Please find OTL scan log for pc that is running slow and has multiple pop ups of a black box screen with just
run32.dll.exe in title. Scan using Spybot and Malwarebytes has been clean. Also using AVG free with no issues know.
Do I need to scan other user profiles on this PC as well?
DoOTL logfile created on: 10/24/2011 3:50:50 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.85 Mb Total Physical Memory | 341.64 Mb Available Physical Memory | 33.43% Memory free
2.40 Gb Paging File | 1.42 Gb Available in Paging File | 59.30% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 54.15 Gb Free Space | 23.74% Space Free | Partition Type: NTFS
Computer Name: FAMILYROOM1206 | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Brian\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe (Google)
PRC - C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe (Intel Corporation)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\WINDOWS\system32\hooks.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\tmdbg.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\PcSSE.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEHook.dll ()
MOD - C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe ()
========== Win32 Services (SafeList) ==========
SRV - (Workstation (lanmanworkstation)) Workstation (lanmanworkstation) – File not found
SRV - (ExpatTrayService) – C:\Program Files\Expat Shield\bin\ExpatTrayService.exe ()
SRV - (ExpatShieldService) – C:\Program Files\Expat Shield\bin\openvpnas.exe ()
SRV - (ExpatWd) – C:\Program Files\Expat Shield\bin\hsswd.exe ()
SRV - (ExpatSrv) – C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (PublicPreviewTurbineMessageService) – C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineMessageService.exe (Turbine, Inc.)
SRV - (PublicPreviewTurbineNetworkService) – C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineNetworkService.exe (Turbine, Inc.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (GoogleDesktopManager) – C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (Google)
SRV - (PcCtlCom) – C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
SRV - (Tmntsrv) – C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ELService) Intel® – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe (Intel Corporation)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (HssDrv) – C:\WINDOWS\system32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\Elmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\Elkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\Elmou.sys (Intel Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\Elhid.sys (Intel Corporation)
DRV - (DSproct) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (Politecnico di Torino)
DRV - (SDDMI2) – C:\WINDOWS\system32\DDMI2.sys (Gteko Ltd.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=3061211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=3061211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=3061211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@gametap.com/npgametaptool,version=1.0: C:\Program Files\GameTap\bin\Release\npgametaptool.dll (Turner Broadcasting System, Inc. ("TBS"))
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\Documents and Settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\octoprogram-L03-NMS1101262_SUA_000\npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/22 10:08:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/30 00:16:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/30 00:16:58 | 000,000,000 | —D | M]
[2008/12/07 16:10:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Brian\Application Data\Mozilla\Extensions
[2009/03/06 20:38:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\o4mvb5ed.default\extensions
[2009/03/02 12:37:36 | 000,001,739 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\o4mvb5ed.default\searchplugins\aim-search.xml
[2011/10/04 22:59:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/07 22:33:36 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2009/12/22 10:08:37 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG8\FIREFOX
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2010/06/23 00:06:32 | 000,001,490 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\AOL Search.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - Extension: Entanglement = C:\Documents and Settings\Brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Skype Extension = C:\Documents and Settings\Brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7280_0\
CHR - Extension: Poppit = C:\Documents and Settings\Brian\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2008/11/06 23:19:16 | 000,287,238 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 9901 more lines…
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {d3d4e26a-0509-4013-87c2-2a522206a14e} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [pccguide.exe] C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [SysMon] C:\Documents and Settings\All Users\Application Data\SysMon\SysMon.dll (Amplusnet)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe ()
