aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-09 03:18:20
—————————–
03:18:20.038 OS Version: Windows 5.1.2600 Service Pack 3
03:18:20.038 Number of processors: 1 586 0x209
03:18:20.038 ComputerName: YOUR-3B54ED6EDD UserName: Owner
03:18:21.148 Initialize success
03:20:54.851 AVAST engine defs: 12010900
03:21:02.960 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
03:21:02.960 Disk 0 Vendor: WDC_WD400EB-11CPF0 06.04G06 Size: 38166MB BusType: 3
03:21:03.226 Disk 0 MBR read successfully
03:21:03.242 Disk 0 MBR scan
03:21:03.570 Disk 0 Windows XP default MBR code
03:21:03.648 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38162 MB offset 63
03:21:03.820 Disk 0 scanning sectors +78156225
03:21:04.023 Disk 0 scanning C:\WINNT\system32\drivers
03:21:51.663 Service scanning
03:21:53.882 Service MpKsldd2d8606 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKsldd2d8606.sys **LOCKED** 32
03:21:54.679 Modules scanning
03:22:08.163 Disk 0 trace - called modules:
03:22:08.195 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
03:22:08.195 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86379ab8]
03:22:08.195 3 CLASSPNP.SYS[f765bfd7] -> nt!IofCallDriver -> \Device\0000006a[0x863aa030]
03:22:08.195 5 ACPI.sys[f75c2620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x863e2d98]
03:22:08.898 AVAST engine scan C:\WINNT
03:22:39.632 AVAST engine scan C:\WINNT\system32
03:30:43.007 AVAST engine scan C:\WINNT\system32\drivers
03:31:40.585 AVAST engine scan C:\Documents and Settings\Owner
03:33:02.242 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
03:33:02.242 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
OTL logfile created on: 1/9/2012 3:36:19 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.73 Mb Total Physical Memory | 375.67 Mb Available Physical Memory | 37.02% Memory free
1.88 Gb Paging File | 1.39 Gb Available in Paging File | 73.97% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 23.32 Gb Free Space | 62.57% Space Free | Partition Type: NTFS
Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\desktop\OTL.exe
PRC - [2011/11/14 18:45:19 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINNT\explorer.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINNT\wanmpsvc.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/28 21:24:24 | 008,527,008 | —- | M] () – C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/14 18:45:17 | 001,989,592 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (AOLService)
SRV - File not found [Disabled | Stopped] – – (AOL ACS)
SRV - File not found [Disabled | Stopped] – – (ACDaemon)
SRV - File not found [Disabled | Stopped] – – (aawservice)
SRV - [2011/12/24 17:50:18 | 000,652,872 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/11/29 21:24:28 | 000,603,904 | —- | M] (TuneUp Software) [Disabled | Stopped] – C:\WINNT\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/27 12:26:42 | 000,398,336 | —- | M] (Ares Development Group) [On_Demand | Stopped] – C:\Program Files\Ares\chatServer.exe – (AresChatServer)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2007/01/04 15:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [On_Demand | Stopped] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/10/15 16:24:42 | 000,206,048 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINNT\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Running] – – (MpKsl2341df66)
DRV - [2012/01/09 03:15:59 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKsldd2d8606.sys – (MpKsldd2d8606)
DRV - [2012/01/08 06:11:25 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54E79FD9-7FE8-46FD-B13D-E63B75AAA7C6}\MpKslc414cb9b.sys – (MpKslc414cb9b)
DRV - [2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\WINNT\system32\drivers\mbam.sys – (MBAMProtector)
DRV - [2010/05/20 14:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/03/15 20:28:27 | 000,095,024 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINNT\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2010/02/11 06:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINNT\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2007/10/11 05:20:56 | 000,000,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/10/02 16:45:04 | 004,109,376 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:41:39 | 000,013,776 | —- | M] (Smart Link) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\recagent.sys – (RecAgent)
