupreme CommanderbinSupremeCommander.exe:*:Enabled:Supreme Commander
"C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe" = C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe:*:Enabled:GPGNet - Supreme Commander
"C:Program FilesMicrosoft XNAXNA Game Studio Expressv1.0BinXnaTrans.exe" = C:Program FilesMicrosoft XNAXNA Game Studio Expressv1.0BinXnaTrans.exe:LocalSubNet:Enabled:XNA Game Studio Transport – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{0028A6EE-4945-4233-8024-80A546F56A5C}" = JetBrains dotTrace 3.1
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{006DEADE-E12E-4DA0-AB65-134F0DE9AF9A}" = Swift 3D v4.50
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{01C79EF3-DE84-4B56-B638-8BEA0D507506}" = Microsoft XNA Game Studio 4.0 (XnaLiveProxy)
"{030FF28D-42E3-44C1-BDC6-7451CB89B41D}" = Exception Hunter 2
"{05855322-BE43-41FE-B583-D3AE0C326D58}" = Microsoft Silverlight 4 SDK
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
"{0666E46E-A860-4353-BE6D-13AA72FABB57}" = Microsoft XNA Game Studio Platform Tools
"{06CB415E-F256-4097-95B2-7555EBD1DBC0}" = "WPF/E" Visual Studio 2005 Template CTP (Dec 2006)
"{070B87FB-CD1A-45AA-9E5E-484E5964C6ED}" = Microsoft XNA Game Studio 2.0 (ARP entry)
"{077C74E2-A2A8-11D5-8CD5-00104BB9CE36}" = Speech
"{07EF3970-F8E5-4A27-A5A3-230484D35026}" = Microsoft Expression Encoder 4
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{08C84CC6-E7FD-4B2D-BBF9-B02CC90EE031}" = Microsoft XNA Game Studio 4.0 (Shared Components)
"{08D605B4-DCD1-451F-ABD7-52E6BB868E4E}" = Microsoft Expression Design 4
"{09C52940-A4D1-4409-A7CC-1AAE630CF578}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0BE273CD-AAB9-361B-8C32-D955EAC929E3}" = Microsoft Visual Studio 2010 SharePoint Developer Tools
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D1CBBB9-F4A8-45B6-95E7-202BA61D7AF4}" = Microsoft Office Communicator 2007 R2
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool
"{0FF406B0-98E3-4872-A743-6FBB0259BDF2}" = Composite UI Application Block December 2005 (C#)
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{11971FBC-7388-4D30-8D64-17741D2D665C}" = Microsoft Windows Software Development Kit Documentation (5536.0.2)
"{124533B3-5155-339B-A641-67BB84F39475}" = Visual C++ 2008 x64 Runtime - (v9.0.30428)
"{124533B3-5155-339B-A641-67BB84F39475}.vc_x64runtime_30428_01" = Visual C++ 2008 x64 Runtime - v9.0.30428.01
"{1287B0B4-0E89-4839-B552-809D5C0DC9F6}" = StudioTax 2010
"{1389C6A4-4965-4AEC-9175-08B54A10FA48}" = Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{152F8595-0D36-4BE4-9FBD-5AD87AC3D3E5}" = Microsoft XNA Game Studio Express 1.0 Refresh
"{170DE2A7-4768-370C-9671-D8D17826EFBF}" = Microsoft Visual Studio 2010 Performance Collection Tools SP1 - ENU
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}" = Sound Blaster X-Fi
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C997E1C-5CE9-4AF3-AAA9-DC65E6090827}" = Microsoft Expression Blend SDK for Silverlight 4
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F85CAAA-B786-4E5B-AADD-638856992EF3}" = Opera 10.53
"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{213C85AC-6CB3-4B52-8420-AFFAEEF4DE75}" = Smoke - Game Technology Demo