O4 - HKCU..\Run: [OE_OEM] C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10m_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1198700661371 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1198701034665 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0CAAA2E6-3D17-490B-994C-B5EDB1AAC8C6}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Brian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/10/24 15:45:32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Brian\Desktop\HiJackThis (3).exe
[2011/10/24 15:39:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Desktop\HiJack
[2011/10/03 12:31:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\My Documents\Timmy Stuff
[2011/09/29 03:04:48 | 000,000,000 | —D | C] – C:\d6b86374d9bddaab6960ceaed83b00
[2011/09/27 11:08:39 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/09/27 03:18:07 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2011/09/26 21:33:53 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2011/09/26 21:33:52 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/09/26 21:29:47 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/09/26 21:26:30 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/09/26 21:24:36 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/09/26 21:20:03 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/09/26 21:20:02 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2011/09/26 21:03:24 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/09/26 21:03:03 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/09/26 20:54:51 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2011/09/26 20:41:22 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/09/26 20:39:00 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/09/26 20:38:49 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2011/09/26 11:41:20 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleaccrc.dll
[2011/09/26 09:50:31 | 000,000,000 | R–D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\Administrative Tools
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Brian\My Documents\*.tmp files -> C:\Documents and Settings\Brian\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/24 15:47:32 | 000,000,878 | —- | M] () – C:\Documents and Settings\Brian\Desktop\Shortcut to OTL.lnk
[2011/10/24 15:45:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Brian\Desktop\HiJackThis (3).exe
[2011/10/24 03:17:01 | 085,009,718 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/10/21 11:17:53 | 000,202,956 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/10/21 11:17:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/21 11:17:02 | 1071,562,752 | -HS- | M] () – C:\hiberfil.sys
[2011/10/20 23:16:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/14 03:26:57 | 000,280,536 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/14 03:09:14 | 000,445,792 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/14 03:09:14 | 000,072,998 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/14 03:05:44 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/09/26 18:22:12 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/26 11:41:20 | 000,611,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\uiautomationcore.dll
[2011/09/26 11:41:20 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\oleaccrc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleaccrc.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Brian\My Documents\*.tmp files -> C:\Documents and Settings\Brian\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/24 15:47:32 | 000,000,878 | —- | C] () – C:\Documents and Settings\Brian\Desktop\Shortcut to OTL.lnk
[2011/04/07 22:36:16 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/02 19:24:55 | 000,723,294 | —- | C] () – C:\WINDOWS\unins001.exe
[2011/04/02 19:24:55 | 000,135,634 | —- | C] () – C:\WINDOWS\unins001.dat
[2009/07/12 21:19:50 | 000,138,944 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/07/12 21:19:49 | 000,022,328 | —- | C] () – C:\Documents and Settings\Brian\Application Data\PnkBstrK.sys
[2009/07/12 21:19:27 | 000,189,784 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/07/12 21:19:25 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/07/12 21:19:21 | 002,246,144 | —- | C] () – C:\WINDOWS\System32\pbsvc.exe
[2008/12/04 05:35:20 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\hooks.dll
[2008/10/28 18:40:48 | 000,173,552 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/09/20 22:28:40 | 000,058,708 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/05/27 19:25:40 | 000,006,478 | —- | C] () – C:\WINDOWS\scedunin.dat
[2008/05/25 11:38:56 | 000,691,545 | —- | C] () – C:\WINDOWS\unins000.exe
[2008/05/25 11:38:56 | 000,002,549 | —- | C] () – C:\WINDOWS\unins000.dat