DRV - [2004/05/13 18:01:23 | 000,028,352 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\System32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/05/20 12:23:10 | 000,210,592 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\mtlmnt5.sys – (Mtlmnt5)
DRV - [2003/05/20 12:21:44 | 001,295,472 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\mtlstrm.sys – (Mtlstrm)
DRV - [2003/05/20 12:19:24 | 000,085,688 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\slnthal.sys – (SlNtHal)
DRV - [2003/05/19 14:30:02 | 000,169,120 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\ntmtlfax.sys – (NtMtlFax)
DRV - [2003/05/13 09:58:34 | 000,521,408 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slntamr.sys – (Slntamr)
DRV - [2003/01/16 23:19:32 | 000,039,348 | —- | M] (Vireo Software) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slwdmsup.sys – (SlWdmSup)
DRV - [2003/01/10 16:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/09/10 05:06:00 | 000,025,244 | —- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINNT\System32\drivers\aspi32.sys – (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://att.yahoo.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://att.yahoo.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 59636
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINNT\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/14 18:45:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/15 03:27:53 | 000,000,000 | —D | M]
[2008/07/02 13:47:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/05 22:54:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions
[2011/11/12 20:09:02 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/03/12 14:01:35 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/01/13 12:01:00 | 000,000,000 | —D | M] (Vacuum Places Improved) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default\extensions\[removed]
[2011/06/24 20:08:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HK5TJ3JO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/14 18:45:20 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 11:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2011/11/14 18:45:12 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/14 18:45:11 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2009/11/04 20:41:25 | 000,350,719 | R— | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.123haustiereundmehr.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 12024 more lines…
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] Narrator.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] Narrator.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - mswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - mswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1199318644546 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire
http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC7BC81B-A70D-4700-8CBA-E1D77637A0FA}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - File not found
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - File not found
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - File not found
O20 - Winlogon\Notify\opnlMdBU: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - File not found
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - File not found
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\WRNotifier: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll File not found
O29 - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29 - HKLM SecurityProviders - (schannel.dll) - File not found
O29 - HKLM SecurityProviders - (digest.dll) - File not found
O29 - HKLM SecurityProviders - (msnsspc.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINNT\system32\ssqRJCSM) - File not found
O32 - HKLM CDRom: AutoRun - 0
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/09 03:34:48 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:17:15 | 004,713,472 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/08 21:58:32 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/04 21:37:25 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MpSigStub.exe
[2012/01/04 21:31:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/01/04 21:28:53 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:17 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | C] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 04:54:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/03 04:54:11 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2012/01/03 04:54:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/03 04:52:52 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/03 04:40:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/03 04:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/01/03 04:26:01 | 000,000,000 | —D | C] – C:\Program Files\505B1
[2012/01/03 04:25:18 | 000,000,000 | —D | C] – C:\Program Files\LP
[2012/01/03 04:25:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\F4250
[2008/06/01 17:56:09 | 001,030,144 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/06/01 17:56:09 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2008/06/01 17:56:09 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2008/06/01 17:56:09 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2003/07/01 19:02:45 | 000,014,976 | —- | C] ( ) – C:\WINNT\System32\drivers\winddx.sys
[1979/12/31 23:00:00 | 001,295,472 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlstrm.sys
[1979/12/31 23:00:00 | 000,521,408 | —- | C] ( ) – C:\WINNT\System32\drivers\slntamr.sys
[1979/12/31 23:00:00 | 000,210,592 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlmnt5.sys
[1979/12/31 23:00:00 | 000,169,120 | —- | C] ( ) – C:\WINNT\System32\drivers\ntmtlfax.sys
[1979/12/31 23:00:00 | 000,085,688 | —- | C] ( ) – C:\WINNT\System32\drivers\slnthal.sys
[1979/12/31 23:00:00 | 000,045,056 | —- | C] ( ) – C:\WINNT\System32\slserv.exe
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/09 03:34:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/09 03:33:02 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/09 03:21:01 | 000,000,424 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/09 03:17:54 | 004,713,472 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner\Desktop\aswMBR.exe
[2012/01/09 03:17:17 | 000,000,978 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
[2012/01/08 04:17:00 | 000,000,926 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
[2012/01/07 05:22:05 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/07 05:22:04 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/01/04 22:00:56 | 000,000,207 | -HS- | M] () – C:\boot.ini
[2012/01/04 21:53:14 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2012/01/04 21:33:04 | 000,001,945 | —- | M] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:31:31 | 000,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2012/01/04 21:29:05 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\mseinstall.exe
[2012/01/03 19:55:56 | 000,302,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2012/01/03 19:51:56 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\dds.com
[2012/01/03 19:50:18 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HijackThis.exe
[2012/01/03 19:46:00 | 000,509,440 | —- | M] (Tech Support Guy System) – C:\Documents and Settings\Owner\Desktop\SysInfo.exe
[2012/01/03 13:40:54 | 000,433,414 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2012/01/03 13:40:54 | 000,068,244 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2012/01/03 04:53:24 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.60.0.1800.exe
[2011/12/14 07:05:01 | 000,001,393 | —- | M] () – C:\WINNT\imsins.BAK
[2011/12/13 23:42:09 | 000,221,632 | —- | M] () – C:\WINNT\System32\FNTCACHE.DAT
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[1 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/09 03:33:02 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MBR.dat
[2012/01/04 21:37:52 | 000,000,424 | -H– | C] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/04 21:33:04 | 000,001,945 | —- | C] () – C:\WINNT\epplauncher.mif
[2012/01/04 21:32:20 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/03 19:55:54 | 000,302,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\44f0pxph.exe
[2010/07/31 15:14:26 | 000,212,400 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/30 19:37:32 | 000,256,368 | —- | C] () – C:\Program Files\WinRAR.chm
[2010/04/30 19:37:32 | 000,141,824 | —- | C] () – C:\Program Files\RarExt.dll
[2010/04/30 19:37:32 | 000,052,224 | —- | C] () – C:\Program Files\RarExt64.dll
[2010/04/30 19:37:32 | 000,000,495 | —- | C] () – C:\Program Files\File_Id.diz
[2010/01/09 21:27:08 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/08/31 19:13:08 | 000,073,220 | —- | C] () – C:\WINNT\System32\EPPICPrinterDB.dat
[2008/08/31 19:13:08 | 000,000,097 | —- | C] () – C:\WINNT\System32\PICSDK.ini
[2008/08/31 19:13:07 | 000,031,053 | —- | C] () – C:\WINNT\System32\EPPICPattern131.dat
[2008/08/31 19:13:07 | 000,029,114 | —- | C] () – C:\WINNT\System32\EPPICPattern1.dat
[2008/08/31 19:13:07 | 000,027,417 | —- | C] () – C:\WINNT\System32\EPPICPattern121.dat
[2008/08/31 19:13:07 | 000,021,021 | —- | C] () – C:\WINNT\System32\EPPICPattern3.dat
[2008/08/31 19:13:07 | 000,015,670 | —- | C] () – C:\WINNT\System32\EPPICPattern5.dat
[2008/08/31 19:13:07 | 000,013,280 | —- | C] () – C:\WINNT\System32\EPPICPattern2.dat
[2008/08/31 19:13:07 | 000,010,673 | —- | C] () – C:\WINNT\System32\EPPICPattern4.dat
[2008/08/31 19:13:07 | 000,004,943 | —- | C] () – C:\WINNT\System32\EPPICPattern6.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_PT.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_BP.dat
[2008/08/31 19:13:07 | 000,001,137 | —- | C] () – C:\WINNT\System32\EPPICPresetData_ES.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_FR.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_CF.dat
[2008/08/31 19:13:07 | 000,001,104 | —- | C] () – C:\WINNT\System32\EPPICPresetData_EN.dat
[2008/08/31 19:11:38 | 000,000,044 | —- | C] () – C:\WINNT\EPSNX400.ini
[2008/06/19 23:32:00 | 000,001,160 | —- | C] () – C:\WINNT\mozver.dat
[2008/06/02 17:23:38 | 000,021,312 | —- | C] () – C:\WINNT\choice.exe
[2008/06/01 17:56:28 | 000,018,464 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox.dat
[2008/06/01 17:56:28 | 000,001,056 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox2.dat
[2008/06/01 16:24:37 | 000,594,427 | -HS- | C] () – C:\WINNT\System32\MSCJRqss.ini
[2008/05/29 23:48:08 | 000,001,217 | -HS- | C] () – C:\WINNT\System32\egNWwGgh.ini
[2008/05/16 13:59:02 | 000,000,374 | —- | C] () – C:\WINNT\wininit.ini
[2008/03/11 16:20:45 | 000,000,121 | —- | C] () – C:\WINNT\winzipsp.ini
[2008/02/08 02:00:14 | 000,000,080 | —- | C] () – C:\WINNT\SuperUtil.ini
[2008/02/08 01:51:36 | 000,000,000 | —- | C] () – C:\WINNT\System32\suupdate.dat
[2008/02/08 01:51:35 | 000,000,000 | —- | C] () – C:\WINNT\System32\mssurun.dat
[2007/12/05 03:08:52 | 001,446,464 | —- | C] () – C:\Program Files\Silverlight.exe
[2007/10/20 19:08:23 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
[2007/10/20 18:25:18 | 000,049,152 | —- | C] () – C:\WINNT\System32\ChCfg.exe
[2007/10/20 18:23:14 | 000,147,456 | —- | C] () – C:\WINNT\System32\RtlCPAPI.dll
[2007/10/18 00:00:21 | 000,055,949 | —- | C] () – C:\WINNT\System32\x264-uninstall.exe
[2007/10/11 05:20:56 | 000,000,000 | —- | C] () – C:\WINNT\System32\drivers\atwpkt2.sys
[2007/03/02 16:03:53 | 000,001,763 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/12 22:02:29 | 000,000,116 | —- | C] () – C:\WINNT\NeroDigital.ini
[2007/01/15 01:25:20 | 000,000,079 | —- | C] () – C:\WINNT\xptools.ini
[2007/01/15 01:21:58 | 000,000,120 | —- | C] () – C:\WINNT\System32\bn.dll
[2007/01/08 18:20:12 | 000,014,848 | —- | C] () – C:\WINNT\System32\BASSMOD.dll
[2006/12/18 03:43:12 | 000,000,022 | —- | C] () – C:\Program Files\zipnew.dat
[2006/12/18 03:43:12 | 000,000,020 | —- | C] () – C:\Program Files\rarnew.dat
[2006/12/18 03:42:56 | 001,039,360 | —- | C] () – C:\Program Files\WinRAR.exe
[2006/12/18 03:42:56 | 000,378,880 | —- | C] () – C:\Program Files\Rar.exe
[2006/12/18 03:42:56 | 000,246,272 | —- | C] () – C:\Program Files\UnRAR.exe
[2006/12/18 03:42:56 | 000,120,832 | —- | C] () – C:\Program Files\Uninstall.exe
[2006/12/18 03:42:56 | 000,092,672 | —- | C] () – C:\Program Files\Default.SFX
[2006/12/18 03:42:56 | 000,074,240 | —- | C] () – C:\Program Files\Zip.SFX
[2006/12/18 03:42:56 | 000,069,632 | —- | C] () – C:\Program Files\WinCon.SFX
[2006/12/18 03:42:56 | 000,045,056 | —- | C] () – C:\Program Files\RarExtLoader.exe
[2006/12/18 03:42:55 | 000,003,271 | —- | C] () – C:\Program Files\Order.htm
[2006/12/18 03:42:55 | 000,001,088 | —- | C] () – C:\Program Files\RarFiles.lst
[2006/12/18 03:42:55 | 000,001,063 | —- | C] () – C:\Program Files\Descript.ion
[2006/12/18 03:42:55 | 000,000,639 | —- | C] () – C:\Program Files\Uninstall.lst
[2006/11/07 20:52:05 | 000,000,044 | —- | C] () – C:\WINNT\liveup.ini
[2006/08/12 22:09:45 | 000,004,096 | —- | C] () – C:\WINNT\d3dx.dat
[2006/07/16 17:08:08 | 000,000,627 | —- | C] () – C:\Program Files\playlist.xml
[2006/03/23 19:13:53 | 000,052,490 | —- | C] () – C:\WINNT\DcArt32presets.ini
[2006/03/05 01:46:11 | 000,001,610 | —- | C] () – C:\WINNT\GPlrLanc.dat
[2005/12/13 17:30:33 | 000,122,535 | —- | C] () – C:\WINNT\RSEDNClientUninstaller.exe
[2005/11/22 00:41:22 | 000,000,784 | —- | C] () – C:\Documents and Settings\Owner\Application Data\mpauth.dat
[2005/09/26 18:27:37 | 000,000,028 | —- | C] () – C:\WINNT\Systems.ini
[2005/08/31 18:05:37 | 000,000,075 | —- | C] () – C:\WINNT\System32\sysogg.dll
[2005/07/09 06:00:53 | 000,000,008 | —- | C] () – C:\WINNT\System32\wtl.dat
[2005/07/09 05:25:40 | 000,000,004 | —- | C] () – C:\WINNT\System32\micr0st.dll
[2005/07/09 05:16:13 | 000,129,024 | —- | C] () – C:\WINNT\UNWISE.EXE
[2005/06/29 14:53:05 | 000,005,460 | —- | C] () – C:\WINNT\kwv2.dat
[2005/06/27 17:37:46 | 000,187,512 | —- | C] () – C:\WINNT\System32\u3ldgpnu.dat
[2005/06/27 17:37:46 | 000,026,736 | —- | C] () – C:\WINNT\System32\4qlv6iqe.dat
[2005/06/27 17:37:46 | 000,003,864 | —- | C] () – C:\WINNT\System32\ahkhsbsu.dat
[2005/06/27 17:37:46 | 000,002,715 | —- | C] () – C:\WINNT\System32\mvkl8s1u.dat
[2005/06/27 17:37:46 | 000,000,000 | —- | C] () – C:\WINNT\System32\g8k3i4ve.dat
[2005/06/27 17:37:38 | 000,000,035 | —- | C] () – C:\WINNT\System32\01ii4bjf.ini
[2005/06/27 17:37:37 | 000,003,485 | —- | C] () – C:\WINNT\System32\mdeaf9ej.ini
[2005/05/20 21:35:09 | 000,000,056 | RHS- | C] () – C:\WINNT\System32\566097EC98.sys
[2005/03/21 20:59:40 | 000,000,715 | —- | C] () – C:\WINNT\aolback.exe.lnk
[2005/03/21 20:53:31 | 000,000,335 | —- | C] () – C:\WINNT\nsreg.dat
[2005/02/18 16:53:48 | 000,000,000 | —- | C] () – C:\WINNT\impborl.dll
[2005/02/08 14:42:45 | 000,000,092 | —- | C] () – C:\Program Files\play.rbn.rm&proto;=rtsp
[2005/01/13 22:23:53 | 000,001,131 | —- | C] () – C:\WINNT\System32\vh.dat
[2005/01/04 16:19:13 | 000,001,100 | —- | C] () – C:\WINNT\dhstatus.dat
[2004/12/15 08:22:09 | 000,149,504 | —- | C] () – C:\WINNT\System32\UNWISE.EXE
[2004/10/31 18:32:17 | 000,001,100 | —- | C] () – C:\WINNT\checkip.dat
[2004/10/31 18:29:50 | 000,001,393 | —- | C] () – C:\WINNT\ipconfig.dat
[2004/09/25 22:23:36 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/08/29 21:52:13 | 000,131,072 | —- | C] () – C:\WINNT\System32\SpoonUninstall.exe
[2004/08/25 17:53:06 | 000,000,032 | —- | C] () – C:\WINNT\easecdripper.ini
[2004/08/25 17:28:05 | 000,003,082 | —- | C] () – C:\WINNT\System32\affv6628p4now.sys
[2004/08/17 01:56:38 | 000,122,880 | —- | C] () – C:\WINNT\UnGins.exe
[2004/08/13 03:53:41 | 000,000,014 | —- | C] () – C:\WINNT\msoffice.ini
[2004/07/21 21:54:24 | 000,001,125 | —- | C] () – C:\WINNT\winamp.ini
[2004/05/26 14:42:25 | 000,000,048 | —- | C] () – C:\WINNT\upth.ini
[2004/05/26 14:42:25 | 000,000,028 | —- | C] () – C:\WINNT\atid.ini
[2004/02/11 07:50:12 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/02/07 14:41:59 | 000,082,944 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 12:00:28 | 000,012,635 | —- | C] () – C:\WINNT\System32\DAntivirus.ini
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\{419EC9B7-3209-4445-9EEC-01B25AAF5B29}.dat
[2004/01/14 18:58:45 | 000,000,032 | -HS- | C] () – C:\WINNT\System32\{0D36DCD8-9C7D-430C-A8AA-BD8DF873A105}.dat
[2003/10/25 14:37:35 | 000,067,857 | —- | C] () – C:\WINNT\cdPlayer.ini
[2003/10/22 10:05:08 | 000,000,030 | —- | C] () – C:\WINNT\Morphexe.INI
[2003/10/08 13:34:26 | 000,121,440 | —- | C] () – C:\WINNT\System32\MSDRMCtrl.dll
[2003/08/27 18:06:58 | 000,000,027 | —- | C] () – C:\WINNT\UP9ASP.INI
[2003/08/27 17:33:30 | 000,006,550 | —- | C] () – C:\WINNT\jautoexp.dat
[2003/08/27 16:45:53 | 000,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2003/08/27 14:24:03 | 000,000,242 | —- | C] () – C:\WINNT\qwimp.ini
[2003/08/26 16:10:20 | 000,000,120 | —- | C] () – C:\WINNT\SIERRA.INI
[2003/08/23 13:49:22 | 000,000,396 | —- | C] () – C:\WINNT\intuprof.ini
[2003/08/23 13:48:46 | 000,000,880 | —- | C] () – C:\WINNT\QUICKEN.INI
[2003/08/22 20:05:57 | 000,002,241 | —- | C] () – C:\WINNT\hpdj5600.ini
[2003/08/22 20:05:25 | 000,000,414 | —- | C] () – C:\WINNT\hpbvspst.ini
[2003/07/16 14:22:18 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINNT\patchw32.dll
[2003/07/14 13:30:27 | 000,034,816 | —- | C] () – C:\WINNT\patch.exe
[2003/07/01 19:23:27 | 000,000,000 | —- | C] () – C:\WINNT\System32\a3d.dll
[2003/07/01 19:10:07 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/07/01 19:07:33 | 000,282,624 | —- | C] () – C:\WINNT\System32\PCDrSystemInformation.dll
[2003/07/01 19:05:00 | 000,094,208 | —- | C] () – C:\WINNT\System32\PCDrKernelModeServices.dll
[2003/07/01 19:05:00 | 000,077,824 | —- | C] () – C:\WINNT\System32\ProgressTrace.dll
[2003/07/01 19:03:46 | 000,000,561 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2003/07/01 19:02:45 | 000,466,944 | —- | C] () – C:\WINNT\System32\SLLights.dll
[2003/07/01 19:02:45 | 000,376,832 | —- | C] () – C:\WINNT\System32\slmh.exe
[2003/07/01 19:02:45 | 000,167,936 | —- | C] () – C:\WINNT\System32\minirec.exe
[2003/07/01 19:02:45 | 000,151,552 | —- | C] () – C:\WINNT\System32\amr_cpl.dll
[2003/07/01 19:02:45 | 000,061,440 | —- | C] () – C:\WINNT\SmCfg.exe
[2003/05/16 11:56:01 | 000,000,770 | —- | C] () – C:\WINNT\orun32.ini
[2003/05/16 10:34:34 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/05/16 10:26:45 | 000,021,640 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2003/05/16 10:20:03 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/05/16 10:18:53 | 000,221,632 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2003/03/27 15:28:44 | 000,004,955 | —- | C] () – C:\WINNT\System32\DProg.ini
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINNT\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINNT\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINNT\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINNT\System32\ogg.dll
[2002/09/06 10:36:16 | 000,233,472 | —- | C] () – C:\WINNT\System32\lame_enc.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINNT\System32\libpostproc.dll
[2001/08/29 18:57:40 | 000,155,648 | —- | C] () – C:\WINNT\System32\addurl41.DLL
[2001/07/10 13:43:16 | 000,018,432 | —- | C] () – C:\WINNT\System32\winwatch.DLL
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINNT\System32\MPEG2DEC.dll
[2000/09/08 16:53:50 | 000,073,839 | —- | C] () – C:\WINNT\System32\KodakOneTouch.dll
[1979/12/31 23:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[1979/12/31 23:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[1979/12/31 23:00:00 | 000,433,414 | —- | C] () – C:\WINNT\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[1979/12/31 23:00:00 | 000,188,416 | —- | C] () – C:\WINNT\System32\slextspk.dll
[1979/12/31 23:00:00 | 000,159,744 | —- | C] () – C:\WINNT\System32\SLGen.dll
[1979/12/31 23:00:00 | 000,068,244 | —- | C] () – C:\WINNT\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\coinst.dll
[1979/12/31 23:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[1979/12/31 23:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | —- | C] () – C:\WINNT\slrundll.exe
[1979/12/31 23:00:00 | 000,005,114 | —- | C] () – C:\WINNT\System32\oembios.dat
[1979/12/31 23:00:00 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat
========== LOP Check ==========
[2008/12/11 17:53:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/06/11 18:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/07/21 19:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/31 21:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/01/06 14:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/08/09 17:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/10 22:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2011/10/09 18:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/07 18:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/07/07 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/06 19:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/01/03 05:06:09 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/10/18 21:27:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/07 18:04:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2003/07/01 19:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2009/12/07 19:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2006/03/04 04:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2007/01/04 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/06/21 16:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DC++
[2008/09/05 16:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eBookPro6
[2012/01/03 05:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F4250
[2010/07/07 21:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/08/05 22:50:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/08/31 21:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2008/08/31 19:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/02/16 23:56:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2011/09/05 15:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/05/09 07:48:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCToolsFirewallPlus
[2008/08/15 02:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2009/11/28 20:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2009/10/19 00:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SharePod
[2009/01/04 23:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/05/02 11:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/05/09 07:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2009/11/29 21:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/15 01:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Systweak
[2009/09/26 16:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TikisLab
[2005/12/15 03:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2008/02/12 04:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Uniblue
[2007/01/20 03:49:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/06/29 14:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2007/10/07 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2006/08/12 22:14:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wildfire
[2012/01/09 03:21:01 | 000,000,424 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Program Files\play.rbn.rm&proto;=rtsp:SummaryInformation
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >
OTL Extras logfile created on: 1/9/2012 3:36:19 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.73 Mb Total Physical Memory | 375.67 Mb Available Physical Memory | 37.02% Memory free
1.88 Gb Paging File | 1.39 Gb Available in Paging File | 73.97% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 23.32 Gb Free Space | 62.57% Space Free | Partition Type: NTFS
Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg [@ = regfile] – regedit.exe "%1"
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1
piffile [open] – "%1" %*
regfile [open] – regedit.exe "%1"
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2234:TCP" = 2234:TCP:*:Enabled:Soulseek
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"9420:TCP" = 9420:TCP:*:Enabled:RSP
"1035:TCP" = 1035:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Program Files\DC++\DCPlusPlus.exe" = F:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\twc\medicsp2\bin\sprtcmd.exe" = C:\Program Files\twc\medicsp2\bin\sprtcmd.exe:*:Enabled:sprtcmd
"C:\Program Files\twc\medicsp2\bin\sprtsvc.exe" = C:\Program Files\twc\medicsp2\bin\sprtsvc.exe:*:Enabled:sprtsvc
"C:\Program Files\twc\medicsp2\agent\bin\bcont.exe" = C:\Program Files\twc\medicsp2\agent\bin\bcont.exe:*:Enabled:bcont
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
"C:\Program Files\Common Files\AOL\1141465714\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1141465714\ee\aolsoftware.exe:*:Enabled:AOL Services
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information
"C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys" = C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys:*:Enabled:PnkBstrK.sys – ()
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares – (Ares Development Group)
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE" = C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE:*:Enabled:EPSON Driver Update – (SEIKO EPSON CORPORATION)
"C:\WINNT\system32\mmc.exe" = C:\WINNT\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7169B8E4-2632-46B1-AA5F-167CB5FE5029}" = Symantec Network Drivers Update
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}" = Microsoft Works Suite Add-in for Microsoft Word
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.7
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management client
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Ares" = Ares 2.1.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DC++" = DC++ 0.761
"EPSON Scanner" = EPSON Scan
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"hp print screen utility" = hp print screen utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InterActual Player" = InterActual Player
"IrfanView" = IrfanView (remove only)
"LTCM Client" = LTCM Client
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoParade.exe" = PhotoParade Player
"Portraits" = Portraits Screen Saver
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 12.0" = RealPlayer
"RSNet EDN" = Red Swoosh EDN Client (lol remove only)
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON NX400 User's Guide
"SLAMRMO" = Smart Link 56K Modem
"SopCast" = SopCast 3.2.4
"Soulseek2" = SoulSeek 157 NS 13c
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"X264 H.264/AVC Video Codec" = X264 H.264/AVC Video Codec (remove only)
"Yahoo! Software Update" = Yahoo! Software Update
"yBook_is1" = yBook
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/9/2011 10:26:20 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 2/9/2011 1:33:19 PM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 2/10/2011 7:15:35 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 2/10/2011 7:15:40 AM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 2/21/2011 1:44:31 AM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 2/21/2011 1:44:33 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
[ System Events ]
Error - 1/4/2012 11:55:20 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7022
Description = The MSCamSvc service hung on starting.
Error - 1/4/2012 11:55:21 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SuperMounter TfFsMon TFSysMon
Error - 1/4/2012 11:59:55 PM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7034
Description = The MSCamSvc service terminated unexpectedly. It has done this 1
time(s).
Error - 1/5/2012 7:12:23 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0007E9438D70 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).
Error - 1/5/2012 7:12:54 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.2 on
the Network Card with network address 0007E9438D70.
Error - 1/7/2012 6:50:57 AM | Computer Name = YOUR-3B54ED6EDD | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0007E9438D70 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).
Error - 1/8/2012 11:58:30 PM | Computer Name = YOUR-3B54ED6EDD | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.117.2462.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7903.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.
Error - 1/9/2012 5:15:07 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 1/9/2012 5:15:20 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7034
Description = The MBAMService service terminated unexpectedly. It has done this
1 time(s).
Error - 1/9/2012 5:15:34 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 2 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
[ TuneUp Events ]
Error - 2/12/2010 8:59:58 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 2/16/2010 12:42:08 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 2/16/2010 12:45:32 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 2/17/2010 2:03:32 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 2/17/2010 10:23:36 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 2/28/2010 9:07:54 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 3/2/2010 4:58:56 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 4/18/2010 2:45:02 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:45:02', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3340',0)
Error - 4/18/2010 2:47:06 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:47:06', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3080',0)
Error - 4/18/2010 2:50:22 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:50:22', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2620',0)
< End of report >