Very Hot Computer and Unknown .exe in the task manage\r |
![]() ![]() |
Very Hot Computer and Unknown .exe in the task manage\r |
Jul 23 2009, 11:41 PM
Post
#1
|
|
|
New Member ![]() Posts: 3 OS: Vista |
Hello, my laptop and the power inverter has been running hot and the memory at about 50-60%. It never has run that high, and there is an unknown .exe file in my task manager that doesn't belong to the program google says it does, as it's never been on my hard drive. It's not the BIOS, that was updated after the computer began heating up. I'm all caught up on drivers and windows updates. There are no "new" programs installed my me besides the few that were told to by the guide. I have Ad aware, Telus security, windows firewall. I run ad aware and telus scanner weekly, and have no other symptoms aside l
Log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/07/23 19:30 Program Version: Version 1.3.2.0 Windows Version: Windows Vista SP1 ================================================== Processes ------------------- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\spoolsv.exe PID: 372 Status: - Path: C:\Windows\System32\smss.exe PID: 424 Status: - Path: C:\Windows\System32\wlanext.exe PID: 444 Status: - Path: C:\Windows\System32\svchost.exe PID: 456 Status: - Path: C:\Windows\System32\taskeng.exe PID: 532 Status: - Path: C:\Windows\System32\csrss.exe PID: 572 Status: - Path: C:\Windows\System32\wininit.exe PID: 624 Status: - Path: C:\Windows\System32\csrss.exe PID: 636 Status: - Path: C:\Windows\System32\services.exe PID: 668 Status: - Path: C:\Windows\System32\lsass.exe PID: 680 Status: - Path: C:\Windows\System32\lsm.exe PID: 688 Status: - Path: C:\Windows\System32\svchost.exe PID: 832 Status: - Path: C:\Windows\System32\nvvsvc.exe PID: 876 Status: - Path: C:\Windows\System32\winlogon.exe PID: 912 Status: - Path: C:\Windows\System32\svchost.exe PID: 936 Status: - Path: C:\Windows\System32\svchost.exe PID: 980 Status: - Path: C:\Windows\System32\svchost.exe PID: 1076 Status: - Path: C:\Windows\System32\svchost.exe PID: 1136 Status: - Path: C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe PID: 1156 Status: - Path: C:\Windows\System32\svchost.exe PID: 1200 Status: - Path: C:\Windows\System32\audiodg.exe PID: 1252 Status: Locked to the Windows API! Path: C:\Windows\System32\svchost.exe PID: 1276 Status: - Path: C:\Windows\System32\SLsvc.exe PID: 1300 Status: - Path: C:\Windows\System32\svchost.exe PID: 1352 Status: - Path: C:\Windows\System32\rundll32.exe PID: 1408 Status: - Path: C:\Program Files\TELUS\TELUS security services\Fws.exe PID: 1604 Status: - Path: C:\Program Files\Windows Sidebar\sidebar.exe PID: 1632 Status: - Path: C:\Windows\System32\dwm.exe PID: 1712 Status: - Path: C:\Windows\explorer.exe PID: 1740 Status: - Path: C:\Windows\System32\svchost.exe PID: 1820 Status: - Path: C:\Windows\System32\taskeng.exe PID: 1840 Status: - Path: C:\Program Files\TELUS\TELUS security services\RPS.exe PID: 1872 Status: - Path: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe PID: 1976 Status: - Path: C:\Program Files\Common Files\LightScribe\LSSrvc.exe PID: 2064 Status: - Path: C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe PID: 2128 Status: - Path: C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe PID: 2200 Status: - Path: C:\Program Files\Raxco\PerfectDisk\PDAgent.exe PID: 2240 Status: - Path: C:\Windows\System32\svchost.exe PID: 2284 Status: - Path: C:\Windows\SMINST\BLService.exe PID: 2300 Status: - Path: C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe PID: 2308 Status: - Path: C:\Program Files\CyberLink\Shared Files\RichVideo.exe PID: 2352 Status: - Path: C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PID: 2380 Status: - Path: C:\Windows\System32\svchost.exe PID: 2448 Status: - Path: C:\Windows\System32\svchost.exe PID: 2492 Status: - Path: C:\Windows\System32\SearchIndexer.exe PID: 2524 Status: - Path: C:\Windows\System32\drivers\XAudio.exe PID: 2572 Status: - Path: C:\Program Files\Raxco\PerfectDisk\PDEngine.exe PID: 2772 Status: - Path: C:\Windows\System32\wbem\unsecapp.exe PID: 2780 Status: - Path: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PID: 3004 Status: - Path: C:\Program Files\Windows Defender\MSASCui.exe PID: 3052 Status: - Path: C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe PID: 3092 Status: - Path: C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe PID: 3148 Status: - Path: C:\Windows\System32\wbem\WmiPrvSE.exe PID: 3200 Status: - Path: C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe PID: 3240 Status: - Path: C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe PID: 3420 Status: - Path: C:\Program Files\TELUS\TELUS security advisor\Tsa.exe PID: 3464 Status: - Path: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe PID: 3488 Status: - Path: C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe PID: 3524 Status: - Path: C:\Program Files\Java\jre6\bin\jusched.exe PID: 3588 Status: - Path: C:\Program Files\Zune\ZuneLauncher.exe PID: 3636 Status: - Path: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe PID: 3844 Status: - Path: C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe PID: 3852 Status: - Path: C:\Program Files\Windows Media Player\wmpnscfg.exe PID: 3888 Status: - Path: C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe PID: 4012 Status: - Path: C:\Program Files\HP\QuickPlay\QPService.exe PID: 4016 Status: - Path: C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe PID: 4200 Status: - Path: C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe PID: 4220 Status: - Path: C:\Program Files\Windows Media Player\wmpnetwk.exe PID: 4324 Status: - Path: C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe PID: 4344 Status: - Path: C:\Program Files\Mozilla Firefox\firefox.exe PID: 4444 Status: - Path: C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe PID: 4984 Status: - Path: C:\Program Files\Windows Sidebar\sidebar.exe PID: 5076 Status: - Path: C:\Program Files\TELUS\TELUS security services\Kav\Bin\ScanningProcess.exe PID: 5148 Status: - Path: C:\Program Files\Synaptics\SynTP\SynTPHelper.exe PID: 6132 Status: - Path: C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe PID: 6424 Status: - Path: C:\Windows\System32\svchost.exe PID: 6796 Status: - Path: C:\Windows\System32\SearchProtocolHost.exe PID: 7296 Status: - Path: C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe PID: 8012 Status: - Path: C:\Users\Kitten\AppData\Local\Temp\Temp1_RootRepeal.zip\RootRepeal.exe PID: 8936 Status: - Path: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe PID: 9300 Status: - Path: C:\Windows\System32\wbem\WmiPrvSE.exe PID: 9876 Status: - Path: C:\Windows\System32\SearchFilterHost.exe PID: 10128 Status: - MBAM: Malwarebytes' Anti-Malware 1.39 Database version: 2492 Windows 6.0.6001 Service Pack 1 23/07/2009 10:40:28 PM mbam-log-2009-07-23 (22-40-28).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 253778 Time elapsed: 3 hour(s), 14 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) OTL: Otl.txt: OTL logfile created on: 23/07/2009 7:31:14 PM - Run 1 OTL by OldTimer - Version 3.0.10.2 Folder = C:\Users\Kitten\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18783) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.17% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 176.49 Gb Total Space | 127.35 Gb Free Space | 72.16% Space Free | Partition Type: NTFS Drive D: | 9.82 Gb Total Space | 1.45 Gb Free Space | 14.75% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KITTEN-LAPTOP Current User Name: Kitten Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Processes (SafeList) ========== PRC - [2008/07/12 09:31:00 | 00,196,608 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe PRC - [2007/07/20 01:40:48 | 00,137,752 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe PRC - [2008/10/09 14:19:40 | 00,359,664 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\Fws.exe PRC - [2008/10/28 23:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE PRC - [2008/10/09 14:20:26 | 00,626,928 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\rps.exe PRC - [2009/07/06 22:43:25 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe PRC - [2009/01/27 22:37:24 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe PRC - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe PRC - [2008/04/28 08:23:28 | 00,414,984 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe PRC - [2008/04/25 16:15:26 | 00,361,808 | ---- | M] () -- C:\Windows\SMINST\BLService.exe PRC - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe PRC - [2007/01/09 02:25:00 | 00,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe PRC - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PRC - [2007/10/17 16:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe PRC - [2008/04/28 08:23:36 | 00,738,568 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe PRC - [2008/01/20 19:23:52 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe PRC - [2008/04/17 11:05:10 | 01,049,896 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PRC - [2008/01/20 19:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2008/08/01 17:14:02 | 00,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe PRC - [2008/06/02 00:55:22 | 00,080,896 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe PRC - [2009/03/02 19:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe PRC - [2008/04/15 14:51:00 | 00,488,752 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe PRC - [2008/09/18 12:11:22 | 03,228,912 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security advisor\Tsa.exe PRC - [2009/07/06 22:43:26 | 00,520,024 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe PRC - [2007/07/25 17:02:54 | 00,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe PRC - [2008/12/12 12:41:06 | 00,157,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneLauncher.exe PRC - [2009/03/10 20:19:56 | 00,468,264 | ---- | M] (CyberLink Corp.) -- C:\Program Files\HP\QuickPlay\QPService.exe PRC - [2008/05/01 17:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe PRC - [2008/01/20 19:23:29 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe PRC - [2007/08/30 11:50:42 | 00,205,480 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe PRC - [2008/01/20 19:25:33 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe PRC - [2009/01/29 23:32:29 | 00,091,440 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe PRC - [2008/04/03 12:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe PRC - [2007/09/26 07:34:40 | 00,316,720 