[2008/05/16 14:01:00 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/16 14:01:00 | 001,657,376 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2008/05/16 14:01:00 | 001,503,232 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/16 14:01:00 | 001,346,080 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/05/16 14:01:00 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/16 14:01:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/16 14:01:00 | 000,449,056 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/05/16 14:01:00 | 000,436,768 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/05/16 14:01:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2008/05/08 03:20:40 | 000,005,120 | —- | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/09 18:36:11 | 000,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2007/10/25 11:26:48 | 000,053,248 | —- | C] () – C:\WINDOWS\bdoscandel.exe
[2007/10/25 11:26:48 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2007/09/30 11:30:12 | 000,003,292 | —- | C] () – C:\Documents and Settings\Brian\Application Data\wklnhst.dat
[2007/09/02 23:10:50 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2007/09/02 23:02:47 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Equalizer
[2007/09/02 23:02:47 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2007/09/02 23:02:47 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\External Build System
[2007/04/12 18:40:18 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/04/01 21:26:08 | 000,000,047 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/26 11:45:18 | 000,071,208 | —- | C] () – C:\WINDOWS\System32\PhysXLoader.dll
[2007/02/20 15:59:08 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/02/20 15:59:06 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/02/20 15:59:04 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/02/03 06:57:46 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/01/21 22:01:38 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2007/01/13 15:16:11 | 000,002,828 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/13 15:16:11 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\6A0F9E10A2.sys
[2007/01/06 15:01:24 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2007/01/06 14:52:25 | 000,118,642 | —- | C] () – C:\WINDOWS\hpoins09.dat
[2006/12/28 21:43:47 | 000,011,697 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2006/12/26 13:16:44 | 000,000,128 | —- | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\fusioncache.dat
[2006/12/11 21:47:31 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/12/11 21:41:11 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/11 21:34:55 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/12/11 21:30:18 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\Elusetup.exe
[2006/12/11 21:10:52 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/12/11 21:10:28 | 000,000,393 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/03/09 13:29:36 | 000,011,645 | —- | C] () – C:\WINDOWS\hpomdl09.dat
[2005/11/10 09:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 05:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 05:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 05:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 05:27:59 | 000,280,536 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 05:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 05:18:33 | 000,445,792 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 05:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 05:18:33 | 000,072,998 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 05:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 05:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 05:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 05:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 05:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 05:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 05:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 05:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 15:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/12/10 04:42:08 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 04:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2009/03/02 12:26:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/06/23 00:06:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2009/03/02 12:26:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2008/03/17 15:01:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CCP
[2005/08/16 21:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2007/09/02 23:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/03/01 17:17:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap
[2007/10/25 15:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/07/12 21:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\id Software
[2007/09/02 23:21:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2008/08/29 12:38:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2007/09/02 23:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/04/22 04:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SysMon
[2009/01/01 13:56:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/24 18:34:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Turbine
[2007/09/02 23:10:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/03/02 12:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/01/01 14:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/12/11 21:38:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2008/02/06 22:02:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
[2010/08/23 18:05:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/01/09 18:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\acccore
[2007/03/04 01:53:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Command & Conquer 3 Tiberium Wars Demo
[2008/04/11 17:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Electronic Arts
[2006/12/27 10:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\EVEMon
[2008/06/25 16:32:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\GarageGames
[2008/08/29 16:42:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\GetRightToGo
[2009/07/12 21:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\id Software
[2010/05/04 21:32:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Image Zone Express
[2008/03/28 02:45:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Mount&Blade;
[2007/07/20 11:16:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\NCSoft
[2008/09/11 18:40:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Nikon
[2007/12/31 22:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Sierra Entertainment
[2008/06/20 14:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\SPORE Creature Creator
[2009/05/03 23:37:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\SystemRequirementsLab
[2007/09/30 11:30:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Template
[2009/02/21 12:15:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\The Creative Assembly
[2007/12/23 14:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\The Witcher Demo
[2007/04/07 13:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\Turbine
[2007/01/01 14:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\WildTangent
[2009/01/01 14:10:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Brian\Application Data\WinPatrol
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/05/28 03:22:43 | 000,000,659 | —- | M] () – C:\aaw7boot.log
[2006/09/21 12:02:46 | 001,116,109 | —- | M] () – C:\Apr2006_d3dx9_30_x86.cab
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/12/31 21:53:50 | 000,000,221 | RHS- | M] () – C:\boot.ini
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/12/11 21:13:14 | 000,007,123 | RH– | M] () – C:\dell.sdr
[2008/08/27 16:29:09 | 000,135,168 | —- | M] (Netsurfer, Inc.) – C:\DHCPD.exe
[2008/08/27 16:29:10 | 000,458,752 | —- | M] (Netsurfer, Inc.) – C:\Dist32.dll
[2006/09/21 12:02:46 | 000,074,520 | —- | M] (Microsoft Corporation) – C:\DSETUP.dll
[2006/09/21 12:02:46 | 002,248,984 | —- | M] (Microsoft Corporation) – C:\dsetup32.dll
[2006/09/21 12:02:46 | 000,041,995 | —- | M] () – C:\dxdllreg_x86.cab
[2006/09/21 12:02:46 | 000,484,632 | —- | M] (Microsoft Corporation) – C:\DXSETUP.exe
[2006/09/21 12:02:46 | 000,082,338 | —- | M] () – C:\dxupdate.cab
[2011/10/21 11:17:02 | 1071,562,752 | -HS- | M] () – C:\hiberfil.sys
[2011/10/24 15:49:14 | 000,388,019 | —- | M] () – C:\hpfr5100.log
[2009/07/25 18:09:46 | 000,000,079 | —- | M] () – C:\ifsverifylog.txt
[2006/12/28 17:20:42 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/06/23 00:07:09 | 000,002,919 | -H– | M] () – C:\IPH.PH
[2007/12/22 14:47:49 | 000,006,722 | —- | M] () – C:\logfile
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/08/27 16:29:09 | 000,045,056 | —- | M] (Netsurfer, Inc.) – C:\NetUtils.dll
[2008/08/27 16:29:05 | 000,000,036 | —- | M] () – C:\ns_info.ini
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/04 15:24:19 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/21 11:17:00 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2008/08/27 16:29:09 | 000,790,528 | —- | M] (Netsurfer, Inc.) – C:\setup32.exe
[2008/08/27 16:30:26 | 000,000,000 | —- | M] () – C:\SoftCast.fl
[2008/08/27 16:38:04 | 000,000,000 | —- | M] () – C:\SoftCast.ini
[2006/12/11 21:42:21 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2008/08/27 16:29:10 | 000,344,064 | —- | M] (Netsurfer, Inc.) – C:\Yampa.exe
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 16:43:24 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/04 15:30:35 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2006/07/21 14:03:18 | 000,053,248 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\NetZero - First Three Months Free!.exe
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2006/12/11 21:29:59 | 000,492,256 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\TRANSFORMS=1033.mst
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/12/26 13:17:16 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 05:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/05/03 23:38:56 | 080,754,536 | —- | M] (NVIDIA Corporation ) – C:\Documents and Settings\Brian\Desktop\182.50_geforce_winxp_32bit_english_whql.exe
[2010/12/25 13:57:03 | 000,266,576 | —- | M] () – C:\Documents and Settings\Brian\Desktop\ExpatShield-DM-232.exe
[2009/05/03 21:31:28 | 000,499,712 | —- | M] (Fallen Earth, LLC) – C:\Documents and Settings\Brian\Desktop\FallenEarthAlphaDownloader.exe
[2011/10/24 15:45:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Brian\Desktop\HiJackThis (3).exe
[2010/12/25 13:58:27 | 005,888,552 | —- | M] () – C:\Documents and Settings\Brian\Desktop\HSS-1.56-install-anchorfree-232-expatshield.exe
[2009/05/19 18:40:28 | 001,878,888 | —- | M] (Adobe Systems Incorporated) – C:\Documents and Settings\Brian\Desktop\install_flash_player.exe
[2009/03/15 00:27:52 | 122,889,958 | —- | M] (Frictional Games ) – C:\Documents and Settings\Brian\Desktop\penumbra_overture_demo_1.0.3.exe
[2009/02/13 15:39:51 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Brian\Desktop\spybotsd162.exe
[2007/01/20 02:12:15 | 021,540,864 | —- | M] (Cavedog Entertainment) – C:\Documents and Settings\Brian\Desktop\tadinst.exe
[2005/07/14 12:47:02 | 000,933,888 | —- | M] () – C:\Documents and Settings\Brian\Desktop\Ventrilo.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-21 15:51:46
========== Alternate Data Streams ==========
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEB71B81
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 10/24/2011 3:50:50 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1021.85 Mb Total Physical Memory | 341.64 Mb Available Physical Memory | 33.43% Memory free
2.40 Gb Paging File | 1.42 Gb Available in Paging File | 59.30% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.13 Gb Total Space | 54.15 Gb Free Space | 23.74% Space Free | Partition Type: NTFS
Computer Name: FAMILYROOM1206 | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" = C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Dark Oberon\dark-oberon.exe" = C:\Program Files\Dark Oberon\dark-oberon.exe:*:Enabled:dark-oberon
"C:\Program Files\Armada Online Alpha\ArmadaAlpha\ArmadaOnline.exe" = C:\Program Files\Armada Online Alpha\ArmadaAlpha\ArmadaOnline.exe:*:Enabled:ArmadaOnline
"C:\Program Files\Tremulous\tremulous.exe" = C:\Program Files\Tremulous\tremulous.exe:*:Enabled:tremulous
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – (THQ Canada Inc.)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\NAMCO BANDAI Games\Warhammer Mark of Chaos DEMO\Warhammer_DEMO.exe" = C:\Program Files\NAMCO BANDAI Games\Warhammer Mark of Chaos DEMO\Warhammer_DEMO.exe:*:Enabled:Warhammer®: Mark of Chaos™ Single Player Demo
"C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe" = C:\Program Files\Turbine\The Lord of the Rings Online\lotroclient.exe:*:Enabled:lotroclient.exe – (Turbine, Inc.)
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Home Networking Application
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\RealVNC\VNC4\winvnc4.exe" = C:\Program Files\RealVNC\VNC4\winvnc4.exe:*:Enabled:winvnc4 – (RealVNC Ltd.)
"C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" = C:\Documents and Settings\Brian\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Disabled:OctoshapeClient – ()
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare
"C:\Program Files\CCP\EVE\bin\ExeFile.exe" = C:\Program Files\CCP\EVE\bin\ExeFile.exe:*:Enabled:CCP ExeFile – (CCP hf.)
"C:\Program Files\SEGA\Universe At War Earth Assault (DEMO)\UAWEA.exe" = C:\Program Files\SEGA\Universe At War Earth Assault (DEMO)\UAWEA.exe:*:Enabled:Universe at War: Earth Assault Application
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\THQ\Dawn of War - Soulstorm Demo\Soulstorm.exe" = C:\Program Files\THQ\Dawn of War - Soulstorm Demo\Soulstorm.exe:*:Enabled:Soulstorm
"C:\Program Files\Savage 2 - A Tortured Soul\savage2.exe" = C:\Program Files\Savage 2 - A Tortured Soul\savage2.exe:*:Disabled:savage2
"C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe" = C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:*:Enabled:Sins of a Solar Empire – (Ironclad Games)
"C:\Documents and Settings\All Users\Application Data\GameTap\games\140000150\data\UruExplorer.exe" = C:\Documents and Settings\All Users\Application Data\GameTap\games\140000150\data\UruExplorer.exe:*:Disabled:UruExplorer – ()
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Program Files\NCsoft\Exteel\System\Exteel.exe" = C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel
"C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" = C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe:*:Enabled:pccguide – (Trend Micro Inc.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost
"C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineMessageService.exe" = C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineMessageService.exe:*:Enabled:TurbineMessageService – (Turbine, Inc.)
"C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineNetworkService.exe" = C:\Program Files\Turbine\Turbine Download Manager - Lamannia\TurbineNetworkService.exe:*:Enabled:TurbineNetworkService – (Turbine, Inc.)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\Steam\steamapps\common\rome total war gold\RomeTW.exe" = C:\Program Files\Steam\steamapps\common\rome total war gold\RomeTW.exe:*:Enabled:Rome: Total War Gold Edition – (The Creative Assembly Ltd)
"C:\Program Files\Steam\steamapps\common\rome total war gold\RomeTW-BI.exe" = C:\Program Files\Steam\steamapps\common\rome total war gold\RomeTW-BI.exe:*:Enabled:Rome: Total War Gold Edition – (The Creative Assembly Ltd)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\steamapps\common\medieval ii total war\Launcher.exe" = C:\Program Files\Steam\steamapps\common\medieval ii total war\Launcher.exe:*:Enabled:Medieval II: Total War Kingdoms – ( )
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}" = Intel® PRO Network Connections
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{15C165F1-1DAE-4476-AFB6-8723729B41E7}" = hp deskjet 5100
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}" = EarthLink Setup Files
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = PlayNC Launcher
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6589F749-4A50-4B15-BE59-14626F2D3B02}_is1" = Penumbra Episode 1 Demo
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67E158AF-8856-4337-B483-EA21930786AF}" = GameTap
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{739126B3-1B80-4F9F-8D59-312A19633E1A}_is1" = Quick Web Player
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7ADE3A47-B425-45E9-8FF6-11BE2B775645}" = Corel Snapfire Plus
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7EAB1D85-7BA3-47C1-BBF7-A0EBC241DB94}" = Intel® Viiv™ Software
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{82448C0D-FB2A-4E10-9F2C-F404F067A85B}" = FallenEarth
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{85EBB283-65AF-4C53-9EBE-7C0A232762F7}" = AGEIA PhysX v7.03.21
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{924EB80F-C2BB-4B9F-8412-88BBA937393F}" = MobileMe Control Panel
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9FC8D8F8-AF3A-4488-98AF-51C6DEC732F2}" = c3100_Help
"{A1BC9F13-59FE-43E4-8498-DF5A721196C5}" = BlackBerry USB Drivers
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F5421F-DA70-4C77-BB97-8D77EC33ED5E}" = HP Photosmart and Deskjet 7.0.A
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C325F588-D6B1-4A7F-B6A2-914C75DDA348}" = Morrowind
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EA8C73AA-3D75-44C9-87A2-8E945FC5FEE6}" = Trend Micro PC-cillin Internet Security 14
"{EB8C9964-09AC-48bf-8B98-027609C78251}" = C3100
"{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41}" = Sins of a Solar Empire
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F5C521B6-1AF2-432C-A061-E79E2141A32F}" = Quake Live Mozilla Plugin
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB26A501-6BA6-459B-89AA-9736730752FB}" = VoiceOver Kit
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"{FF39FC01-819B-42E4-AE49-1968AF12DDD4}" = Dawn of War - Dark Crusade
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™: Shadows of Angmar™ v06.11.30.134
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM Toolbar" = AIM Toolbar
"AIM_6" = AIM 6
"AIMTunes" = AIMTunes
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"AVG8Uninstall" = AVG Free 8.5
"b35d407a-d5d8-4a2e-91bf-1d95b9f3f590_is1" = Turbine Download Manager - PublicPreview
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Dell Game Console" = Dell Game Console
"Deus Ex" = Deus Ex
"ef57af2e-47b7-4e04-8c4b-48fb10fc34f0_is1" = Dungeons and Dragons Online™ - Lamannia - PublicPreview
"EL" = Intel® Quick Resume Technology Drivers
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EndItAll_is1" = EndItAll 2.0
"ERUNT_is1" = ERUNT 1.1j
"ESPNMotion" = ESPNMotion
"EVE" = EVE-ONLINE (remove only)
"ExpatShield" = Expat Shield 1.56
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Graboid Video" = Graboid Video 2.03
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mount&Blade;" = Mount&Blade;
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer Basic
"RealVNC_is1" = VNC Free Edition 4.1.2
"SearchAssist" = SearchAssist
"Setup Support for ShopToWin" = Setup Support for ShopToWin 1.0
"Shop to Win 11" = Shop to Win 11
"Sins of a Solar Empire" = Sins of a Solar Empire
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"SpywareBlaster_is1" = SpywareBlaster 4.1
"Starcraft Shareware(ED)" = Starcraft Shareware(ED)
"Steam App 15660" = Warhammer 40,000: Dawn of War II - Beta
"Steam App 280" = Half-Life: Source
"Steam App 4700" = Medieval II: Total War
"Steam App 4760" = Rome: Total War Gold Edition
"Steam App 4780" = Medieval II: Total War Kingdoms
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TmPcc" = Trend Micro PC-cillin Internet Security 14
"uTorrent" = µTorrent
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.1
"Warhammer Online - Age of Reckoning" = Warhammer Online - Age of Reckoning
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2008
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape Streaming Services" = Octoshape Streaming Services
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/23/2011 10:58:02 PM | Computer Name = FAMILYROOM1206 | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
module sysmon.dll, version 1.0.0.1, fault address 0x00005cab.
Error - 10/23/2011 11:46:30 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = Connections: blacklisted: 85.214.133.89
Error - 10/23/2011 11:46:51 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = Connections: blacklisted: 85.214.133.89
Error - 10/23/2011 11:47:27 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = Connections: blacklisted: 85.214.133.89
Error - 10/23/2011 11:48:22 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = Connections: blacklisted: 85.214.133.89
Error - 10/23/2011 11:49:21 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = Connections: blacklisted: 85.214.133.89
Error - 10/24/2011 9:59:42 AM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = SDisplay: hook subsystem failed to initialise
Error - 10/24/2011 12:04:30 PM | Computer Name = FAMILYROOM1206 | Source = WinVNC4 | ID = 1
Description = SDisplay: hook subsystem failed to initialise
Error - 10/24/2011 3:33:40 PM | Computer Name = FAMILYROOM1206 | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
module sysmon.dll, version 1.0.0.1, fault address 0x00005cab.
Error - 10/24/2011 3:46:36 PM | Computer Name = FAMILYROOM1206 | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 5.1.2600.5512, faulting
module sysmon.dll, version 1.0.0.1, fault address 0x00005cab.
[ System Events ]
Error - 10/14/2011 3:29:21 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7001
Description = The Trend Micro Personal Firewall service depends on the Trend Micro
Common Firewall Service service which failed to start because of the following
error: %%1058
Error - 10/15/2011 7:22:19 AM | Computer Name = FAMILYROOM1206 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0019D103595C has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 10/21/2011 11:20:49 AM | Computer Name = FAMILYROOM1206 | Source = DCOM | ID = 10010
Description = The server {7F6316B4-4D69-4765-B0A3-B2598F2FA80A} did not register
with DCOM within the required timeout.
Error - 10/21/2011 11:20:52 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7000
Description = The Trend Micro Common Firewall Service service failed to start due
to the following error: %%1058
Error - 10/21/2011 11:20:52 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7001
Description = The Trend Micro Personal Firewall service depends on the Trend Micro
Common Firewall Service service which failed to start because of the following
error: %%1058
Error - 10/21/2011 11:22:04 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.
Error - 10/21/2011 11:22:04 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.
Error - 10/21/2011 11:22:04 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
Error - 10/21/2011 11:22:25 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7000
Description = The Trend Micro Common Firewall Service service failed to start due
to the following error: %%1058
Error - 10/21/2011 11:22:25 AM | Computer Name = FAMILYROOM1206 | Source = Service Control Manager | ID = 7001
Description = The Trend Micro Personal Firewall service depends on the Trend Micro
Common Firewall Service service which failed to start because of the following
error: %%1058
< End of report >