Malwarebytes' Anti-Malware 1.33
Database version: 1712
Windows 5.1.2600 Service Pack 3
1/31/2009 12:43:07 PM
mbam-log-2009-01-31 (12-43-07).txt
Scan type: Full Scan (C:\|)
Objects scanned: 270352
Time elapsed: 2 hour(s), 8 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\Ranch Rush\ijl15.dll (Trojan.Agent) -> Quarantined and deleted successfully.
_________________________________________________
OTViewIt logfile created on: 1/31/2009 12:44:32 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 62.17% Memory free
3.35 Gb Paging File | 2.65 Gb Available in Paging File | 79.15% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 82.02 Gb Free Space | 44.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOUGAS3
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
[2008/10/05 13:54:08 | 00,611,664 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2005/12/12 15:02:24 | 00,176,193 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
[2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2004/07/20 15:15:20 | 00,090,112 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe
[2009/01/30 00:01:58 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
[1999/12/13 01:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE
[2006/09/10 04:25:38 | 00,539,136 | —- | M] (Distributed Computing Technologies, Inc.) – C:\WINDOWS\dnetc.exe
[2008/12/10 12:12:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
[2008/12/16 21:59:50 | 00,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
[2006/10/26 13:40:34 | 00,335,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
[2007/12/05 02:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
[2005/08/08 14:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
[2009/01/30 00:02:02 | 00,484,120 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
[2003/10/06 01:57:32 | 00,024,576 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTHELPER.EXE
[2003/09/17 10:43:36 | 00,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
[2003/06/18 01:00:00 | 00,045,056 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe
[2003/05/07 00:56:22 | 00,188,416 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[2003/05/22 07:55:38 | 00,483,328 | R— | M] (Hewlett-Packard) – C:\WINDOWS\system32\hphmon05.exe
[2001/08/16 23:41:58 | 00,028,738 | —- | M] (Microsoft® Corporation) – C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[2005/06/07 00:46:24 | 00,057,344 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/12/07 23:57:00 | 00,030,208 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[2006/12/10 21:52:38 | 00,049,152 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
[2008/04/13 19:12:33 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\rundll32.exe
[2009/01/30 00:01:55 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
[2008/05/22 21:14:39 | 00,185,896 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/06/06 00:00:00 | 00,087,336 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
[2007/02/05 15:34:38 | 00,300,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchindexer.exe
[2008/11/20 14:20:54 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
[2008/12/20 07:50:34 | 02,656,528 | —- | M] () – C:\Program Files\Logitech\QuickCam\Quickcam.exe
[2008/12/10 12:12:50 | 00,136,600 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
[2003/10/08 16:35:42 | 00,139,264 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
[2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2008/12/20 07:46:58 | 00,558,864 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
[2006/10/18 21:05:26 | 00,204,288 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
[2008/04/01 04:39:48 | 00,486,856 | —- | M] (DT Soft Ltd) – C:\Program Files\DAEMON Tools Lite\daemon.exe
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
[2004/07/15 12:56:56 | 00,581,632 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KEM.exe
[2001/08/07 18:06:54 | 00,024,633 | —- | M] (Microsoft® Corporation) – C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[2004/02/05 14:28:16 | 00,118,784 | —- | M] (Nikon Corporation) – C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[2007/02/05 15:40:46 | 00,118,784 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[2008/02/05 15:29:20 | 00,054,512 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
[2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2009/01/16 11:30:40 | 04,519,832 | —- | M] (MétéoMédia/The Weather Network) – C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[2005/12/12 15:03:54 | 00,417,855 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
[2004/06/08 13:31:38 | 00,029,696 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
[2006/12/10 21:51:08 | 00,271,960 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
[2004/05/29 00:08:52 | 00,520,192 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
[2007/02/05 15:32:28 | 00,182,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchprotocolhost.exe
[2007/02/05 15:31:10 | 00,076,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchfilterhost.exe
[2009/01/31 10:24:20 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/10/05 13:54:08 | 00,611,664 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe – (aawservice [Auto | Running])
[2005/12/12 15:02:24 | 00,176,193 | —- | M] (American Power Conversion Corporation) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service [Auto | Running])
[2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
[2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
[2004/07/20 15:15:20 | 00,090,112 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe – (ATKKeyboardService [Auto | Running])
File not found – – (Automatic LiveUpdate Scheduler [Auto | Stopped])
[2009/01/30 00:01:58 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
[2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[1999/12/13 01:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE – (Creative Service for CDROM Access [Auto | Running])
[2006/09/10 04:25:38 | 00,539,136 | —- | M] (Distributed Computing Technologies, Inc.) – C:\WINDOWS\dnetc.exe – (dnetc [Auto | Running])
[2007/01/03 20:40:21 | 00,136,120 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
[2005/04/04 01:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
[2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
[2008/12/10 12:12:50 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
[2008/12/16 21:59:50 | 00,150,040 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv [Auto | Running])
[2006/10/26 13:40:34 | 00,335,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe – (MDM [Auto | Running])
[2007/08/24 06:59:20 | 00,068,464 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2007/12/05 02:41:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
[2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
[2005/08/08 14:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo [Auto | Running])
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe – (Simply Accounting Database Connection Manager [Auto | Running])
[2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Stopped])
[2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend [Auto | Running])
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [Auto | Running])
[2007/02/05 15:34:38 | 00,300,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\searchindexer.exe – (WSearch [Auto | Running])
========== Driver Services ==========
[2004/10/07 20:16:04 | 00,035,840 | —- | M] (Oak Technology Inc.) – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K [System | Running])
[2008/04/13 13:31:33 | 00,037,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\amdk7.sys – (AmdK7 [System | Stopped])
[2004/07/20 15:19:16 | 00,020,096 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\system32\drivers\atkkbnt.sys – (asuskbnt [System | Running])
[2004/08/03 17:29:28 | 00,327,040 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\drivers\ati2mtaa.sys – (ati2mtaa [On_Demand | Stopped])
[2009/01/30 00:02:02 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86 [System | Running])
[2009/01/30 00:02:02 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
[2006/10/18 04:00:00 | 00,002,432 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
[2006/10/18 04:00:00 | 00,002,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
[2003/11/05 01:26:02 | 00,645,392 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k [On_Demand | Running])
[2003/11/18 21:13:54 | 00,366,160 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k [On_Demand | Running])
[2003/10/13 22:17:56 | 00,332,800 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k [On_Demand | Stopped])
[2003/10/07 21:08:12 | 00,006,096 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k [On_Demand | Running])
[2003/10/07 21:09:10 | 00,130,288 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k [On_Demand | Running])
[2005/11/25 17:43:48 | 00,031,896 | —- | M] (DemoForge, LLC) – C:\WINDOWS\system32\drivers\dfmirage.sys – (dfmirage [On_Demand | Running])
[2006/10/26 03:00:00 | 00,387,432 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl [System | Running])
[2004/10/11 00:51:00 | 00,008,037 | R— | M] (ASUSTeK Computer Inc.) – C:\WINDOWS\system32\drivers\EIO.sys – (EIO [Auto | Running])
[2003/10/13 04:42:12 | 00,145,488 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia [On_Demand | Running])
[2008/04/13 13:36:40 | 00,046,464 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\gagp30kx.sys – (gagp30kx [Boot | Running])
[2008/04/13 13:45:29 | 00,010,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum [On_Demand | Running])
[2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
[2003/10/21 04:26:08 | 00,904,496 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ha10kx2k.sys – (ha10kx2k [On_Demand | Running])
[2003/10/21 04:23:44 | 00,148,432 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\haP16v2k.sys – (hap16v2k [On_Demand | Running])
[2008/04/13 13:36:38 | 00,020,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\hidbatt.sys – (HidBatt [On_Demand | Stopped])
[2006/03/19 19:48:36 | 00,049,920 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412 [On_Demand | Running])
[2006/03/19 19:48:36 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
[2006/03/19 19:48:37 | 00,021,568 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12 [On_Demand | Running])
[2004/06/17 06:41:44 | 00,024,971 | —- | M] (Integrated Technology Express, Inc.) – C:\WINDOWS\system32\drivers\iteraid.sys – (iteraid [Boot | Stopped])
[2004/06/08 13:36:28 | 00,013,105 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\L8042Kbd.sys – (L8042Kbd [On_Demand | Running])
[2004/06/08 13:35:18 | 00,054,817 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
[2004/06/08 13:35:08 | 00,071,533 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
[2008/12/16 21:58:54 | 00,025,624 | —- | M] () – C:\WINDOWS\system32\drivers\LVPr2Mon.sys – (LVPr2Mon [On_Demand | Running])
[2008/12/17 01:00:12 | 00,768,024 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS [On_Demand | Running])
[2008/12/17 01:01:20 | 00,041,752 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta [On_Demand | Running])
[2005/02/04 18:00:12 | 00,085,888 | —- | M] (ULi Electronics Inc.) – C:\WINDOWS\system32\drivers\m5287.sys – (m5287 [Boot | Stopped])
[2001/08/17 16:00:04 | 00,002,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401 [On_Demand | Stopped])
[2004/08/12 21:56:20 | 00,005,810 | —- | M] () – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor [On_Demand | Running])
[2007/12/05 02:41:00 | 07,435,392 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv [On_Demand | Running])
[2003/10/07 21:06:50 | 00,178,672 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv [On_Demand | Running])
[2008/12/17 00:53:22 | 00,013,848 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\lv302af.sys – (pepifilter [On_Demand | Running])
[2003/09/19 15:47:24 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
[2003/03/05 12:19:28 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\PfModNT.sys – (PfDetNT [Auto | Running])
[2003/03/05 12:19:28 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\PfModNT.sys – (PfModNT [Auto | Stopped])
[2008/12/17 00:53:44 | 02,686,104 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\drivers\LV302V32.SYS – (PID_PEPI [On_Demand | Running])
[2004/08/04 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink [On_Demand | Running])
[2006/10/18 04:00:00 | 00,036,624 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2005/05/27 10:32:52 | 01,317,152 | —- | M] () – C:\WINDOWS\system32\drivers\lvcm.sys – (QCMerced [On_Demand | Stopped])
[2005/03/04 10:10:26 | 00,074,496 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp [On_Demand | Stopped])
[2001/08/17 13:50:34 | 00,166,720 | —- | M] (S3 Incorporated) – C:\WINDOWS\system32\drivers\s3m.sys – (s3m [On_Demand | Stopped])
[2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv [On_Demand | Stopped])
[2003/05/30 03:05:30 | 00,089,610 | R— | M] (Silicon Image, Inc) – C:\WINDOWS\system32\drivers\Si3112r.sys – (Si3112r [Boot | Stopped])
[2005/01/19 01:30:52 | 00,067,200 | —- | M] (Silicon Image, Inc.) – C:\WINDOWS\system32\drivers\Si3132.sys – (SI3132 [Boot | Stopped])
[2003/12/09 01:43:36 | 00,045,568 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid.sys – (SiSRaid [Boot | Stopped])
[2003/12/09 01:50:18 | 00,045,568 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid1.sys – (SiSRaid1 [Boot | Stopped])
[2004/05/24 19:36:12 | 00,028,544 | —- | M] (Silicon Integrated Systems) – C:\WINDOWS\system32\drivers\sisraid2.sys – (SiSRaid2 [Boot | Stopped])
[2008/04/13 22:45:32 | 00,717,296 | —- | M] () – C:\WINDOWS\system32\drivers\sptd.sys – (sptd [Boot | Running])
[2008/04/13 13:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio [On_Demand | Running])
[2004/07/06 09:45:42 | 00,060,672 | R— | M] (VIA Technologies inc,.ltd) – C:\WINDOWS\system32\drivers\viamraid.sys – (viamraid [Boot | Running])
[2003/10/01 02:59:14 | 00,077,056 | —- | M] (VIA Technologies inc,.ltd) – C:\WINDOWS\system32\drivers\viasraid.sys – (viasraid [Boot | Stopped])
[2004/08/04 07:00:00 | 00,012,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\ws2ifsl.sys – (WS2IFSL [System | Running])
[2005/05/06 07:27:00 | 00,232,064 | —- | M] (Marvell) – C:\WINDOWS\system32\drivers\yk51x86.sys – (yukonwxp [On_Demand | Running])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.daemon-search.com/startpage
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = localhost
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.daemon-search.com/startpage
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = localhost
========== (O1) Hosts File ==========
HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
========== (O3) Toolbars ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"ConnectionManager"=C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe (Sage Software)
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" (Creative Technology Ltd)
"CTHelper"=CTHELPER.EXE (Creative Technology Ltd)
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r (Creative Technology Ltd)
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
"HPHmon05"=C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" (Hewlett-Packard)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers (Microsoft® Corporation)
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" (Microsoft® Corporation)
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"nwiz"=nwiz.exe /install ()
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" (Roxio)
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r (Creative Technology Ltd)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UpdReg"=C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" (Microsoft® Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"RemoteCenter"="C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" (Creative Technology Ltd)
"WeatherEye"=C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye (MétéoMédia/The Weather Network)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"RemoteCenter"="C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" (Creative Technology Ltd)
"WeatherEye"=C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye (MétéoMédia/The Weather Network)
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
========== (O4) Startup Folders ==========
[2005/12/12 15:05:30 | 00,221,247 | —- | M] (American Power Conversion Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
[2004/05/29 00:06:36 | 00,053,248 | —- | M] (Hewlett-Packard Co.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[2004/07/15 12:56:56 | 00,581,632 | —- | M] (Logitech Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
[2001/08/07 18:06:54 | 00,024,633 | —- | M] (Microsoft® Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[2004/02/05 14:28:16 | 00,118,784 | —- | M] (Nikon Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[2007/02/05 15:40:46 | 00,118,784 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[2008/02/05 15:29:20 | 00,054,512 | —- | M] (Yahoo! Inc.) – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
[2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\user\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"CDRAutoRun"=0
"NoDriveAutoRun"=67108863
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"CDRAutoRun"=0
"NoDriveAutoRun"=67108863
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2008/10/18 19:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE File not found
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE File not found
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2008/10/18 19:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console – %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote – %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote – %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research – %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 – %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [Sun Java Console] -> [2008/12/10 12:12:50 | 00,132,504 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
aol.com\free: http in Local intranet
35 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
33 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
aol.com\free: http in Local intranet
35 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{0B79F48A-E8D6-11DB-9283-E25056D89593}: http://support.f-secure.com/ols/fscax.cab – F-Secure Online Scanner 3.1
{0E5F0222-96B9-11D3-8997-00104BD12D94}: http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB – PCPitstop Utility
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}:
http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab – CKAVWebScan Object
{17492023-C23A-453E-A040-C7C580BBF700}: http://go.microsoft.com/fwlink/?linkid=39204 – Windows Genuine Advantage Validation Tool
{33564D57-0000-0010-8000-00AA00389B71}: http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB – Reg Error: Key does not exist or could not be opened.
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}: http://office.microsoft.com/officeupdate/content/opuc3.cab – Office Update Installation Engine
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab – OnlineScanner Control
{6414512B-B978-451D-A0D8-FCFDF33E833C}:
http://update.microsoft.com/windowsupdate/…b?1120829558027 – WUWebControl Class
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}:
http://update.microsoft.com/microsoftupdat…b?1136849927000 – MUWebControl Class
{7B297BFD-85E4-4092-B2AF-16A91B2EA103}: http://www3.ca.com/securityadvisor/virusinfo/webscan.cab – WScanCtl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab – Java Plug-in 1.5.0_11
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_01
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_02
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_03
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_06
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_07
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwa…ash/swflash.cab – Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{B66F470E-2EE2-499F-8CA2-0CEE25E0EB09} (Servers: | Description: )
{C4158F05-7D38-4C3C-9688-880B6D336870} (Servers: | Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller)
{CAD443DA-676E-4FAE-B114-A63FCB8974BF} (Servers: | Description: 1394 Net Adapter)
{ED77007E-0B02-466E-8D67-EBF7110D07E4} (Servers: | Description: )
{F03B4758-FF56-4F74-B713-CD05D160D368} (Servers: | Description: )
========== (O19) User Style Sheets ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles]
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
avgrsstarter: "DllName" = avgrsstx.dll – C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
WRNotifier: "DllName" = WRLogonNTF.dll – File not found
========== (O21) SSODL Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CDBurn"={fbeb8a05-beee-4442-804e-409d6c4515e9} (HKLM) – CLSID or file not found.
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" (HKLM) – C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" (HKLM) – C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) – C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
autoAlbum.log [-i="C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0.txt" -o="C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0_out.txt" -g -b -s=4 -f="text"input text file: C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0.txt | output file: C:\Documents and Settings\user\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_20\tmpAlb_20_0_out.txt | | Value of width is 1165 and ht is 1701creating book layout … | layout is complete, writing output file of type 1… | ]
[2008/01/16 21:23:35 | 00,000,623 | —- | M] () – C:\autoAlbum.log – [ NTFS ]
AUTOEXEC.BAT []
[2005/07/08 08:20:19 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT – [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[11 C:\WINDOWS\*.tmp files]
[2009/01/31 10:23:59 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe
[2009/01/31 09:49:05 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/31 01:00:09 | 00,000,000 | R–D | C] – C:\Documents and Settings\user\Desktop\Games
[2009/01/30 20:32:31 | 00,000,000 | —D | C] – C:\Program Files\EsetOnlineScanner
[2009/01/30 20:22:22 | 00,000,319 | —- | C] () – C:\Documents and Settings\user\My Documents\My Documents.lnk
[2009/01/30 20:04:34 | 00,000,000 | —D | C] – C:\Rooter$
[2009/01/30 01:03:21 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/01/30 00:41:52 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/01/30 00:41:49 | 00,260,272 | —- | C] () – C:\cmldr
[2009/01/30 00:41:47 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/01/30 00:40:10 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/01/30 00:40:10 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/01/30 00:40:10 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/01/30 00:40:10 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/01/30 00:40:10 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINDOWS\fdsv.exe
[2009/01/30 00:40:10 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/01/30 00:40:10 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/01/30 00:40:10 | 00,049,152 | —- | C] () – C:\WINDOWS\VFIND.exe
[2009/01/30 00:40:10 | 00,029,696 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/01/30 00:40:05 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/01/30 00:40:05 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/30 00:38:15 | 03,048,418 | R— | C] () – C:\Documents and Settings\user\Desktop\ComboFix.exe
[2009/01/30 00:05:47 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\WinRAR
[2009/01/30 00:02:02 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/29 23:54:32 | 21,458,98496 | -HS- | C] () – C:\hiberfil.sys
[2009/01/29 23:22:06 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/29 23:15:48 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/29 23:02:40 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/29 17:29:39 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\user\Desktop\HiJackThis.exe
[2009/01/29 10:38:51 | 00,030,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Volunteer and Event Coordinator.doc
[2009/01/29 10:09:11 | 00,014,227 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Volunteer and Event Coordinator.docx
[2009/01/28 16:52:46 | 00,225,122 | —- | C] () – C:\Documents and Settings\All Users\Documents\Awards1.jpg
[2009/01/28 12:44:08 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\EA
[2009/01/27 11:49:27 | 00,031,232 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Office Receptionist.doc
[2009/01/25 21:25:37 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\December 2008
[2009/01/25 21:23:13 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Desktop\January 2009
[2009/01/23 09:00:38 | 00,000,000 | —D | C] – C:\Program Files\Games
[2009/01/22 22:45:54 | 00,000,000 | —D | C] – C:\WINDOWS\Parking Dash
[2009/01/22 22:45:54 | 00,000,000 | —D | C] – C:\Program Files\Parking Dash
[2009/01/22 11:01:27 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\blg
[2009/01/22 11:01:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\blg
[2009/01/22 10:33:28 | 00,000,000 | —D | C] – C:\Program Files\LeeGTs Games
[2009/01/21 20:04:06 | 00,000,000 | —D | C] – C:\WINDOWS\Operation Mania
[2009/01/21 20:04:06 | 00,000,000 | —D | C] – C:\Program Files\Operation Mania
[2009/01/21 14:06:16 | 00,014,387 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Human Resources Generalist.docx
[2009/01/21 13:58:33 | 00,014,471 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Human Resources Generalist.docx
[2009/01/21 13:42:59 | 00,014,493 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Project Administrator.docx
[2009/01/15 16:46:32 | 00,030,720 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant 2.doc
[2009/01/15 16:45:56 | 00,030,720 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.doc
[2009/01/15 16:45:31 | 00,030,208 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant 2.doc
[2009/01/15 14:33:55 | 00,014,280 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant.docx
[2009/01/15 14:16:59 | 00,014,419 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.docx
[2009/01/15 13:01:23 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\Home Sweet Home 2
[2009/01/15 10:07:46 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Application Data\PetShowCraze
[2009/01/15 10:07:29 | 00,000,000 | —D | C] – C:\WINDOWS\Home Sweet Home 2 Kitchens and Baths
[2009/01/15 10:07:29 | 00,000,000 | —D | C] – C:\Program Files\Home Sweet Home 2 Kitchens and Baths
[2009/01/15 10:07:02 | 00,000,000 | —D | C] – C:\WINDOWS\Restaurant Rush
[2009/01/15 10:07:02 | 00,000,000 | —D | C] – C:\Program Files\Restaurant Rush
[2009/01/15 10:05:36 | 00,000,000 | —D | C] – C:\WINDOWS\Pet Show Craze
[2009/01/14 23:20:25 | 00,000,000 | —D | C] – C:\WINDOWS\Beach Party Craze
[2009/01/14 23:20:25 | 00,000,000 | —D | C] – C:\Program Files\Beach Party Craze
[2009/01/14 17:18:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FreshGames
[2009/01/14 17:17:22 | 00,000,000 | —D | C] – C:\WINDOWS\Ranch Rush
[2009/01/14 17:17:22 | 00,000,000 | —D | C] – C:\Program Files\Ranch Rush
[2009/01/14 15:42:42 | 00,000,000 | —D | C] – C:\Program Files\Mystic Inn
[2009/01/14 13:02:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2009/01/14 13:01:37 | 00,000,000 | —D | C] – C:\WINDOWS\Farm Frenzy 2
[2009/01/14 13:01:36 | 00,000,000 | —D | C] – C:\Program Files\Farm Frenzy 2
[2009/01/13 09:07:18 | 00,013,704 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter Regional Intake Officers Métis Nation.docx
[2009/01/13 08:45:17 | 00,014,343 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Regional Intake Officers.docx
[2009/01/11 10:14:59 | 00,000,000 | —D | C] – C:\WINDOWS\Wedding Dash 2 - Rings Around the World
[2009/01/11 10:14:59 | 00,000,000 | —D | C] – C:\Program Files\Wedding Dash 2 - Rings Around the World
[2009/01/09 23:44:31 | 00,000,000 | —D | C] – C:\Program Files\Wedding Dash
[2009/01/09 13:44:31 | 00,219,158 | —- | C] () – C:\Documents and Settings\user\Desktop\petey.jpg
[2009/01/09 12:02:01 | 00,014,375 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Pharmacy Technician.docx
[2009/01/09 11:58:33 | 00,014,402 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume Office Coordinator.docx
[2009/01/09 10:39:29 | 00,014,436 | —- | C] () – C:\Documents and Settings\user\My Documents\Resume PT Studies Coordinator.docx
[2009/01/09 10:38:44 | 00,013,986 | —- | C] () – C:\Documents and Settings\user\My Documents\Cover Letter PT Studies Coordinator.docx
[2009/01/05 13:26:51 | 00,014,395 | —- | C] () – C:\Documents and Settings\user\My Documents\Combo Style Resume Karri.docx
========== Files - Modified Within 30 Days ==========
[5 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\user\My Documents\*.tmp files]
[2009/01/31 12:38:05 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-out.ogf
[2009/01/31 12:38:03 | 00,070,432 | —- | M] () – C:\WINDOWS\buff-in.r72
[2009/01/31 12:38:03 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-out.r72
[2009/01/31 12:38:03 | 00,000,032 | —- | M] () – C:\WINDOWS\buff-in.ogf
[2009/01/31 12:37:32 | 00,000,208 | —- | M] () – C:\WINDOWS\jantje
[2009/01/31 10:24:20 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTViewIt.exe
[2009/01/31 09:55:03 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/01/31 09:53:21 | 00,020,712 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/31 09:53:11 | 04,932,286 | —- | M] () – C:\WINDOWS\{00000000-00000000-0000000B-00001102-00000004-20021102}.CDF
[2009/01/31 09:51:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/31 09:51:45 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/31 09:51:43 | 21,458,98496 | -HS- | M] () – C:\hiberfil.sys
[2009/01/31 09:50:45 | 00,003,048 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/01/31 09:50:45 | 00,003,048 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/01/31 09:50:45 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-20021102}.dat
[2009/01/31 09:50:45 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000B-00001102-00000004-20021102}.dat
[2009/01/31 09:50:44 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/31 09:50:44 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000B-00001102-00000004-20021102}.rfx
[2009/01/30 20:22:22 | 00,000,319 | —- | M] () – C:\Documents and Settings\user\My Documents\My Documents.lnk
[2009/01/30 17:03:21 | 32,607,818 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/01/30 09:40:48 | 00,082,350 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/01/30 00:43:50 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/01/30 00:41:52 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/01/30 00:38:51 | 03,048,418 | R— | M] () – C:\Documents and Settings\user\Desktop\ComboFix.exe
[2009/01/30 00:02:02 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/30 00:02:02 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/30 00:02:02 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/29 23:23:36 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/01/29 23:22:06 | 00,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/29 23:08:44 | 05,332,966 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/01/29 17:29:48 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\user\Desktop\HiJackThis.exe
[2009/01/29 12:33:58 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/29 12:20:33 | 00,000,125 | —- | M] () – C:\ioSpecial.ini
[2009/01/29 10:38:51 | 00,030,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Volunteer and Event Coordinator.doc
[2009/01/29 10:09:11 | 00,014,227 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Volunteer and Event Coordinator.docx
[2009/01/28 16:52:46 | 00,225,122 | —- | M] () – C:\Documents and Settings\All Users\Documents\Awards1.jpg
[2009/01/27 11:49:28 | 00,031,232 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Office Receptionist.doc
[2009/01/27 09:02:04 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/01/21 14:06:16 | 00,014,387 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Human Resources Generalist.docx
[2009/01/21 13:58:33 | 00,014,471 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Human Resources Generalist.docx
[2009/01/21 13:42:59 | 00,014,493 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Project Administrator.docx
[2009/01/15 16:46:33 | 00,030,720 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant 2.doc
[2009/01/15 16:45:57 | 00,030,720 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.doc
[2009/01/15 16:45:32 | 00,030,208 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant 2.doc
[2009/01/15 14:48:47 | 00,197,120 | -HS- | M] () – C:\Documents and Settings\user\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\user\My Documents\Thumbs.db:encryptable
[2009/01/15 14:33:55 | 00,014,280 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Executive Assistant.docx
[2009/01/15 14:16:59 | 00,014,419 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Executive Assistant.docx
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/13 09:07:18 | 00,013,704 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter Regional Intake Officers Métis Nation.docx
[2009/01/13 08:45:17 | 00,014,343 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Regional Intake Officers.docx
[2009/01/09 20:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/09 20:18:51 | 00,039,424 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/09 13:40:19 | 00,219,158 | —- | M] () – C:\Documents and Settings\user\Desktop\petey.jpg
[2009/01/09 12:02:02 | 00,014,375 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Pharmacy Technician.docx
[2009/01/09 11:58:33 | 00,014,402 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume Office Coordinator.docx
[2009/01/09 10:39:29 | 00,014,436 | —- | M] () – C:\Documents and Settings\user\My Documents\Resume PT Studies Coordinator.docx
[2009/01/09 10:38:45 | 00,013,986 | —- | M] () – C:\Documents and Settings\user\My Documents\Cover Letter PT Studies Coordinator.docx
[2009/01/08 21:22:43 | 00,014,395 | —- | M] () – C:\Documents and Settings\user\My Documents\Combo Style Resume Karri.docx
< End of report >
___________________________________________________
OTViewIt Extras logfile created on: 1/31/2009 12:44:32 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 62.17% Memory free
3.35 Gb Paging File | 2.65 Gb Available in Paging File | 79.15% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 82.02 Gb Free Space | 44.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOUGAS3
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
"Use My Stylesheet"=
"User Stylesheet"=
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) – %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found – C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 19:12:34 | 00,141,312 | —- | M] (Microsoft Corporation) – %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 19:12:28 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found – C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2006/10/10 12:53:46 | 00,010,800 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
[2006/05/09 19:24:16 | 00,050,760 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1134336249\ee\aolsoftware.exe:*:Enabled:AOL Services
[2006/08/28 15:22:24 | 00,050,768 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1134336249\ee\aim6.exe:*:Enabled:AIM
[2006/10/17 12:56:10 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mshta.exe:*:Enabled:Microsoft ® HTML Application host
[2008/06/10 18:04:58 | 00,689,456 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client
File not found – C:\Program Files\Java\jre1.5.0_07\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
[2006/07/28 15:11:12 | 02,109,440 | —- | M] (mIRC Co. Ltd.) – C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC
[2008/10/27 17:05:49 | 00,270,128 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
File not found – C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/12/19 14:16:34 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
[2008/02/05 15:29:18 | 06,190,320 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox
[2008/05/22 21:14:46 | 00,214,560 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2008/05/21 04:37:24 | 12,844,576 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
[2007/08/29 00:23:36 | 00,340,856 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
[2008/05/21 05:54:40 | 01,022,496 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
[2009/01/29 23:07:05 | 01,032,984 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2007/05/18 00:00:00 | 04,583,424 | —- | M] () – C:\Program Files\Winsim\ConnectionManager\MySqlBinary\5.0.38\mysql\mysqld-nt.exe:*:Enabled:mysqld-nt.exe 5.0.38
[2008/06/06 00:00:00 | 00,018,216 | —- | M] (Sage Software) – C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe:*:Enabled:SimplyConnectionManager.exe
[2007/01/19 13:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 17:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2007/01/02 21:40:10 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
[2006/12/10 21:51:08 | 00,271,960 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
[2007/01/02 22:46:54 | 00,280,152 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
[2007/01/02 22:46:54 | 00,053,248 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
[2006/12/10 23:29:24 | 00,108,120 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
[2007/01/02 17:27:40 | 00,221,184 | —- | M] () – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
[2007/01/02 17:27:38 | 01,138,688 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
[2004/05/29 00:06:26 | 00,512,000 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy.exe:*:Enabled:hpqcopy.exe
[2007/01/02 22:46:54 | 00,472,664 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe
[2006/02/09 16:43:36 | 00,110,592 | R— | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe
[2006/02/09 16:41:28 | 00,573,440 | —- | M] ( ) – C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe
[2006/12/10 23:29:24 | 00,075,352 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe
[2008/11/01 12:15:46 | 00,067,128 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
[2008/11/20 14:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2008/11/07 14:31:38 | 21,633,320 | R— | M] (Skype Technologies S.A.) – C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/11/01 12:15:47 | 00,028,711 | —- | M] (Logitech Inc.) C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (bwfile-8876480:{9462A756-7B47-47BC-8C80-C34B9B80B32B} (HKLM) [BackWeb GA Pluggable Protocol])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/08/24 07:01:46 | 00,224,128 | —- | M] (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} (HKLM) [Local Groove Web Services Protocol])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/12/12 13:17:12 | 00,069,632 | —- | M] (Intuit Canada, a general partnership/une société en nom collectif.) C:\Program Files\QuickTax 2007\ic2007pp.dll (intu-qt2007:{026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} (HKLM) [qt2007 Pluggable Protocol Handler Class])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2009/01/30 00:02:00 | 00,079,128 | —- | M] (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgpp.dll (linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} (HKLM) [XPLPPFilter Class])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | —- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2006/10/26 13:45:02 | 00,873,216 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} (HKLM) [HxProtocol Class])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 12:53:24 | 00,063,344 | —- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/05/30 15:54:14 | 01,942,864 | R— | M] (Skype Technologies) C:\Program Files\Common Files\Skype\Skype4COM.dll (skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} (HKLM) [IEProtocolHandler Class])
========== (O18) Protocol Filters ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2006/10/26 21:41:48 | 00,044,344 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL text/xml:{807563E5-5146-11D5-A672-00B0D022E945} (HKLM) [Microsoft Office InfoPath XML Mime Filter]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}"=Windows Installer Clean Up
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}"=Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}"=WebReg
"{1A15507A-8551-4626-915D-3D5FA095CC1B}"=Corel Paint Shop Pro X
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}"=QuickTax 2007
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}"=HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java™ 6 Update 11
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}"=CreativeProjects
"{2DBFBD32-00BB-4678-B77B-8F5F729842BC}"=PS7600
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}"=Logitech SetPoint
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}"=ASUS Enhanced Display Driver
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}"=Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}"=Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}"=Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}"=Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160060}"=Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}"=PanoStandAlone
"{3666ABBE-F749-4747-BAAE-0B0712B130E4}"=Yahoo! Music Jukebox
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}"=HP Product Assistant
"{378299DC-4DA8-48B3-BD2C-4596EEDC0627}_is1"=Mystic Inn v1.0.8
"{3A1421C0-5610-46D4-8283-82F3CA755FDB}"=Roxio PhotoSuite 5
"{3AE681E0-4E8D-453F-950A-48534D3C0724}"=Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}"=HPSystemDiagnostics
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{45B6180B-DCAB-4093-8EE8-6164457517F0}"=Photosmart 140,240,7200,7600,7700,7900 Series
"{4817189D-1785-4627-A33C-39FD90919300}"=The Sims 2 Pets
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}"=DocProc
"{4ADC0BF7-B965-11D8-AA51-00B0D0627A8E}"=Simply Accounting 2005 Basic
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe® Photoshop® Album Starter Edition 3.0
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}"=BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}"=BPD_HPSU
"{517B8FB2-26EE-43B0-AE1B-07408860AA69}"=DigitImg
"{53337CA9-E9A4-4C59-9D1C-D980EF9BF0C2}"=QuickTax 2004
"{5421155F-B033-49DB-9B33-8F80F233D4D5}"=GdiplusUpgrade
"{5567F737-98A5-4CF3-8B4A-2F4E515966F7}"=Simply Accounting by Sage 2008
"{56F3E1FF-54FE-4384-A153-6CCABA097814}"=Creative MediaSource
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}"=Windows Live Messenger
"{590D4F8F-98FE-47FA-AC2B-3F22FDCF7C09}"=ShareIns
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}"=APC PowerChute Personal Edition
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}"=Skype™ 3.8
"{60758250-C8CF-47EB-8CB6-E0C3B84D8207}"=PSShortcuts
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}"=Windows Genuine Advantage v1.3.0254.0
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}"=HPProductAssistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}"=PowerDVD
"{6909F917-5499-482e-9AA1-FAD06A99F231}"=Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}"=The Sims 2 Family Fun Stuff
"{6DA9102E-199F-43A0-A36B-6EF48081A658}"=MobileMe Control Panel
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}"=HP Update
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}"=DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}"=overland
"{7729A02E-D1AD-4830-8FC5-11853500D90D}"=HP Officejet Pro All-In-One Series
"{777CA290-7D14-77c5-C518-684DC520A777}_is1"=Puzzle Mania
"{78AD4938-7EE6-4DC0-A5BC-3AF82750A617}"=QuickTax Tracker
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}"=Fax
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}"=The Sims 2 Open For Business
"{806E137F-D829-463D-8635-01A55A734B29}_is1"=Musikapa
"{81DB3158-20CC-41B1-8281-D5422F6DEA12}"=ASUS ATI Driver
"{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}"=3D Home Architect Design Suite Deluxe 8
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}"=HP Officejet Pro All-In-One Series
"{8777AC6D-89F9-4793-8266-DE406F343E89}"=QFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}"=7500_7600_7700_Help
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}"=The Sims 2
"{8C5766F2-81D9-4B5A-8AD5-A8BD6361EF0A}"=Hoyle Card Games
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}"=Unload
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}"=The Sims 2 University
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}"=Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}"=Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}"=Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}"=Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}"=Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}"=Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}"=Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}"=Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}"=Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}"=Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}"=Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}"=Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}"=Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}"=Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}"=Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}"=Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}"=Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}"=Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}"=Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}"=2007 Microsoft Office Suite Service Pack 1 (SP1)
"{937B232D-9776-471E-92BD-D424E514EF14}"=Logitech QuickCam
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}"=MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}"=Status
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}"=SkinsHP1
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}"=Destinations
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}"=QuickProjects
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}"=The Sims 2 Glamour Life Stuff
"{9E2514D9-DC24-4634-B348-61F3EF0F1628}"=Sound Blaster Audigy 2 ZS
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}"=PrintScreen
"{A06275F4-324B-4E85-95E6-87B2CD729401}"=Windows Defender
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}"=Microsoft Works 6.0
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}"=PhotoGallery
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}"=SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}"=L7500
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}"=Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{B2E92CF8-8D2F-4203-B5C4-177174472C9A}"=The Typing of The Dead
"{B376402D-58EA-45EA-BD50-DD924EB67A70}"=HP Memories Disc
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}"=CreativeProjectsTemplates
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B8D0BC3E-67DF-48A3-ACC9-EEAA8DBFBF29}"=QuickTax 2005
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}"=InstantShare
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}"=Works Synchronization
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}"=BufferChm
"{C1177B5C-6C8A-420B-84D3-287E456651F9}"=Airport Mania - First Flight
"{C3A439E4-7303-491F-A678-CEA36A87D517}"=Microsoft Works Suite Add-in for Microsoft Word
"{C4F1B9FE-F3AF-11D5-93D1-00C0CA18FDE6}"=Hotel Giant
"{C716522C-3731-4667-8579-40B098294500}"=Toolbox
"{C769A271-7E1C-48F9-B331-474600DD4C06}"=Microsoft Picture It! Photo 2002
"{C93A6CFE-2C74-428B-9CFE-6EAF1BE34BFA}"=ArcSoft Collage Creator
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}"=Adobe® Photoshop® Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}"=Nikon Message Center
"{D361C406-ED11-4A88-AD42-4A749BBAE6F9}"=Hoyle Card Games 2007
"{D48AD533-BAD5-469B-A9AA-272C6D80E70B}"=MPM
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}"=iPod for Windows 2005-10-12
"{DA83FEB1-B397-461D-B120-7B996E83ADEE}"=Simply Accounting by Sage 2008
"{DC19E750-988B-4005-A355-85EF66055EFE}"=Works Suite OS Pack
"{DE4997B5-55AD-4878-97A7-C9FA84FE23C7}"=PSUsage
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}"=ProductContext
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}"=UnloadSupport
"{EB21A812-671B-4D08-B974-2A347F0D8F70}"=HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}"=HPSSupply
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}"=BPDSoftware
"{EE7C3A14-1D20-49F6-B903-491561076F0F}"=ArcSoft Software Suite
"{F157460F-720E-482f-8625-AD7843891E5F}"=InstantShareDevicesMFC
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}"=32 Bit HP CIO Components Installer
"{F4476AF5-B402-4C62-BE7D-0182F2B15D0A}"=Simply Accounting by Sage 2008
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}"=The Sims 2 Nightlife
"{F929096B-54A0-4C5C-B125-1E7EB1917412}"=MySQL Connector/ODBC 3.51
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FAFDA89B-1031-4BDB-8619-DE20CBDEDF32}"=QuickTax 2006
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}"=HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF075778-6E50-47ed-991D-3B07FD4E3250}"=TrayApp
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}"=CueTour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}"=PictureProject
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player
"AIM_6.0"=AIM 6.0
"Arxon"=Arxon
"Avalon Deluxe_is1"=Avalon Deluxe v1.1.0
"AVG8Uninstall"=AVG Free 8.0
"Azangara_is1"=Azangara version 1.1
"Beach Party Craze1.0"=Beach Party Craze
"Bejeweled 2"=GameHouse Games Collection: Bejeweled 2
"BFGC"=Big Fish Games Client
"BFG-Home Sweet Home"=Home Sweet Home (remove only)
"Build-a-lot"=Build-a-lot
"Cake Mania"=Cake Mania
"Chameleon Gems"=Chameleon Gems
"Charm Tale"=GameHouse Games Collection: Charm Tale
"Chuzzle Deluxe"=GameHouse Games Collection: Chuzzle Deluxe
"Collapse! Crunch"=GameHouse Games Collection: Collapse! Crunch
"Combo Chaos!"=GameHouse Games Collection: Combo Chaos!
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"Crossing 3D_is1"=Crossing 3D 1.1
"Crystal Path"=GameHouse Games Collection: Crystal Path
"Cubis Gold 2"=GameHouse Games Collection: Cubis Gold 2
"Cursed Weel"=Cursed Weel 1.0
"Deep Sea Tycoon 2_is1"=Deep Sea Tycoon 2
"Delivery King"=Delivery King
"Diner Dash"=GameHouse Games Collection: Diner Dash
"E2BABA4F-C37B-4A6C-8F00-0D303441C2D3"=FATE from WildGames (remove only)
"Encore LaunchPad_is1"=Encore LaunchPad [removed]
"ENTERPRISE"=Microsoft Office Enterprise 2007
"EsetOnlineScanner"=ESET Online Scanner
"Farm Frenzy 21.0"=Farm Frenzy 2
"Feeding Frenzy"=GameHouse Games Collection: Feeding Frenzy
"Five Card Deluxe"=GameHouse Games Collection: Five Card Deluxe
"Flip Words"=GameHouse Games Collection: Flip Words
"Flying Leo"=GameHouse Games Collection: Flying Leo
"Fortune Tiles Gold"=GameHouse Games Collection: Fortune Tiles Gold
"Fresco Wizard"=GameHouse Games Collection: Fresco Wizard
"Gearz"=GameHouse Games Collection: Gearz
"Hamsterball"=GameHouse Games Collection: Hamsterball
"Hello!"=GameHouse Games Collection: Hello!
"HijackThis"=HijackThis 2.0.2
"Holiday Express"=GameHouse Games Collection: Holiday Express
"Home Sweet Home 2 Kitchens and Baths1.02"=Home Sweet Home 2 Kitchens and Baths
"HP Imaging Device Functions"=HP Imaging Device Functions 8.0
"HP Photo & Imaging"=HP Image Zone 4.0
"HP Solution Center & Imaging Support Tools"=HP Solution Center 8.0
"HPExtendedCapabilities"=HP Customer Participation Program 8.0
"HPOCR"=HP OCR Software 8.0
"Ice Age_is1"=Ice Age
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"Iggle Pop!"=GameHouse Games Collection: Iggle Pop!
"Incadia"=GameHouse Games Collection: Incadia
"Incredible Ink"=GameHouse Games Collection: Incredible Ink
"Insaniquarium Deluxe"=GameHouse Games Collection: Insaniquarium Deluxe
"Inspector Parker"=GameHouse Games Collection: Inspector Parker
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}"=DesignPro 5.4 Limited Edition
"InstallShield_{78AD4938-7EE6-4DC0-A5BC-3AF82750A617}"=QuickTax Tracker
"InstallShield_{83EC8AE9-53A6-474D-95AF-8F5116CC9C4E}"=3D Home Architect Design Suite Deluxe 8
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}"=iPod for Windows 2005-10-12
"Invadazoid"=GameHouse Games Collection: Invadazoid
"Jewel Quest"=GameHouse Games Collection: Jewel Quest
"Kaspersky Online Scanner"=Kaspersky Online Scanner
"legacyqcam_11.10"=Logitech Legacy USB Camera Driver Package
"Lemonade Tycoon"=GameHouse Games Collection: Lemonade Tycoon
"Lemonade Tycoon 2_is1"=Lemonade Tycoon 2
"Logitech Print Service"=Logitech Print Service
"Luxor"=GameHouse Games Collection: Luxor
"lvdrivers_11.90"=Logitech QuickCam Driver Package
"Mad Caps"=GameHouse Games Collection: Mad Caps
"Magic Ball 2"=GameHouse Games Collection: Magic Ball 2
"Magic Ball 2 - New Worlds"=GameHouse Games Collection: Magic Ball 2 - New Worlds
"Magic Ball Deluxe"=GameHouse Games Collection: Magic Ball
"Magic Inlay"=GameHouse Games Collection: Magic Inlay
"Magic Tea"=Magic Tea
"Magic Vines"=GameHouse Games Collection: Magic Vines
"Mah Jong Adventures"=GameHouse Games Collection: Mah Jong Adventures
"Mah Jong Medley"=GameHouse Games Collection: Mah Jong Medley
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Maui Wowee"=GameHouse Games Collection: Maui Wowee
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Mindlink2005Underground"=Mindlink2005Underground (remove only)
"Mirage Driver_is1"=Mirage Driver 1.1
"mIRC"=mIRC
"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"Mysteries of Horus"=Mysteries of Horus
"Nero - Burning Rom!UninstallKey"=Nero OEM
"NeroVision!UninstallKey"=NeroVision Express 2
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NMPUninstallKey"=Nero Media Player
"NVIDIA Drivers"=NVIDIA Drivers
"Operation Mania1.0.5"=Operation Mania
"Parking Dash1.0"=Parking Dash
"Phantasia 2"=Phantasia 2 1.02
"Phlinx To Go"=GameHouse Games Collection: Phlinx To Go
"Picasa2"=Picasa 2
"Pin High Country Club Golf"=GameHouse Games Collection: Pin High Country Club Golf
"Pizza Frenzy"=GameHouse Games Collection: Pizza Frenzy
"Platypus"=GameHouse Games Collection: Platypus
"Poker Superstars"=GameHouse Games Collection: Poker Superstars
"PopCap Browser Plugin"=PopCap Browser Plugin
"Puzzle Express"=GameHouse Games Collection: Puzzle Express
"Puzzle Inlay"=GameHouse Games Collection: Puzzle Inlay
"Puzzle Solitaire"=GameHouse Games Collection: Puzzle Solitaire
"QBz"=GameHouse Games Collection: QBz
"Ranch Rush1.0"=Ranch Rush
"Reader's Digest Super Word Power"=GameHouse Games Collection: Reader's Digest Super Word Power
"RealPlayer 6.0"=RealPlayer
"Ricochet"=GameHouse Games Collection: Ricochet
"Ricochet Lost Worlds"=GameHouse Games Collection: Ricochet Lost Worlds
"Ricochet Lost Worlds: Recharged"=GameHouse Games Collection: Ricochet Lost Worlds - Recharged
"Roboball"=Roboball
"Roller Rush"=GameHouse Games Collection: Roller Rush
"RotoBlox_is1"=RotoBlox version 2.2
"Saints & Sinners Bingo"=GameHouse Games Collection: Saints & Sinners Bingo
"Sandlot Games Client Services 1.2.2_is1"=Sandlot Games Client Services 1.2.2
"Sandlot Games Client Services_is1"=Sandlot Games Client Services
"SCRABBLE"=GameHouse Games Collection: SCRABBLE
"Sea Bounty"=Sea Bounty
"Shape Shifter"=GameHouse Games Collection: Shape Shifter
"ShockwaveFlash"=Adobe Flash Player 9 ActiveX
"Slingo Deluxe"=GameHouse Games Collection: Slingo Deluxe
"Spelvin"=GameHouse Games Collection: Spelvin
"Splash"=GameHouse Games Collection: Splash
"Spring Sprang Sprung"=GameHouse Games Collection: Spring Sprang Sprung
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.4
"Super 5-Line Slots"=GameHouse Games Collection: Super 5-Line Slots
"Super Blackjack!"=GameHouse Games Collection: Super Blackjack!
"Super Bounce Out!"=GameHouse Games Collection: Super Bounce Out!
"Super Candy Cruncher"=GameHouse Games Collection: Super Candy Cruncher
"Super Collapse!"=GameHouse Games Collection: Super Collapse!
"Super Collapse! II"=GameHouse Games Collection: Super Collapse! II
"Super Collapse! II Platinum"=GameHouse Games Collection: Super Collapse! II Platinum
"Super Fruit Frolic"=GameHouse Games Collection: Super Fruit Frolic
"Super GameHouse Solitaire Vol. 1"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 1
"Super GameHouse Solitaire Vol. 2"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 2
"Super GameHouse Solitaire Vol. 3"=GameHouse Games Collection: Super GameHouse Solitaire Vol. 3
"Super Gem Drop"=GameHouse Games Collection: Super Gem Drop
"Super Glinx!"=GameHouse Games Collection: Super Glinx!
"Super Letter Linker"=GameHouse Games Collection: Super Letter Linker
"Super Mah Jong Solitaire"=GameHouse Games Collection: Super Mah Jong Solitaire
"Super Nisqually"=GameHouse Games Collection: Super Nisqually
"Super PileUp!"=GameHouse Games Collection: Super PileUp!
"Super Pool"=GameHouse Games Collection: Super Pool
"Super Pop & Drop!"=GameHouse Games Collection: Super Pop & Drop!
"Super Rumble Cube"=GameHouse Games Collection: Super Rumble Cube
"Super SpongeBob Collapse!"=GameHouse Games Collection: Super SpongeBob Collapse!
"Super TextTwist"=GameHouse Games Collection: Super TextTwist
"Super WHATword"=GameHouse Games Collection: Super WHATword
"Super Wild Wild Words"=GameHouse Games Collection: Super Wild Wild Words
"SysInfo"=Creative System Information
"Tap a Jam"=GameHouse Games Collection: Tap a Jam
"Ten Pin Championship Bowling Pro"=GameHouse Games Collection: Ten Pin Championship Bowling Pro
"Tennis Titans"=GameHouse Games Collection: Tennis Titans
"Tetpic 4000(v2.6 Full Version)"=Tetpic 4000(v2.6 Full Version)
"The Treasures Of Montezuma"=The Treasures Of Montezuma
"Tradewinds 2"=GameHouse Games Collection: Tradewinds 2
"Trivia Machine"=GameHouse Games Collection: Trivia Machine
"Tropical Swaps"=GameHouse Games Collection: Tropical Swaps
"TUGZip_is1"=TUGZip 3.4
"Tumblebugs"=GameHouse Games Collection: Tumblebugs
"Turtle Bay"=GameHouse Games Collection: Turtle Bay
"Twistingo"=GameHouse Games Collection: Twistingo
"Ultimate Dominoes"=GameHouse Games Collection: Ultimate Dominoes
"uTorrent"=µTorrent
"Vanilla and Chocolate FINAL 1.00"=Vanilla and Chocolate FINAL 1.00
"Varmintz Deluxe"=GameHouse Games Collection: Varmintz Deluxe
"Walls of Jericho, The"=GameHouse Games Collection: Walls of Jericho, The
"Wedding Dash 2 - Rings Around the World1.0"=Wedding Dash 2 - Rings Around the World
"Wheel of Fortune"=GameHouse Games Collection: Wheel of Fortune
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMCSetup"=Windows Media Connect
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wonderland Online_is1"=Wonderland Online 2.0.3
"Word Jolt"=GameHouse Games Collection: Word Jolt
"Word Slinger"=GameHouse Games Collection: Word Slinger
"WordJong To Go"=GameHouse Games Collection: WordJong To Go
"Works2002Setup"=Microsoft Works 2002 Setup Launcher
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Zoo Tycoon 1.0"=Zoo Tycoon: Complete Collection
"Zuma Deluxe"=GameHouse Games Collection: Zuma Deluxe
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent"=µTorrent
"WeatherEye"=WeatherEye
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-2801406412-1217885714-445896202-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent"=µTorrent
"WeatherEye"=WeatherEye
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/28/2009 4:04:41 PM | Computer Name = TOUGAS3 | Source = Application Error | ID = 1000
Description = Faulting application pet show craze.exe, version 0.0.0.0, faulting
module pet show craze.exe, version 0.0.0.0, fault address 0x0007264a.
Error - 1/28/2009 4:11:28 PM | Computer Name = TOUGAS3 | Source = Application Error | ID = 1000
Description = Faulting application pet show craze.exe, version 0.0.0.0, faulting
module pet show craze.exe, version 0.0.0.0, fault address 0x0007264a.
Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.
Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).
Error - 1/29/2009 5:58:09 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).
Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.
Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).
Error - 1/30/2009 1:53:42 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).
Error - 1/30/2009 7:26:24 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 34
Description = Failed to get the Crawl Scope Manager with error=0x8001010d.
Error - 1/30/2009 7:26:24 PM | Computer Name = TOUGAS3 | Source = Outlook | ID = 35
Description = Failed to determine if the store is in the crawl scope (error=0x8001010d).
[ OSession Events ]
Error - 9/3/2008 10:31:00 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 31
seconds with 0 seconds of active time. This session ended with a crash.
Error - 9/3/2008 10:31:39 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.
Error - 9/8/2008 5:23:27 PM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 631
seconds with 240 seconds of active time. This session ended with a crash.
Error - 9/15/2008 10:02:22 AM | Computer Name = TOUGAS3 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 55389
seconds with 300 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 1/31/2009 1:55:53 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:53 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 1:55:54 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 1/31/2009 10:53:15 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7000
Description = The Automatic LiveUpdate Scheduler service failed to start due to
the following error: %%3
Error - 1/31/2009 10:53:15 AM | Computer Name = TOUGAS3 | Source = Service Control Manager | ID = 7000
Description = The PfModNT service failed to start due to the following error: %%2
< End of report >