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE PRC - [2008/01/20 19:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe PRC - [2008/10/09 14:20:28 | 00,096,496 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe PRC - [2008/04/11 10:04:54 | 00,685,360 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe PRC - [2008/01/20 19:23:29 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe PRC - [2008/07/04 12:45:06 | 00,139,264 | ---- | M] (Kaspersky Lab.) -- C:\Program Files\TELUS\TELUS security services\Kav\Bin\ScanningProcess.exe PRC - [2008/04/17 11:05:20 | 00,103,720 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe PRC - [2007/07/25 17:02:32 | 00,403,728 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe PRC - [2008/10/09 07:56:48 | 00,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe PRC - [2008/06/19 18:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe PRC - [2009/07/06 22:43:32 | 02,353,480 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe PRC - [2009/07/22 09:06:17 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009/07/13 13:36:16 | 01,287,440 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe PRC - [2009/07/23 19:26:44 | 00,469,504 | ---- | M] ( ) -- C:\Users\Kitten\AppData\Local\Temp\Temp1_RootRepeal.zip\RootRepeal.exe PRC - [2009/03/02 19:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe PRC - [2009/07/23 19:31:08 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2008/07/27 11:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2008/04/03 12:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe -- (Com4QLBEx [On_Demand | Running]) SRV - [2008/01/20 19:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped]) SRV - [2006/11/02 05:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped]) SRV - [2006/11/02 05:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped]) SRV - [2008/01/20 19:23:49 | 01,013,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running]) SRV - [2008/06/19 18:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Running]) SRV - [2009/02/06 18:08:58 | 00,533,360 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc [On_Demand | Stopped]) SRV - [2007/12/04 17:41:34 | 00,181,784 | ---- | M] (WildTangent, Inc.) -- C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe -- (GameConsoleService [On_Demand | Stopped]) SRV - [2008/10/09 07:56:48 | 00,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service [Auto | Running]) SRV - [2008/05/01 17:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe -- (hpqwmiex [On_Demand | Running]) SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008/06/19 18:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped]) SRV - [2009/07/06 22:43:25 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [Auto | Running]) SRV - [2009/01/27 22:37:24 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running]) SRV - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer [Auto | Running]) SRV - [2007/07/20 01:40:48 | 00,137,752 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running]) SRV - [2007/07/20 01:42:30 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped]) SRV - [2008/06/19 18:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped]) SRV - [2008/07/12 09:31:00 | 00,196,608 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running]) SRV - [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped]) SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2008/04/28 08:23:28 | 00,414,984 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe -- (PDAgent [Auto | Running]) SRV - [2008/04/28 08:23:36 | 00,738,568 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe -- (PDEngine [On_Demand | Running]) SRV - [2008/10/09 14:20:28 | 00,096,496 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe -- (Radialpoint Security Services [On_Demand | Running]) SRV - [2008/04/25 16:15:26 | 00,361,808 | ---- | M] () -- C:\Windows\SMINST\BLService.exe -- (Recovery Service for Windows [Auto | Running]) SRV - [2007/01/09 02:25:00 | 00,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running]) SRV - File not found -- -- (RoxLiveShare9 [Auto | Stopped]) SRV - [2008/10/09 14:19:40 | 00,359,664 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\Fws.exe -- (RP_FWS [Auto | Running]) SRV - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running]) SRV - [2008/01/20 19:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running]) SRV - [2008/01/20 19:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running]) SRV - [2007/10/17 16:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe -- (XAudioService [Auto | Running]) SRV - [2008/12/12 12:41:18 | 05,117,568 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc [On_Demand | Stopped]) SRV - [2008/12/12 12:41:08 | 00,243,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc [On_Demand | Stopped]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...rio&pf=cnnb IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...rio&pf=cnnb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...rio&pf=cnnb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...rio&pf=cnnb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1 FF - prefs.js..extensions.enabledItems: {40520fe7-6336-4df2-bab1-1f1f8e11bf27}:0.3 FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1 FF - prefs.js..extensions.enabledItems: {2cb97724-d789-4f43-8888-a763cbb8df6f}:3.0.2564.27062 FF - prefs.js..extensions.enabledItems: {F645A8C9-E969-42D9-B3F3-F325537222FD}:1.1.5 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.12 FF - prefs.js..extensions.enabledItems: info@djzig.com:1.0.7 FF - prefs.js..extensions.enabledItems: {d596c130-b00a-11db-abbd-0800200c9a66}:2.080708 FF - prefs.js..extensions.enabledItems: {BF32D2C8-9C75-404b-ACF4-880DB4679236}:1.1 FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.48 FF - prefs.js..extensions.enabledItems: {333b42b0-9c75-11db-b606-0800200c9a66}:2.090208 FF - prefs.js..extensions.enabledItems: redshift_V2@shift-themes.com:2.95 FF - prefs.js..keyword.URL: "http://www.ask.com/web?o=101447&l=dis&q=" FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/05 16:25:37 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/22 20:01:40 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/22 09:06:25 | 00,000,000 | ---D | M] [2009/06/08 15:43:33 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions [2008/10/10 18:01:09 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/06/08 15:43:33 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org [2009/07/23 17:36:37 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions [2009/07/07 09:19:31 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009/03/18 23:30:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{2cb97724-d789-4f43-8888-a763cbb8df6f} [2008/10/10 18:09:34 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{333b42b0-9c75-11db-b606-0800200c9a66} [2008/12/01 09:32:51 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{40520fe7-6336-4df2-bab1-1f1f8e11bf27} [2009/03/30 11:42:32 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236} [2009/07/13 17:04:29 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/05/13 09:04:36 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [2008/10/10 18:09:45 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{d596c130-b00a-11db-abbd-0800200c9a66} [2009/07/13 17:04:01 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008} [2009/05/13 09:04:44 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{F645A8C9-E969-42D9-B3F3-F325537222FD} [2009/07/13 17:04:14 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com [2009/03/14 21:24:39 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\redshift_V2@shift-themes.com [2009/07/13 17:04:22 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions [2009/07/13 17:04:26 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\chatzilla [2009/07/13 17:04:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\Console2 [2009/07/13 17:04:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\downthemall [2009/07/13 17:04:22 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\emusic [2009/07/13 17:04:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\fullerscreen [2009/07/13 17:04:26 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\sage [2009/07/13 17:04:25 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\toolkit [2009/07/13 17:04:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\global\extensions\webdeveloper [2009/07/13 17:04:24 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\info@djzig.com\chrome\mozapps\extensions [2009/07/23 17:36:37 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/07/22 09:06:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/14 11:20:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/04/15 21:15:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009/07/22 09:06:16 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/07/22 09:06:16 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2009/07/22 09:06:19 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009/02/19 12:33:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/02/19 12:33:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/02/19 12:33:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/02/19 12:33:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/02/19 12:33:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/02/19 12:33:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/02/19 12:33:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\TELUS\TELUS security services\pkR.dll (TELUS) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft) O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe () O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe () O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [QlbCtrl.exe] File not found O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) O4 - HKLM..