"{21D8E686-2E8F-46F1-B997-209E4E0873A1}" = Microsoft Visual Studio 2005 Team Explorer - ENU
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729)
"{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01
"{23E5C72C-CC08-4EE0-9CC2-D925B232B331}" = Microsoft MSDN 2005 Express Edition - ENU
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{24C56EE0-76FC-42C7-BD42-78F2EEE63FCD}" = NDEV software
"{256E7DAC-9BE8-494E-8DE7-7857BF96B774}" = Microsoft Expression Blend 3 SDK
"{26119A24-8F74-4F62-A278-AB3984B12C04}" = Microsoft Web Platform Installer 2.0 RC
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2A42414B-1E07-454B-97C4-4789D8DBD338}" = Multiverse Tools
"{2A5A6D00-2B27-4E1A-8A33-E3A40DFDF3EB}" = Microsoft XNA Game Studio 2.0
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C057674-72BF-410E-820F-054F43293E65}" = WCF RIA Services V1.0 SP2 Preview (April 2011)
"{2C695618-6950-4C88-B836-A4FE7DD7FC9F}" = CuneiForm OpenOCR
"{2C97AA6D-8B10-46CA-B7A5-36DF71ACD1E0}" = GoSilverlight [removed]
"{2D514F36-DD72-4F2B-B10A-C5BC76585760}" = MagnetarTrystAddIn
"{2DDCCEA5-2AA4-4ABB-BCAD-41BB115A4333}" = Microsoft Silverlight 4 Toolkit April 2010
"{2DFDD440-A33C-42E4-A366-71E6CB4246A0}" = Microsoft Command Shell
"{2E402AA9-5C0E-45E7-8E70-C23FA0F265D5}" = Microsoft XNA Game Studio 3.1 (devenv)
"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86
"{302F9AB2-9165-4968-B482-11E2673B62D3}" = Mindjet MindManager Pro 7
"{310141DF-B0E2-428C-BE3B-25A5F9517F6E}" = MindManager Accelerator SDK
"{31EA6FCB-6C53-4BA7-BE88-9BA788899C2C}" = Microsoft XNA Game Studio 2.0 (Redists)
"{33AE9E89-47C9-4A0D-9E9D-BDD6966A3804}" = Microsoft SQL Server 2008 RsFx Driver
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{3432C2AA-BB3E-44B3-B5ED-EF36E0241100}" = Microsoft XNA Game Studio 2.0 (spacewar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{370BBA05-01E7-4BCC-9B38-E85DB8E13E11}" = Microsoft Silverlight 2 SDK
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{39970EE2-C8E3-3095-8B15-A7B99863527F}" = Visual C++ 2008 x64 Runtime - KB2465361 - (v9.0.30729.5570)
"{39970EE2-C8E3-3095-8B15-A7B99863527F}.vc_x64runtime_30729_5570" = Visual C++ 2008 x64 Runtime - v9.0.30729.5570
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B5A6E00-2B27-4E1A-8A33-E3A40DEFD4DC}" = Microsoft XNA Game Studio 2.0 Documentation
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.4148)
"{3C11D2DA-6802-3F66-BE6B-B2C046AFE866}.vc_x64runtime_30729_4148" = Visual C++ 2008 x64 Runtime - v9.0.30729.4148
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB09FD2-DBF7-4BB1-8A68-1D48A9B22CEA}" = XNA Build System
"{3F4EB5FE-B5BE-4069-A5A8-6D9262E1B379}" = Microsoft XNA Game Studio 4.0 Documentation
"{3F8D9A47-9C50-3F46-8F12-B92DD5CA0A2E}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.6161)
"{3F8D9A47-9C50-3F46-8F12-B92DD5CA0A2E}.vc_x86runtime_30729_6161" = Visual C++ 2008 x86 Runtime - v9.0.30729.6161
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{4112625F-2D38-49EF-924F-48511BC5CD34}" = Microsoft SQL Server 2008 Database Engine Services
"{431FC52A-2963-4F92-A2FB-5E5C2EF9069F}" = Warplanner2
"{437AB8E0-FB69-4222-B280-A64F3DE22591}" = Microsoft Visual Studio 2005 Professional Edition - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{44F7BA74-C11A-49FC-B2FC-1B827C491F74}" = Microsoft Expression Studio 3
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4723f199-fa64-4233-8e6e-9fccc95a18ee}" = Python 2.6.5
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4946979B-3624-3F97-997E-49F4CA0E3E90}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.6161)
"{4946979B-3624-3F97-997E-49F4CA0E3E90}.vc_i64runtime_30729_6161" = Visual C++ 2008 IA64 Runtime - v9.0.30729.6161
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4B4345D9-A3BF-409F-A392-3B45C4C3E067}" = tIDE v2.0.1
"{4B6A3B5E-D26E-4690-A061-F3E2FB10F0E5}" = TortoiseSVN 1.6.9.19725 (32 bit)
"{4C6D5779-A766-45DF-9938-D6F595A66F2B}" = Microsoft Expression Blend 4
"{4DE79189-E5DD-49A0-914F-E40919AAB597}" = Okino Plug-ins Installer (Demo Version)
"{4F44B5AE-82A6-4A8A-A3E3-E24D489728E3}" = Microsoft SQL Server 2008 Native Client
"{51A6F9AE-AFF6-4A96-BEBA-217350BC3803}" = Infragistics NetAdvantage 2006 Vol. 1 for CLR 2.0
"{531B96B7-5126-4DC6-B51B-3DCDB0F93BA6}" = Microsoft® MechCommander® 2 Shared Source Release
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{550B72C4-F404-4812-971F-947E835A877E}" = Gtk# for .Net 2.12.10
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{558358E5-E4F3-4374-BA1D-26FF39EF87D9}" = Microsoft Silverlight 4 Tools for Visual Studio 2010
"{55979D54-FE44-4BCE-A2CF-9D29727F267D}" = Altova Enterprise XML Suite 2006
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57BB52B7-6B7B-31F3-89F4-4EE8FE5CEF6D}" = Microsoft Help Viewer 1.1
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5C741A01-05D6-4306-BA6A-DC8401285AE8}" = Debugging Tools for Windows
"{5D05CEB3-647F-4408-BC8C-B1247B107E61}" = Microsoft Silverlight 5 Beta SDK
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
"{5EE6E987-1B79-4A93-832B-27472C7D1579}" = WPF Toolkit February 2010 (Version 3.5.50211.1)
"{5F8D931D-B230-47F3-A9C0-0C8CA459A332}" = Microsoft Expression Web 4
"{60E2C8C9-6CF3-4B1A-9618-E304946C94E6}" = Python 2.4.4
"{60EEBD86-9EF0-444B-90ED-43AE78D09C7F}" = MonoDevelop 2.6
"{6201E1EB-DA64-4714-ADBB-852D74B1E5CC}" = Mono for Android 1.2.0.24718
"{62B002C5-1AB3-11D8-8092-00E018B21FC0}" = USB Mass Storage Toolbox
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6356A0A5-B9B8-4A9E-BEBC-8D3B73E8CF30}" = Torque X 2D 3.1
"{63B9D49E-6417-4BA7-AC6E-1654A853C2CD}" = .NET Memory Profiler 3.1
"{63FAC405-B376-4F24-A31C-321E904CFD38}" = Microsoft .NET Client Futures Code Name "Acropolis" CTP1
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{654EF90B-6DAD-4734-B6F0-F56AF7F2B1A0}" = Microsoft Visual Studio 2005 SDK April 2006
"{65BCF909-6AF7-4B01-8EB3-713CE2873DC8}" = Microsoft Expression Web 3
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{68BD57D3-D606-411E-A7E0-3EB6EA5660F6}" = Microsoft XNA Game Studio 4.0 (Redists)
"{69F0982C-F08D-49E0-B8FB-FD636FD4DE40}" = XMLSPY 5 Professional Edition
"{6AFBA3EB-0BBC-4E7B-9410-D319B55B3794}" = Microsoft Windows Software Development Kit Compilers (5536.0.2)
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6ED37A91-7710-3183-BE50-AB043FF6689E}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{6FAE970B-73B6-4490-9A8E-74DFB09742D7}" = Microsoft Windows Software Development Kit Utilities for Win32 Development (5536.0.2)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7348C833-0030-4EAF-8EB2-085B3D5D2BFB}" = Microsoft Windows Software Development Kit Utilities for .NET Development (5536.0.2)
"{73BE04D9-BA0E-4BAF-9C9D-677278BDB3DC}" = Microsoft XNA Game Studio 4.0 (ARP entry)
"{7451D88C-8A79-44C2-8528-8C952730B6B5}" = Nova Studio 2010
"{752E90AC-3F11-4EA3-88EA-96441047EC31}" = Microsoft Expression Web 3 SP1
"{766B3A7A-B5AE-33F5-9858-75E692799C84}" = Microsoft Visual Studio 2008 Team Explorer - ENU
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}" = Microsoft SQL Server 2008 R2 Management Objects
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A56D81D-6406-40E7-9184-8AC1769C4D69}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}" = Visual C++ 2008 x86 Runtime - (v9.0.30729.4148)
"{7B33F480-496D-334A-BAC2-205DEC0CBC2D}.vc_x86runtime_30729_4148" = Visual C++ 2008 x86 Runtime - v9.0.30729.4148
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E7D7935-B0C8-4032-80BA-2CDC9E43C3B8}" = Microsoft Visual C# 2005 Express Edition - ENU
"{7EA88F86-024F-46B6-AE24-327001D6A9E1}" = ANTS Memory Profiler 5
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{7FEDF49B-01B3-3E2B-9C41-3A6F9583A040}" = Visual C++ 2008 IA64 Runtime - KB2465361 - (v9.0.30729.5570)
"{7FEDF49B-01B3-3E2B-9C41-3A6F9583A040}.vc_i64runtime_30729_5570" = Visual C++ 2008 IA64 Runtime - v9.0.30729.5570
"{80C06CCD-7D07-3DB6-86CD-B57B3F0614D8}" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"{80D4FD4C-A8B7-4924-94B9-079C657F0DFA}" = Microsoft Windows Software Development Kit (5536.0.2)
"{827990C7-4D30-3627-A2D1-5FFA09198BB2}" = Microsoft Visual Studio 2010 Office Developer Tools (x86)
"{828BC0F5-C51E-4037-9B33-3C108F92E0FC}" = WPF Performance Suite
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{846D9AAD-EA7D-4126-9177-F874FD389BE4}" = Microsoft FxCop 1.35
"{85195381-0426-4715-8D25-E21B9457FC00}" = Ad-Aware
"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{877B76B2-F83F-4F5A-B28D-3F398641ADB6}" = Microsoft SQL Server System CLR Types
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8C496FBF-DB4A-468D-A3A1-15E127382218}" = Microsoft XNA Game Studio 4.0 (Visual Studio)
"{8E67940F-CFDB-4B01-A83A-4D75923FAFC1}" = Microsoft Silverlight 3 Tools for Visual Studio 2008 SP1 - ENU
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9660018B-2873-44BD-95E5-A06AC4F7FE62}" = NUnit 2.4 (Beta 1) for .Net 2.0
"{97CE8B73-AA5A-4987-A1BE-50DD1A187478}" = Microsoft Sync Framework SDK v1.0 SP1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4
"{9B96628C-8898-4FED-9612-25631C27AB13}" = Microsoft XNA Game Studio 2.0 (xnaliveproxy)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DDE6C99-1659-4355-B7E5-30D2B38E3224}" = Actipro Wizard v3.0.0129
"{9EE2C1FE-6A4D-4C9C-B10B-FCBFA5478753}" = Microsoft Windows Software Development Kit Common Utilities (5536.0.2)
"{A06FE62B-CEBC-4E94-AED8-92DCC33BC8EA}" = Microsoft Expression Studio 4
"{A1E28FCC-0BE8-3556-A851-669BCD314D02}" = Visual C++ 2008 IA64 Runtime - (v9.0.30428)
"{A1E28FCC-0BE8-3556-A851-669BCD314D02}.vc_i64runtime_30428_01" = Visual C++ 2008 IA64 Runtime - v9.0.30428.01
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2425E6C-8A37-3D63-A3A7-8ED5355FDF0B}" = Visual C++ 2008 x86 Runtime - KB2465361 - (v9.0.30729.5570)
"{A2425E6C-8A37-3D63-A3A7-8ED5355FDF0B}.vc_x86runtime_30729_5570" = Visual C++ 2008 x86 Runtime - v9.0.30729.5570
"{A24DDA75-14A2-479C-B281-5C78B3E472FC}" = ZAM 3D
"{A2FCFCB8-38BB-4DCE-BE85-EB921AEFCD9A}" = Nova 2010 SDK
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4394612-D02F-11DC-9BFF-D18556D89593}" = Microsoft ASP.NET MVC RC
"{A4FA40F1-B88C-4BDF-B291-ED34982CB48F}" = Microsoft Expression Blend 3
"{A5E08284-41D3-4ACB-804D-47FBE5976A59}" = Multiverse Client
"{A77CBE0F-1EB2-30B8-89FA-6F5E51AF82B7}" = Visual C++ 2008 x86 Runtime - (v9.0.30428)
"{A77CBE0F-1EB2-30B8-89FA-6F5E51AF82B7}.vc_x86runtime_30428_01" = Visual C++ 2008 x86 Runtime - v9.0.30428.01
"{A91E3887-5185-4091-AF33-AB0048444055}" = Microsoft Online Services Sign In
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAF71941-BF2F-48FD-A52C-BD819C33F0FB}" = "WPF/E" (codename) SDK CTP (Dec 2006)
"{ABCA0C33-0F35-497D-9D66-09E524051115}" = Zillions of Games Demo
"{AC1A9DFE-812F-4D47-A1EE-329CFA331E4B}" = Shader Build Task
"{AC388C78-2619-452C-BFBE-FABCC3194387}" = Microsoft Office Live Meeting 2007
"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729.4148)
"{B28FC790-C93F-3A9C-A913-7E891487D1F1}.vc_i64runtime_30729_4148" = Visual C++ 2008 IA64 Runtime - v9.0.30729.4148
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3D1CFF9-C5DA-3590-894B-40821DDB67C5}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{B4DADED7-14DB-4FC0-BFAB-8549AD2191AE}" = Actipro Wizard v1.0.0305 for WPF
"{B5C9E5BD-7E70-4317-9779-22633C3BA1AF}" = Telerik RadControls for Silverlight Q1 2011
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8E9F8A1-9F4D-43D5-ABD6-1DF067FAA469}" = Microsoft SQL Server 2008 Database Engine Services
"{BA0C9AAF-1327-3F06-B49C-349B4BE8F740}" = Microsoft Visual Studio 2008 Shell (integrated mode) - ENU
"{BB4473CB-0CA3-4F4C-B4C7-427ECA3696BF}" = Microsoft Windows Software Development Kit Debug Symbols for .NET Development (5536.0.2)
"{BC0464FA-A0BA-3E38-85BF-DC5B3A401F48}" = Microsoft Visual Studio 2010 Ultimate - ENU
"{BC537AE0-88AF-47ED-B762-33B0D62B5188}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BF127B80-CFD5-4379-9752-E8AF1A5D0141}" = Microsoft Expression Encoder 4 Screen Capture Codec
"{C05344FF-448C-42FD-88D9-351BEC25C217}" = ANTS Performance Profiler 5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C18DA187-6C0D-4B8E-99AE-74D5C588AFB6}" = Microsoft XNA Game Studio 2.0 (shared components)
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C25EF637-BE7A-4761-9B45-9069989C319F}" = Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C6DD625F-4B61-4561-8286-87CA0275CEA1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86)
"{C73CA646-73B3-4AEF-A136-C37505745174}" = iTunes
"{C7EA29FC-78F2-4680-9D9B-22CA8191E63C}" = Microsoft Visual SourceSafe 2005 - ENU
"{C8A7718A-FF6D-4DDC-AE36-BBF968D6799B}" = Visual Studio 2005 Extensions for Windows Workflow Foundation
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB979F2F-DB8C-495B-AE17-A00ABD083931}" = Mindjet MindManager 6 AddIn Project Template for Visual Studio 2005
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CD5DC4AA-7D62-48D9-B756-5925471001FE}" = Microsoft OLE DB Provider for Visual FoxPro
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D10EC365-8936-4B40-AE2E-FCDA61C326D3}" = Alias DirectConnect 2.0
"{D12775DE-6D75-47A7-8354-44EFBA97B131}" = Microsoft Platform SDK Codenamed 'Phoenix' (June 2008 CTP)
"{D1ED83D7-A98D-4071-B559-B50B899F8554}" = Microsoft Windows Software Development Kit Samples (5536.0.2)
"{D441BD04-E548-4F8E-97A4-1B66135BAAA8}" = Microsoft SQL Server 2008 Setup Support Files
"{D5462C8A-D08C-4163-8293-82F2E11A2760}" = Trend Micro TrendProtect for Internet Explorer
"{D6D42959-143F-456A-9941-A400FD7B25D8}" = Microsoft Visual Studio Code Name "Orcas" Community Technology Preview - Development Tools for .NET Framework 3.0
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DC3D6AFB-78B4-489F-81D7-30B66E0C2417}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x86)
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E7E58A3A-D9BD-3D4B-9475-AE757454AD82}" = Visual C++ 2008 x64 Runtime - (v9.0.30729.6161)
"{E7E58A3A-D9BD-3D4B-9475-AE757454AD82}.vc_x64runtime_30729_6161" = Visual C++ 2008 x64 Runtime - v9.0.30729.6161
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9980014-BE11-4891-A5F4-0F2917B856BC}" = Microsoft Expression Design 3
"{EB3F5C2A-0754-38B8-8722-7B537006BF46}" = Microsoft Visual Studio 2008 Performance Collection Tools - ENU
"{ED780CA9-0687-3C12-B439-3369F224941F}" = Microsoft Visual Studio 2010 Service Pack 1
"{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}" = Adobe Stock Photos 1.0
"{F02D0CB9-C830-4B47-AA88-3125BE5E2E34}" = Groove
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F5993FCC-DF5D-4879-B70D-AA1F379C5C6B}" = Microsoft Expression Web 4 Service Pack 2
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F73340A9-8AA9-49C4-937E-E271B837056C}" = Microsoft Expression Encoder 3
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{F990B526-8F7C-46E0-B1F1-6C893A8B478F}" = Microsoft Sync Framework Services v1.0 SP1 (x86)
"{FAA106B4-2BBC-4ED3-9926-A003F2EAF18E}" = Microsoft DirectX SDK (February 2007)
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FB6ABA92-AF6A-4342-A7D4-D90A6CC66F6A}" = Microsoft Expression Blend 2 August Preview
"{FB8E4A2F-8D7D-4EF0-85FD-1F3D8817E573}" = Microsoft Silverlight PivotViewer
"{FC43B563-6D17-4A92-A314-E139D0D73A63}" = CodeWarrior for Wii V1.3
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FE0E06F7-209A-47BD-AC29-3B584166A627}" = Microsoft Windows Software Development Kit Headers and Libraries (5536.0.2)
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"AC3ACM" = AC-3 ACM Codec
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Flex Builder 2" = Adobe Flex Builder 2
"Adobe Shockwave Player" = Adobe Shockwave Player
"Android SDK Tools" = Android SDK Tools
"AOL Connectivity Services" = AOL Connectivity Services
"Blend_3.0.1927.0" = Microsoft Expression Blend 3
"Blend_4.0.20525.0" = Microsoft Expression Blend 4
"Borland JBuilder 2006 Enterprise" = Borland JBuilder 2006 Enterprise
"CleanUp!" = CleanUp!
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Design_6.0.1739.0" = Microsoft Expression Design 3
"Design_7.0.20516.0" = Microsoft Expression Design 4
"doxygen_is1" = doxygen 1.7.1
"DVDInfoPro" = DVDInfoPro
"Encoder_3.0.1332.0" = Microsoft Expression Encoder 3
"Encoder_4.0.1639.0" = Microsoft Expression Encoder 4
"ExpressionStudio_3.0.1061.0" = Microsoft Expression Studio 3
"ExpressionStudio_4.0.20525.0" = Microsoft Expression Studio 4
"FBX Plugin 2006.11.1 for Max 2008" = FBX Plugin 2006.11.1 for Max 2008
"Fraps" = Fraps
"GOBLIN Graph Library_is1" = GOBLIN Rel. 2.7
"GoToAssist" = GoToAssist 8.0.0.516
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4DE79189-E5DD-49A0-914F-E40919AAB597}" = Okino Plug-ins Installer (Demo Version)
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MeshLab" = MeshLab 1.0.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft DirectX SDK (August 2009)" = Microsoft DirectX SDK (August 2009)
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft MSDN 2005 Express Edition - ENU" = Microsoft MSDN 2005 Express Edition - ENU
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual C# 2005 Express Edition - ENU" = Microsoft Visual C# 2005 Express Edition - ENU
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual SourceSafe 2005 - ENU" = Microsoft Visual SourceSafe 2005 - ENU
"Microsoft Visual Studio 2005 Professional Edition - ENU" = Microsoft Visual Studio 2005 Professional Edition - ENU
"Microsoft Visual Studio 2005 Team Explorer - ENU" = Microsoft Visual Studio 2005 Team Explorer - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Team Explorer - ENU" = Microsoft Visual Studio 2008 Team Explorer - ENU
"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio 2010 Ultimate - ENU" = Microsoft Visual Studio 2010 Ultimate - ENU
"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools
"Microsoft Visual Studio Team System 2008 Team Suite - ENU" = Microsoft Visual Studio Team System 2008 Team Suite - ENU
"Microsoft XNA Game Studio 2.0" = Microsoft XNA Game Studio 2.0
"MilkShape 3D 1.7.10" = MilkShape 3D 1.7.10
"Mozilla Firefox 7.0 (x86 en-US)" = Mozilla Firefox 7.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"myibay eBay bid sniper_is1" = Myibay Auction bid sniper for eBay 1.0.43
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PCFriendly" = PCFriendly
"PeerGuardian_is1" = PeerGuardian 2.0
"PROR" = Microsoft Office Professional 2007
"pRTI 1516 LE v3.1.1" = pRTI 1516 LE v3.1.1
"PVK-Import" = Microsoft PVK Import (Remove only)
"RADVideo" = RAD Video Tools
"RealPlayer 6.0" = RealPlayer Basic
"ScriptEase_is1" = ScriptEase
"SDKSetup_6.0.5536.0" = Microsoft Windows Software Development Kit (5536.0.2)
"SecondLife" = SecondLife (remove only)
"SecondLifeViewer2" = SecondLifeViewer2 (remove only)
"SimpleOCR 3.1" = SimpleOCR 3.1
"ST5UNST #1" = 3DOBuilder+
"ST6UNST #2" = GAF Builder Pro 2.5
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TAE Version 1 beta 1" = TAE Version 1 beta 1
"Tao" = Tao 1.2.0
"TMPGEnc PLUS v2.57.41.146" = TMPGEnc PLUS v2.57.41.146
"Total Annihilation" = Total Annihilation
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"TrueVision3D 6.2_is1" = TrueVision3D 6.2
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"Visual Studio 2005 Extensions for Windows Workflow Foundation" = Visual Studio 2005 Extensions for Windows Workflow Foundation
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VTP Software_is1" = VTP Software 2006.04.16
"Web_3.0.3813.0" = Microsoft Expression Web 3
"Web_4.0.1303.0" = Microsoft Expression Web 4
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Creator v2.5+" = World Creator v2.5+
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"XNA Game Studio 4.0" = Microsoft XNA Game Studio 4.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"yFiles for Silverlight Complete 2.0_is1" = yFiles for Silverlight Complete 2.0.0.1 Evaluation
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"06735F25C3FC3976F627B13FE81EABF2F7752BDC" = Pivot Collection Tool for Microsoft Office Excel
"09d972fdeb31eaa0" = WPF TA unit
"0c1129c2013fbb69" = Total Annihilation Redux
"1851220018.localhost" = TA3DUnit Application
"309a46b1dc89b774" = Dell Driver Download Manager
"3dc17cdbaba1d704" = A World At War
"662641322.localhost" = DarkReignSilverlight Application
"7832512e0f25051d" = Shazzam
"943480793.localhost" = DarkReignSilverlight Application
"d68d21f7865d637e" = Zam3D Test
"e870fb5d023e06e6" = WpfApplication_test
"f407565ed1458231" = WPF Flash Integration
"Google Chrome" = Google Chrome
"yFiles for Silverlight Complete 2.0 Programming Samples_is1" = yFiles for Silverlight Complete 2.0.0.1 Evaluation Programming
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 28/09/2011 3:50:02 PM | Computer Name = NEBULA | Source = Windows Search Service | ID = 3102
Description = The per-user filter pool for session 0 could not be added. Details:
The
operation being requested was not performed because the user has not logged on
to the network. The specified service does not exist. (0x800704dd) For more information
visit http://www.microsoft.com/servers/redirect/…ntredirect2.asp
Error - 28/09/2011 3:50:12 PM | Computer Name = NEBULA | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 28/09/2011 3:50:29 PM | Computer Name = NEBULA | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 3:52:14 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 3:52:30 PM | Computer Name = NEBULA | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 28/09/2011 4:30:56 PM | Computer Name = NEBULA | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog For more information visit http://www.microsoft.com/servers/redirect/…ntredirect2.asp
Error - 28/09/2011 5:39:25 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 28/09/2011 5:39:25 PM | Computer Name = NEBULA | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
[ OSession Events ]
Error - 22/10/2009 4:26:26 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18469
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 03/03/2010 3:33:43 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 15426
seconds with 1980 seconds of active time. This session ended with a crash.
Error - 15/03/2010 1:55:51 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 268545
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 26/04/2010 11:45:07 AM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1235
seconds with 300 seconds of active time. This session ended with a crash.
Error - 24/11/2010 7:00:34 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28226
seconds with 2760 seconds of active time. This session ended with a crash.
Error - 06/01/2011 3:43:49 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16236
seconds with 600 seconds of active time. This session ended with a crash.
Error - 18/02/2011 11:47:21 AM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1831
seconds with 360 seconds of active time. This session ended with a crash.
Error - 02/05/2011 6:35:39 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 28440
seconds with 2280 seconds of active time. This session ended with a crash.
Error - 13/06/2011 3:38:39 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 16193
seconds with 1500 seconds of active time. This session ended with a crash.
Error - 15/09/2011 3:29:49 PM | Computer Name = NEBULA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 15842
seconds with 900 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7001
Description = The Wireless Zero Configuration service depends on the NDIS Usermode
I/O Protocol service which failed to start because of the following error: %%1058
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2
Error - 28/09/2011 3:53:50 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
nvraid
Error - 28/09/2011 3:56:24 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 3:57:22 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7034
Description = The LiveUpdate service terminated unexpectedly. It has done this
1 time(s).
Error - 28/09/2011 3:57:32 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 3:59:35 PM | Computer Name = NEBULA | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 28/09/2011 4:33:07 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 28/09/2011 4:33:21 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Microsoft Antimalware Service
service, but this action failed with the following error: %%1056
Error - 28/09/2011 4:38:28 PM | Computer Name = NEBULA | Source = Service Control Manager | ID = 7034
Description = The LiveUpdate Notice Service service terminated unexpectedly. It
has done this 1 time(s).
< End of report >