i'm not sure that I ever had zone alarm installed on this system. I originally bought it off a friend… they have had it installed prior to me purchasing it…
as requested:
OTL.txt:
OTL logfile created on: 15/11/2011 10:33:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.51% Memory free
5.85 Gb Paging File | 5.49 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 33.83 Gb Free Space | 45.41% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 789.34 Gb Free Space | 84.74% Space Free | Partition Type: NTFS
Computer Name: USER-A6148CA035 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Alwil Software\Avast5\defs\11111501\algo.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\defs\11111501\aswRep.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\pdf.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avutil-51.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avformat-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\avcodec-53.dll ()
MOD - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\gcswf32.dll ()
MOD - C:\Program Files\Alwil Software\Avast5\aswDld.dll ()
MOD - C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (ScsiAccess) – C:\Program Files\Photodex\ProShowGold\scsiaccess.exe ()
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (NIHardwareService) – C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (Native Instruments GmbH)
========== Driver Services (SafeList) ==========
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LVUVC) Logitech Webcam 120(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ca.msn.com/?lang=en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.8.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.5.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.1002
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.4.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.19.1667
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2202
FF - prefs.js..extensions.enabledItems: [removed]:5.0.0.2417
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2200
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2207
FF - prefs.js..extensions.enabledItems: [removed]:3.2.0.2203
FF - prefs.js..extensions.enabledItems: [removed]:1.7.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667
FF - prefs.js..extensions.enabledItems: [removed]:1.0.7.1667
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 23:15:34 | 000,000,000 | —D | M]
[2011/09/26 09:40:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/12/29 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/12/29 19:30:19 | 000,000,530 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Philips-Songbird\Profiles\zuwulc4y.default\searchplugins\e6e50a4b-2416-4c43-925e-dd78043fe347.xml
[2011/01/15 12:14:00 | 000,000,000 | —D | M] (Philips Branding) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:47 | 000,000,000 | —D | M] (QuickTime Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:29:48 | 000,000,000 | —D | M] (Windows Media Playback) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\PHILIPS-SONGBIRD\PROFILES\ZUWULC4Y.DEFAULT\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (7digital Music Store) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Artwork Extras) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (CD Rip Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:20 | 000,000,000 | —D | M] (Concerts) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (AAC Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:17 | 000,000,000 | —D | M] (H.264 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:15 | 000,000,000 | —D | M] (MP3 Encoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:16 | 000,000,000 | —D | M] (MPEG-4 Video Decoding Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (File association) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips GoGear Device Manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (gonzo) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:13 | 000,000,000 | —D | M] (Gracenote Metadata Lookup Provider) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:19 | 000,000,000 | —D | M] (mashTape) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:11 | 000,000,000 | —D | M] (MSC Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:12 | 000,000,000 | —D | M] (MTP Device Support) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:14 | 000,000,000 | —D | M] (Philips addon manager) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:09 | 000,000,000 | —D | M] (Philips auto msc-mtp switch) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips Skin) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:27:08 | 000,000,000 | —D | M] (Philips UI) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
[2010/12/29 19:26:09 | 000,000,000 | —D | M] (Purple Rain) – C:\PROGRAM FILES\PHILIPS\PHILIPS SONGBIRD\EXTENSIONS\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npPxPlay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2006/02/28 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1312.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1295222014093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0}
http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809}
http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}
http://content.systemrequirementslab.com.s…el_4.3.16.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Value error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F}
http://costco.pnimedia.com/upload/activex/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9512CBCA-D924-4335-85D9-3C24D6ACC0C2}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\crypt32chain: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cryptnet: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cscdll: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\Schedule: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\sclgntfy: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\SensLogn: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\termsrv: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - (Reg Error: Key error.) - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/05 13:13:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/03/06 06:54:34 | 000,000,000 | RH-D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2002/10/16 07:56:50 | 000,000,036 | RH– | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell - "" = AutoRun
O33 - MountPoints2\{110886aa-40f3-11df-bcc7-001320e7d5ea}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f2e80ca9-12fb-11e0-bd36-001320e7d5ea}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/15 08:09:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/14 17:05:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\Administrative Tools
[2011/11/14 17:04:26 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.pif
[2011/11/13 09:19:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Unity
[2011/11/13 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Unity
[2011/11/11 18:32:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/11/11 18:31:45 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/11/11 18:31:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/11/07 08:17:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\misfits show
[2011/10/19 17:41:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BAF9AC5D-AA3E-4138-92BE-340E0F0D21EA}
[2011/10/19 09:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Kevin Powe Portfolio
[2011/10/18 14:55:18 | 000,000,000 | —D | C] – C:\Program Files\IK Multimedia
[2011/10/18 13:36:18 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2011/10/18 13:36:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\ASIO4ALL v2
[2011/10/18 13:30:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{D69A48BF-7653-4AA8-94BC-5847522A4573}
[2011/10/18 13:25:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Digidesign
[2011/10/18 13:24:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
[2011/10/18 13:23:52 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
[2011/10/18 13:23:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Native Instruments
[2011/10/18 13:23:42 | 000,000,000 | —D | C] – C:\Program Files\Native Instruments
[2010/04/05 17:47:28 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Owner\Application Data\pcouffin.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/15 22:35:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003UA.job
[2011/11/15 22:28:08 | 000,000,671 | —- | M] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/11/15 20:01:40 | 000,000,664 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/11/15 08:10:04 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/15 02:35:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-515967899-682003330-1003Core.job
[2011/11/14 18:35:04 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/11/14 17:04:31 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.pif
[2011/11/13 14:07:44 | 000,012,378 | —- | M] () – C:\Documents and Settings\Owner\Desktop\new song titles.odt
[2011/11/13 10:32:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/13 10:24:10 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/12 13:05:04 | 000,228,352 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/09 21:08:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/08 22:54:14 | 000,444,106 | —- | M] () – C:\Documents and Settings\Owner\Desktop\2009311_16742_logo.jpg
[2011/11/08 18:12:37 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/08 18:12:37 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/08 18:07:15 | 001,299,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/05 08:59:32 | 000,101,272 | —- | M] () – C:\Documents and Settings\Owner\Desktop\450978_700b.jpg
[2011/10/31 13:51:34 | 000,019,834 | —- | M] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt
[2011/10/30 10:12:11 | 000,053,079 | —- | M] () – C:\Documents and Settings\Owner\Desktop\420615_460s.jpg
[2011/10/26 11:35:06 | 003,118,701 | —- | M] () – C:\Documents and Settings\Owner\Desktop\P1030175.JPG
[2011/10/20 09:08:12 | 000,014,238 | —- | M] () – C:\Documents and Settings\Owner\My Documents\rick solar logix ad.odt
[2011/10/19 11:35:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\System32\w3data.vss
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\System32\msvcsv60.dll
[2011/10/18 14:57:47 | 000,000,016 | —- | M] () – C:\WINDOWS\msocreg32.dat
[2011/10/18 13:36:18 | 000,000,813 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/10/18 13:30:23 | 000,000,811 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Guitar Rig 4.lnk
[2011/10/17 11:34:37 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/14 18:35:04 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/11/08 22:54:17 | 000,444,106 | —- | C] () – C:\Documents and Settings\Owner\Desktop\2009311_16742_logo.jpg
[2011/11/07 08:23:54 | 003,118,701 | —- | C] () – C:\Documents and Settings\Owner\Desktop\P1030175.JPG
[2011/11/05 08:59:37 | 000,101,272 | —- | C] () – C:\Documents and Settings\Owner\Desktop\450978_700b.jpg
[2011/11/03 13:31:12 | 000,000,664 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\d3d9caps.dat
[2011/10/31 13:51:32 | 000,019,834 | —- | C] () – C:\Documents and Settings\Owner\Desktop\idea for printing.odt
[2011/10/30 10:12:15 | 000,053,079 | —- | C] () – C:\Documents and Settings\Owner\Desktop\420615_460s.jpg
[2011/10/25 13:21:26 | 003,149,585 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Death Eater Mask #8 - Full Size.pdf
[2011/10/20 09:59:49 | 000,012,378 | —- | C] () – C:\Documents and Settings\Owner\Desktop\new song titles.odt
[2011/10/20 09:08:12 | 000,014,238 | —- | C] () – C:\Documents and Settings\Owner\My Documents\rick solar logix ad.odt
[2011/10/18 13:36:18 | 000,000,813 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/10/18 13:30:23 | 000,000,811 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Guitar Rig 4.lnk
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2011/10/10 13:51:08 | 000,000,016 | —- | C] () – C:\WINDOWS\msocreg32.dat
[2011/08/23 09:16:44 | 000,000,671 | —- | C] () – C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2011/08/20 20:49:42 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2011/08/20 20:49:34 | 000,650,752 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/08/20 20:49:34 | 000,243,200 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/08/20 20:49:33 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/07/17 12:25:25 | 000,000,022 | —- | C] () – C:\WINDOWS\cmm.dat
[2011/04/18 19:16:34 | 000,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2011/04/12 17:52:55 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2011/04/12 17:52:55 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2011/02/15 17:25:29 | 000,000,078 | —- | C] () – C:\WINDOWS\Simply.ini
[2011/01/28 21:32:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2011/01/27 18:01:44 | 000,830,408 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/27 17:36:44 | 000,000,193 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2011/01/20 18:25:02 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/10/12 20:20:09 | 000,228,352 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 21:37:01 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/27 03:03:20 | 010,829,656 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/07/27 03:03:20 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/07/27 03:03:18 | 000,290,648 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/07/27 02:56:04 | 000,090,411 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/04/27 21:06:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/22 23:13:45 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2010/04/21 21:18:05 | 000,168,057 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2010/04/21 21:18:05 | 000,000,632 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2010/04/06 12:10:00 | 000,000,873 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/04/05 20:30:37 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\AISAWFileMap.dll
[2010/04/05 20:29:53 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\Implode.dll
[2010/04/05 18:25:55 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/05 17:47:28 | 000,087,608 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inst.exe
[2010/04/05 17:47:28 | 000,007,887 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.cat
[2010/04/05 17:47:27 | 000,001,144 | —- | C] () – C:\Documents and Settings\Owner\Application Data\pcouffin.inf
[2010/04/05 13:15:27 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/05 13:10:46 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/05 08:58:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/05 08:57:31 | 001,299,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/05/20 12:44:46 | 000,051,392 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2006/02/28 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 07:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 07:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/03 16:04:16 | 000,139,280 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
========== LOP Check ==========
[2010/04/05 13:49:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/04/05 17:44:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2011/09/19 19:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/09/15 18:14:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\crack-pavka77-GP6.0.1-7840
[2010/11/23 15:25:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2010/05/02 20:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoldWave
[2010/09/15 18:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Guitar Pro 6
[2011/01/16 20:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2011/02/10 21:03:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/10/10 14:41:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Native Instruments
[2010/11/26 13:03:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Particles
[2010/09/08 14:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/05/09 10:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PIXELA
[2010/04/05 20:44:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sage Software
[2010/09/28 18:36:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2011/01/27 18:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soluto
[2010/09/17 17:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonoma Wire Works
[2011/10/19 11:30:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/30 19:43:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/02/10 20:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/18 13:24:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
[2011/10/19 17:58:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BAF9AC5D-AA3E-4138-92BE-340E0F0D21EA}
[2011/10/18 13:30:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{D69A48BF-7653-4AA8-94BC-5847522A4573}
[2011/10/18 13:23:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
[2011/03/18 12:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2010/04/05 17:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ashampoo
[2011/07/16 10:58:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Audacity
[2010/04/19 20:41:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Auslogics
[2010/05/15 19:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Facebook
[2011/08/09 09:24:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2010/07/10 17:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2011/08/08 12:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Guitar Pro 6
[2011/08/25 15:13:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IObit
[2010/10/02 16:40:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/04/05 21:14:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Netscape
[2011/08/16 14:23:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nullsoft
[2010/04/05 17:26:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/01/26 18:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2010/12/29 19:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Philips
[2010/12/29 19:27:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Philips-Songbird
[2010/04/05 21:13:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Photodex
[2011/01/16 20:41:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Registry Mechanic
[2010/11/26 13:02:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Specialbit
[2011/11/11 18:22:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/11/13 09:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Unity
[2011/11/15 21:41:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2011/11/15 22:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2010/09/08 14:43:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/05 16:37:33 | 001,434,405 | —- | M] () – C:\2108FP.TXT
[2010/04/05 13:13:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/03/09 18:30:42 | 000,748,354 | —- | M] () – C:\Backupjune15a1.CAB
[2011/04/07 10:40:34 | 000,750,694 | —- | M] () – C:\Backupmarch22.21.CAB
[2011/03/22 20:02:14 | 000,750,661 | —- | M] () – C:\Backupmarch221.CAB
[2011/10/19 11:35:36 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/04/05 13:13:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/18 10:50:45 | 000,017,250 | —- | M] () – C:\hpfr3320.log
[2010/04/18 10:50:45 | 000,000,522 | —- | M] () – C:\hpfr3320.xml
[2010/04/05 13:13:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/05 13:13:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/08 14:42:21 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/13 10:32:13 | 4290,772,992 | -HS- | M] () – C:\pagefile.sys
[2010/04/05 21:14:48 | 000,001,761 | —- | M] () – C:\photodex-presenter-install.log
[2011/02/24 13:44:35 | 001,875,200 | —- | M] () – C:\pshow-burn-debug-spti.log
[2011/02/24 13:44:35 | 000,002,541 | —- | M] () – C:\pshow-burn-debug.log
[2010/04/19 10:04:06 | 000,396,800 | -HS- | M] () – C:\Thumbs.db
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/04/05 13:13:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/06 14:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/02/23 09:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/04/05 08:56:35 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/04/05 08:56:35 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/04/05 08:56:35 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2010/06/21 22:32:45 | 000,001,778 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Adobe Stock Photos.lnk
[2010/09/08 14:49:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2010/04/21 21:32:21 | 000,001,018 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2010/09/08 14:49:14 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2010/04/05 13:13:33 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2011/01/16 18:53:12 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2010/04/07 19:09:15 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\µTorrent.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-11 07:02:05
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006/02/28 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2011/11/15 22:23:52 | 000,067,026 | —- | M] () MD5=88CE8AE42504042447A6B3F40E73E09B – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SCF >
[2006/02/28 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2006/02/28 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2006/02/28 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2011/11/15 17:42:54 | 000,109,644 | —- | M] () MD5=3AC7423B52D0B32F6C8F311B17C73F76 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2006/02/28 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2006/02/28 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1BFE92CC
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF0C5444
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EE323A4
< End of report >
and extrax.txt:
OTL Extras logfile created on: 15/11/2011 10:33:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.51% Memory free
5.85 Gb Paging File | 5.49 Gb Available in Paging File | 93.88% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 33.83 Gb Free Space | 45.41% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 789.34 Gb Free Space | 84.74% Space Free | Partition Type: NTFS
Computer Name: USER-A6148CA035 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp – (Nullsoft, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1D243F00-1389-4C63-A7E9-B17E967D1901}" = WebEx Record and Playback
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 29
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{497072FE-0A75-4E5C-A5B7-EB1FA67F66F1}" = DJ_AIO_05_F4400_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{51A79BE3-6AF4-4405-AC9A-E5F74FE20299}" = Simply Accounting by Sage 2007
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AEBB4A3-6878-4CEE-AD34-0F6958A983F0}" = HP Deskjet F4400 Printer Driver Software 13.0 Rel .5
"{5CA03ECF-B4A6-464B-9F5D-64D8B61B083F}" = Everio MediaBrowser
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{67F69C6C-8F2F-4C18-AAA8-9BD64BA1B7FB}" = HyperLoad - Wiffle Baseball
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.106e
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8EAD600D-1912-4DEF-92B5-0C7525E17ED2}" = F4400
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9C661DEF-3F08-468D-B5CE-B37E4771B5D2}" = MSN Toolbar
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD [removed]
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C7FAFC98-5ECC-40FC-B440-A5D5FE3A6A6E}" = Native Instruments Guitar Rig 4
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{D597935A-5F0E-44F8-A028-A0EF9C647D95}" = Native Instruments Rammfire
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA8C7558-D8F9-4D36-9487-C835B26A618B}" = Simply Accounting by Sage 2007
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EEEFE7A9-293E-4F5F-A114-81731A9C3826}" = Intel® Network Connections [removed]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFE32BFA-0F26-45BA-9209-4A6B11F74179}" = System Requirements Lab for Intel
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AndreaMosaic" = AndreaMosaic 3.32.3
"Any Video Converter_is1" = Any Video Converter 3.2.2
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"ASIO4ALL" = ASIO4ALL
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"EPSON Artisan 50 Series" = EPSON Artisan 50 Series Printer Uninstall
"GoldWave v5.55" = GoldWave v5.55
"Guitar Pro 5_is1" = Guitar Pro 5.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.6.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Guitar Rig 4" = Native Instruments Guitar Rig 4
"Native Instruments Rammfire" = Native Instruments Rammfire
"Native Instruments Service Center" = Native Instruments Service Center
"Philips Songbird" = Philips Songbird
"Photodex Presenter" = Photodex Presenter
"ProShow Gold" = ProShow Gold
"Registry Mechanic_is1" = Registry Mechanic 9.0
"uTorrent" = µTorrent
"Vector Magic" = Vector Magic
"VST Bridge_is1" = VST Bridge 1.1
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 04/04/2011 12:52:39 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application mplayerc.exe, version 6.4.9.1, faulting module
quicktime.qts, version 7.69.80.9, fault address 0x00009c3f.
Error - 07/04/2011 1:55:52 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application vmde.exe, version 0.0.0.0, faulting module vmde.exe,
version 0.0.0.0, fault address 0x000f45b7.
Error - 07/04/2011 3:58:43 PM | Computer Name = USER-A6148CA035 | Source = MsiInstaller | ID = 11500
Description =
Error - 07/04/2011 3:58:45 PM | Computer Name = USER-A6148CA035 | Source = MsiInstaller | ID = 11500
Description =
Error - 11/04/2011 10:02:39 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
gcswf32.dll, version 10.2.154.26, fault address 0x000c7a3f.
Error - 26/04/2011 4:05:12 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
pmp_p4s.dll, version 0.0.0.0, fault address 0x000017d3.
Error - 18/05/2011 11:51:18 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 12.0.725.0, fault address 0x00962453.
Error - 19/05/2011 10:18:32 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0001b21a.
Error - 30/05/2011 8:54:44 AM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.7.2830, faulting module
ml_bookmarks.dll, version 0.0.0.0, fault address 0x0000128b.
Error - 27/06/2011 8:59:13 PM | Computer Name = USER-A6148CA035 | Source = Application Error | ID = 1000
Description = Faulting application vmde.exe, version 0.0.0.0, faulting module vmde.exe,
version 0.0.0.0, fault address 0x000f45b7.
[ System Events ]
Error - 06/11/2011 9:02:19 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
Error - 08/11/2011 7:10:38 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.
Error - 08/11/2011 7:15:59 PM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).
Error - 10/11/2011 4:13:22 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.
Error - 10/11/2011 9:24:10 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).
Error - 13/11/2011 11:26:26 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.
Error - 13/11/2011 11:35:21 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.
Error - 13/11/2011 11:35:21 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7034
Description = The NIHardwareService service terminated unexpectedly. It has done
this 1 time(s).
Error - 15/11/2011 12:30:49 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.
Error - 15/11/2011 12:30:49 AM | Computer Name = USER-A6148CA035 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
< End of report >