\Run: [Tsa.exe] C:\Program Files\TELUS\TELUS security advisor\Tsa.exe (TELUS) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation) O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation) O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found O4 - Startup: C:\Users\Kitten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008/06/24 23:20:48 | 00,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (PDBoot.exe) - C:\Windows\System32\PDBoot.exe (Raxco Software, Inc.) O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe () ========== Files/Folders - Created Within 14 Days ========== [2009/07/23 19:31:00 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe [2009/07/23 19:26:53 | 00,000,014 | ---- | C] () -- C:\Windows\System32\settings.dat [2009/07/23 19:26:05 | 00,462,508 | ---- | C] () -- C:\Users\Kitten\Desktop\RootRepeal.zip [2009/07/23 19:17:58 | 00,000,000 | ---D | C] -- C:\Users\Kitten\AppData\Roaming\Malwarebytes [2009/07/23 19:17:43 | 00,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/07/23 19:17:38 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/07/23 19:17:33 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009/07/23 19:17:32 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009/07/23 19:17:31 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/07/23 19:16:38 | 03,775,200 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Kitten\Desktop\mbam-setup.exe [2009/07/14 14:17:27 | 00,000,246 | ---- | C] () -- C:\ProgramData\hpqp.ini [2009/07/14 14:05:59 | 00,000,766 | ---- | C] () -- C:\Windows\System\CRIcon.ico [2009/07/13 09:49:30 | 00,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch ========== Files - Modified Within 14 Days ========== [1 C:\Users\Kitten\Desktop\*.tmp files] [2009/07/23 19:37:59 | 30,138,9344 | ---- | M] () -- C:\Windows\System32\drivers\fidbox.dat [2009/07/23 19:37:39 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009/07/23 19:37:39 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009/07/23 19:31:08 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe [2009/07/23 19:28:40 | 00,000,014 | ---- | M] () -- C:\Windows\System32\settings.dat [2009/07/23 19:26:17 | 00,462,508 | ---- | M] () -- C:\Users\Kitten\Desktop\RootRepeal.zip [2009/07/23 19:17:43 | 00,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/07/23 19:17:00 | 03,775,200 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Kitten\Desktop\mbam-setup.exe [2009/07/23 16:23:46 | 00,042,654 | ---- | M] () -- C:\ProgramData\nvModes.dat [2009/07/23 16:23:46 | 00,042,654 | ---- | M] () -- C:\ProgramData\nvModes.001 [2009/07/23 13:38:16 | 00,000,246 | ---- | M] () -- C:\ProgramData\hpqp.ini [2009/07/23 13:37:33 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009/07/23 13:37:24 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009/07/23 13:13:31 | 04,019,384 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx [2009/07/23 13:12:09 | 02,087,093 | -H-- | M] () -- C:\Users\Kitten\AppData\Local\IconCache.db [2009/07/20 22:43:31 | 00,000,472 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job [2009/07/19 19:55:29 | 00,018,944 | ---- | M] () -- C:\Users\Kitten\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/07/19 17:08:57 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2009/07/19 17:08:57 | 00,600,378 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2009/07/19 17:08:57 | 00,105,852 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2009/07/16 03:11:55 | 00,325,304 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2009/07/14 13:55:08 | 00,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys ========== LOP Check ========== [2009/07/23 19:17:58 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming [2008/10/28 14:04:42 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\CyberLink [2009/07/16 11:37:30 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\gtk-2.0 [2009/07/23 17:05:52 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\LimeWire [2006/11/02 05:37:34 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Media Center Programs [2009/03/18 23:30:25 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Neopets Toolbar [2009/01/14 17:38:03 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\OpenOffice.org [2008/12/18 17:47:12 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Roxio [2009/01/05 15:50:28 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\TELUS [2008/11/14 00:36:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\WildTangent [2009/07/20 22:43:31 | 00,000,472 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job [2009/07/23 13:37:33 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT [2009/07/23 13:13:10 | 00,032,586 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== < End of report > Extras.txt: OTL Extras logfile created on: 23/07/2009 7:31:14 PM - Run 1 OTL by OldTimer - Version 3.0.10.2 Folder = C:\Users\Kitten\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18783) Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.17% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 176.49 Gb Total Space | 127.35 Gb Free Space | 72.16% Space Free | Partition Type: NTFS Drive D: | 9.82 Gb Total Space | 1.45 Gb Free Space | 14.75% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KITTEN-LAPTOP Current User Name: Kitten Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Standard Quick Scan ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 1 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5F6120BC-3238-4E95-821C-74C215417330}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{E7FD2062-6DDA-4E16-A14C-6894B8DFC2E4}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{035E6C05-5819-453E-B021-D405A000E6B9}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe | "{057509AF-B2A3-4370-B773-8E7908C8AF0C}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe | "{0E3508F8-00B5-4ECF-A32B-A2F2535E3BE0}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe | "{1378A3D2-157A-46A2-8CE7-DCE7CC4062FF}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{3EC5547E-F450-4C7A-90C1-B84D97B9E6CF}" = dir=in | app=c:\program files\hp\quickplay\qp.exe | "{78946C39-7433-4430-8B05-9EAF59BB895A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{83D84E26-4EDD-4C3D-B5C3-37AB286E5C7E}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | "{8CCEE29B-8F38-40CC-9808-FBC764CCFC63}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{902C1511-41EA-4F94-8EAA-2178A9826391}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{92F5A740-C6A2-4E1D-901F-4F9CADF08992}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{95039E0D-7034-494D-957D-286DA49A7218}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{A0F1928E-7339-4F6A-82E2-9BCB0ABAE115}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{B90E297B-AF2D-44A9-BEF8-65E48FF7F58C}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{C6E58109-6DA8-40CC-8C76-8A21CA658770}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{C8C404FA-74F4-47B3-B849-CA3DA33510EB}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe | "{D9BF988D-14C4-41E8-9410-882DDAAF9EE0}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "TCP Query User{7E85BBC6-5E36-4E9B-995A-EB9BE94ACBD3}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe | "UDP Query User{B77B0F61-0E19-4558-821B-A5404F1ADD87}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support "{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR) "{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1 "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger "{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1 "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1 "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{212F5777-1190-4DEF-8E4D-6B2F313B45E7}" = PerfectDisk "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection "{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 13 "{30383EB1-E954-4CA3-B7DE-9C3A68B69D26}" = RPS Privacy Manager "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7 "{3249C40F-A3BF-4ECC-9824-2F3EB9BFE6A1}" = RPS Ksdk "{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2 "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision "{35CB5932-AE03-491E-9674-DF8E1F38D253}" = RPS Performance Tool "{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1 "{364EC092-93CF-4DDC-9D7A-7278452028E0}" = Logitech QuickCam "{3686AE6A-D426-402A-9A49-973867C92BC4}" = RPS App Detector "{380357CA-29F4-4B3C-B401-32C057E6B59B}" = HP Smart Web Printing "{3838AF48-56E2-4E52-8482-D17CABF63441}" = RPS CRT "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go "{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module "{4229B337-0C40-4181-9C41-CAC4C5952A7A}" = RPS Burn "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7 "{4A9849CA-E11C-4F24-8BB1-97C717A1C898}" = LightScribe System Software "{4C68AB1C-95CB-4699-BBDE-EC4FA2931E3A}" = RPS Security Cleanup "{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update "{55DBDE34-2CAE-455C-A1CD-D91F5EE8E4E0}" = TELUS security services "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3 "{5D995085-1609-40D6-85CD-654C13430EE1}" = RPS ParentalControl "{5DE9ADA1-B9F0-45C5-947F-12E667B01F69}" = RPS Diagnostic Utility "{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2 "{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety "{77E1B36B-2C8F-4D89-ABF0-F3FC85516AC5}" = RPS Ad Blocker "{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module "{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{929A59BE-1E16-41EF-88CA-1006DE77D480}" = RPS AntiSpyware "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar "{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel "{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync "{A296E88E-8459-4CF7-A7C8-AA65A04CAF75}" = RPS Zip "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1 "{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin "{B21DE8E2-03E6-4CFD-A94D-95CC42CD49C8}" = RPS Backup "{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc "{B640E7CC-7091-4A24-AE76-2140065D2054}" = HP User Guides 0110 "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5 "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials "{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library "{D0C5C43F-C534-4A35-AC67-98E64242A3FF}" = RPS AntiFraud "{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader "{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1 "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01 "{E1374244-A8FE-4FDF-B823-184061FE16C5}" = RPS PopupBlocker "{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES) "{EED7DDDC-A01A-4A0D-884A-272C02E96903}" = RPS Firewall "{F06D2782-4C7B-4778-901D-79D63E1B9BB9}" = RPS AntiVirus "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F31E534B-4199-4552-8154-5C130710D68E}" = HP Total Care Advisor "{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0 "{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup "{FDDA11D6-00DE-4957-8761-F97145F438B7}" = RPS RpsCore "{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune "Action Replay Code Manager_is1" = Action Replay Code Manager "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Ad-Aware" = Ad-Aware "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "CNXT_AUDIO_HDA" = Conexant HD Audio "CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "HP Photosmart Essential" = HP Photosmart Essential 2.5 "HP Smart Web Printing" = HP Smart Web Printing "InstallShield_{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "LimeWire" = LimeWire 5.1.3 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.0.12)" = Mozilla Firefox (3.0.12) "Neopets" = Neopets "NVIDIA Drivers" = NVIDIA Drivers "QcDrv" = Logitech® Camera Driver "RadialpointClientGateway_is1" = TELUS security advisor 2.0.21 "SynTPDeinstKey" = Synaptics Pointing Device Driver "WildTangent hp Master Uninstall" = My HP Games "Winamp" = Winamp "WinGimp-2.0_is1" = GIMP 2.4.7 "WinLiveSuite_Wave3" = Windows Live Essentials "Zune" = Zune ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 14/07/2009 5:02:13 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0 Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'. at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri, XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String path) ValidateDocument failed SecurityStates.xml Error - 14/07/2009 5:02:13 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0 Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'. at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri, XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String path) ValidateDocument failed SecurityOffers.xml Error - 14/07/2009 5:05:23 PM | Computer Name = Kitten-Laptop | Source = VSS | ID = 8194 Description = Error - 14/07/2009 5:07:18 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0 Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'. at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri, XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String path) ValidateDocument failed HPPrintersStates.xml Error - 15/07/2009 2:25:02 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = Error - 16/07/2009 6:11:56 AM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = Error - 17/07/2009 12:06:06 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = Error - 17/07/2009 3:44:33 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = Error - 19/07/2009 7:10:14 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = Error - 19/07/2009 7:53:25 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 15/03/2009 11:06:00 PM | Computer Name = Kitten-Laptop | Source = bowser | ID = 8003 Description = Error - 16/03/2009 1:39:00 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016 Description = Error - 16/03/2009 1:40:32 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000 Description = Error - 16/03/2009 1:40:32 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009 Description = Error - 16/03/2009 11:28:08 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016 Description = Error - 16/03/2009 11:29:40 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000 Description = Error - 16/03/2009 11:29:40 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009 Description = Error - 17/03/2009 12:41:16 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016 Description = Error - 17/03/2009 12:42:48 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000 Description = Error - 17/03/2009 12:42:48 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009 Description = < End of report > |
|
|
Jul 25 2009, 12:08 AM
Post
#2
|
|
|
New Member ![]() Posts: 3 OS: Vista |
Bump
|
|
|
Jul 28 2009, 05:37 PM
Post
#3
|
|
|
New Member ![]() Posts: 3 OS: Vista |
What kind of help site is this that doesn't help people when they do what the helpsite says to do? You can't even post something like "I dont know try this" or something? Delete my account, please. This is pathetic.
|
|
|
Jul 29 2009, 03:51 AM
Post
#4
|
|
![]() Malware Moderator / Malware Staff Posts: 2,456 From: The Land Down Under OS: Windows XP pro |
While we try to help everyone as quickly as possible, our malware team is vastly outnumbered by people needing help. Some of our experts work from the older topics towards the newer ones and some take on newer topics rather than older ones. We encourage the former practice, but that's not always practical.
Some of the helpers are more comfortable with certain infections and seek them out...still other helpers will look for the tougher infections to take on. This may explain, at least partially, the seemingly random nature of how topics are selected. We DO try to get to everyone in a timely manner, but as you've seen, the Malware Forum presents a pretty formidable workload for the number of staff members we have. Take a look at this topic which gives instructions when your topic is at least three days old and you haven't received help. That topic is also pinned at the top of this forum. If you still require help then follow those instructions, if not then this topic will be closed as you request. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
36 / 2,434 | 15th October 2005 - 07:31 PM mln started - last by loophole |
|||||
![]() |
0 / 304 | 6th March 2008 - 08:26 AM Tsewangster started - last by Tsewangster |
|||||
![]() |
4 / 396 | 4th January 2009 - 10:54 PM mmatisoff started - last by Broni |
|||||
![]() |
1 / 178 | 2nd August 2009 - 03:34 AM Lagsta started - last by Neil Jones |
|||||
|
Time is now: 21st November 2009 - 01:21 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising