Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Very Hot Computer and Unknown .exe in the task manage\r


  • Please log in to reply

#1
CameraKitten

CameraKitten

    New Member

  • Member
  • Pip
  • 3 posts
Hello, my laptop and the power inverter has been running hot and the memory at about 50-60%. It never has run that high, and there is an unknown .exe file in my task manager that doesn't belong to the program google says it does, as it's never been on my hard drive. It's not the BIOS, that was updated after the computer began heating up. I'm all caught up on drivers and windows updates. There are no "new" programs installed my me besides the few that were told to by the guide. I have Ad aware, Telus security, windows firewall. I run ad aware and telus scanner weekly, and have no other symptoms aside l

Log:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/07/23 19:30
Program Version: Version 1.3.2.0
Windows Version: Windows Vista SP1
==================================================

Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\spoolsv.exe
PID: 372 Status: -

Path: C:\Windows\System32\smss.exe
PID: 424 Status: -

Path: C:\Windows\System32\wlanext.exe
PID: 444 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 456 Status: -

Path: C:\Windows\System32\taskeng.exe
PID: 532 Status: -

Path: C:\Windows\System32\csrss.exe
PID: 572 Status: -

Path: C:\Windows\System32\wininit.exe
PID: 624 Status: -

Path: C:\Windows\System32\csrss.exe
PID: 636 Status: -

Path: C:\Windows\System32\services.exe
PID: 668 Status: -

Path: C:\Windows\System32\lsass.exe
PID: 680 Status: -

Path: C:\Windows\System32\lsm.exe
PID: 688 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 832 Status: -

Path: C:\Windows\System32\nvvsvc.exe
PID: 876 Status: -

Path: C:\Windows\System32\winlogon.exe
PID: 912 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 936 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 980 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 1076 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 1136 Status: -

Path: C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PID: 1156 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 1200 Status: -

Path: C:\Windows\System32\audiodg.exe
PID: 1252 Status: Locked to the Windows API!

Path: C:\Windows\System32\svchost.exe
PID: 1276 Status: -

Path: C:\Windows\System32\SLsvc.exe
PID: 1300 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 1352 Status: -

Path: C:\Windows\System32\rundll32.exe
PID: 1408 Status: -

Path: C:\Program Files\TELUS\TELUS security services\Fws.exe
PID: 1604 Status: -

Path: C:\Program Files\Windows Sidebar\sidebar.exe
PID: 1632 Status: -

Path: C:\Windows\System32\dwm.exe
PID: 1712 Status: -

Path: C:\Windows\explorer.exe
PID: 1740 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 1820 Status: -

Path: C:\Windows\System32\taskeng.exe
PID: 1840 Status: -

Path: C:\Program Files\TELUS\TELUS security services\RPS.exe
PID: 1872 Status: -

Path: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PID: 1976 Status: -

Path: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PID: 2064 Status: -

Path: C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PID: 2128 Status: -

Path: C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
PID: 2200 Status: -

Path: C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
PID: 2240 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 2284 Status: -

Path: C:\Windows\SMINST\BLService.exe
PID: 2300 Status: -

Path: C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PID: 2308 Status: -

Path: C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PID: 2352 Status: -

Path: C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PID: 2380 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 2448 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 2492 Status: -

Path: C:\Windows\System32\SearchIndexer.exe
PID: 2524 Status: -

Path: C:\Windows\System32\drivers\XAudio.exe
PID: 2572 Status: -

Path: C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
PID: 2772 Status: -

Path: C:\Windows\System32\wbem\unsecapp.exe
PID: 2780 Status: -

Path: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 3004 Status: -

Path: C:\Program Files\Windows Defender\MSASCui.exe
PID: 3052 Status: -

Path: C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
PID: 3092 Status: -

Path: C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
PID: 3148 Status: -

Path: C:\Windows\System32\wbem\WmiPrvSE.exe
PID: 3200 Status: -

Path: C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
PID: 3240 Status: -

Path: C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PID: 3420 Status: -

Path: C:\Program Files\TELUS\TELUS security advisor\Tsa.exe
PID: 3464 Status: -

Path: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PID: 3488 Status: -

Path: C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PID: 3524 Status: -

Path: C:\Program Files\Java\jre6\bin\jusched.exe
PID: 3588 Status: -

Path: C:\Program Files\Zune\ZuneLauncher.exe
PID: 3636 Status: -

Path: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PID: 3844 Status: -

Path: C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PID: 3852 Status: -

Path: C:\Program Files\Windows Media Player\wmpnscfg.exe
PID: 3888 Status: -

Path: C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PID: 4012 Status: -

Path: C:\Program Files\HP\QuickPlay\QPService.exe
PID: 4016 Status: -

Path: C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
PID: 4200 Status: -

Path: C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
PID: 4220 Status: -

Path: C:\Program Files\Windows Media Player\wmpnetwk.exe
PID: 4324 Status: -

Path: C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe
PID: 4344 Status: -

Path: C:\Program Files\Mozilla Firefox\firefox.exe
PID: 4444 Status: -

Path: C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
PID: 4984 Status: -

Path: C:\Program Files\Windows Sidebar\sidebar.exe
PID: 5076 Status: -

Path: C:\Program Files\TELUS\TELUS security services\Kav\Bin\ScanningProcess.exe
PID: 5148 Status: -

Path: C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PID: 6132 Status: -

Path: C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
PID: 6424 Status: -

Path: C:\Windows\System32\svchost.exe
PID: 6796 Status: -

Path: C:\Windows\System32\SearchProtocolHost.exe
PID: 7296 Status: -

Path: C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
PID: 8012 Status: -

Path: C:\Users\Kitten\AppData\Local\Temp\Temp1_RootRepeal.zip\RootRepeal.exe
PID: 8936 Status: -

Path: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PID: 9300 Status: -

Path: C:\Windows\System32\wbem\WmiPrvSE.exe
PID: 9876 Status: -

Path: C:\Windows\System32\SearchFilterHost.exe
PID: 10128 Status: -



MBAM:


Malwarebytes' Anti-Malware 1.39
Database version: 2492
Windows 6.0.6001 Service Pack 1

23/07/2009 10:40:28 PM
mbam-log-2009-07-23 (22-40-28).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 253778
Time elapsed: 3 hour(s), 14 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




OTL:

Otl.txt:
OTL logfile created on: 23/07/2009 7:31:14 PM - Run 1
OTL by OldTimer - Version 3.0.10.2 Folder = C:\Users\Kitten\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.17% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 176.49 Gb Total Space | 127.35 Gb Free Space | 72.16% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 1.45 Gb Free Space | 14.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KITTEN-LAPTOP
Current User Name: Kitten
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2008/07/12 09:31:00 | 00,196,608 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe
PRC - [2007/07/20 01:40:48 | 00,137,752 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/10/09 14:19:40 | 00,359,664 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\Fws.exe
PRC - [2008/10/28 23:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008/10/09 14:20:26 | 00,626,928 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\rps.exe
PRC - [2009/07/06 22:43:25 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/01/27 22:37:24 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2008/04/28 08:23:28 | 00,414,984 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
PRC - [2008/04/25 16:15:26 | 00,361,808 | ---- | M] () -- C:\Windows\SMINST\BLService.exe
PRC - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2007/01/09 02:25:00 | 00,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2007/10/17 16:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe
PRC - [2008/04/28 08:23:36 | 00,738,568 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
PRC - [2008/01/20 19:23:52 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2008/04/17 11:05:10 | 01,049,896 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008/01/20 19:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/08/01 17:14:02 | 00,202,032 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
PRC - [2008/06/02 00:55:22 | 00,080,896 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
PRC - [2009/03/02 19:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2008/04/15 14:51:00 | 00,488,752 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
PRC - [2008/09/18 12:11:22 | 03,228,912 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security advisor\Tsa.exe
PRC - [2009/07/06 22:43:26 | 00,520,024 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2007/07/25 17:02:54 | 00,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/12/12 12:41:06 | 00,157,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneLauncher.exe
PRC - [2009/03/10 20:19:56 | 00,468,264 | ---- | M] (CyberLink Corp.) -- C:\Program Files\HP\QuickPlay\QPService.exe
PRC - [2008/05/01 17:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
PRC - [2008/01/20 19:23:29 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2007/08/30 11:50:42 | 00,205,480 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2008/01/20 19:25:33 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2009/01/29 23:32:29 | 00,091,440 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PRC - [2008/04/03 12:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
PRC - [2007/09/26 07:34:40 | 00,316,720 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
PRC - [2008/01/20 19:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008/10/09 14:20:28 | 00,096,496 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe
PRC - [2008/04/11 10:04:54 | 00,685,360 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
PRC - [2008/01/20 19:23:29 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2008/07/04 12:45:06 | 00,139,264 | ---- | M] (Kaspersky Lab.) -- C:\Program Files\TELUS\TELUS security services\Kav\Bin\ScanningProcess.exe
PRC - [2008/04/17 11:05:20 | 00,103,720 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PRC - [2007/07/25 17:02:32 | 00,403,728 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2008/10/09 07:56:48 | 00,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
PRC - [2008/06/19 18:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
PRC - [2009/07/06 22:43:32 | 02,353,480 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2009/07/22 09:06:17 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/13 13:36:16 | 01,287,440 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2009/07/23 19:26:44 | 00,469,504 | ---- | M] ( ) -- C:\Users\Kitten\AppData\Local\Temp\Temp1_RootRepeal.zip\RootRepeal.exe
PRC - [2009/03/02 19:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/07/23 19:31:08 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/27 11:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/04/03 12:33:26 | 00,193,840 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe -- (Com4QLBEx [On_Demand | Running])
SRV - [2008/01/20 19:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 05:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 05:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2008/01/20 19:23:49 | 01,013,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2008/06/19 18:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Running])
SRV - [2009/02/06 18:08:58 | 00,533,360 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc [On_Demand | Stopped])
SRV - [2007/12/04 17:41:34 | 00,181,784 | ---- | M] (WildTangent, Inc.) -- C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe -- (GameConsoleService [On_Demand | Stopped])
SRV - [2008/10/09 07:56:48 | 00,094,208 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service [Auto | Running])
SRV - [2008/05/01 17:25:56 | 00,165,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe -- (hpqwmiex [On_Demand | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 18:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/07/06 22:43:25 | 01,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2009/01/27 22:37:24 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2007/07/20 01:38:54 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer [Auto | Running])
SRV - [2007/07/20 01:40:48 | 00,137,752 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running])
SRV - [2007/07/20 01:42:30 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped])
SRV - [2008/06/19 18:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/12 09:31:00 | 00,196,608 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe -- (nvsvc [Auto | Running])
SRV - [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008/04/28 08:23:28 | 00,414,984 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe -- (PDAgent [Auto | Running])
SRV - [2008/04/28 08:23:36 | 00,738,568 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe -- (PDEngine [On_Demand | Running])
SRV - [2008/10/09 14:20:28 | 00,096,496 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe -- (Radialpoint Security Services [On_Demand | Running])
SRV - [2008/04/25 16:15:26 | 00,361,808 | ---- | M] () -- C:\Windows\SMINST\BLService.exe -- (Recovery Service for Windows [Auto | Running])
SRV - [2007/01/09 02:25:00 | 00,272,024 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - File not found -- -- (RoxLiveShare9 [Auto | Stopped])
SRV - [2008/10/09 14:19:40 | 00,359,664 | ---- | M] (TELUS) -- C:\Program Files\TELUS\TELUS security services\Fws.exe -- (RP_FWS [Auto | Running])
SRV - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running])
SRV - [2008/01/20 19:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/20 19:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running])
SRV - [2007/10/17 16:37:04 | 00,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\DRIVERS\xaudio.exe -- (XAudioService [Auto | Running])
SRV - [2008/12/12 12:41:18 | 05,117,568 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc [On_Demand | Stopped])
SRV - [2008/12/12 12:41:08 | 00,243,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...rio&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...rio&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...rio&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1
FF - prefs.js..extensions.enabledItems: {40520fe7-6336-4df2-bab1-1f1f8e11bf27}:0.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {2cb97724-d789-4f43-8888-a763cbb8df6f}:3.0.2564.27062
FF - prefs.js..extensions.enabledItems: {F645A8C9-E969-42D9-B3F3-F325537222FD}:1.1.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.12
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.7
FF - prefs.js..extensions.enabledItems: {d596c130-b00a-11db-abbd-0800200c9a66}:2.080708
FF - prefs.js..extensions.enabledItems: {BF32D2C8-9C75-404b-ACF4-880DB4679236}:1.1
FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.48
FF - prefs.js..extensions.enabledItems: {333b42b0-9c75-11db-b606-0800200c9a66}:2.090208
FF - prefs.js..extensions.enabledItems: [email protected]:2.95
FF - prefs.js..keyword.URL: "http://www.ask.com/w...01447&l=dis&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/05 16:25:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/22 20:01:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/22 09:06:25 | 00,000,000 | ---D | M]

[2009/06/08 15:43:33 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions
[2008/10/10 18:01:09 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/08 15:43:33 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Extensions\[email protected]
[2009/07/23 17:36:37 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions
[2009/07/07 09:19:31 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/03/18 23:30:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{2cb97724-d789-4f43-8888-a763cbb8df6f}
[2008/10/10 18:09:34 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{333b42b0-9c75-11db-b606-0800200c9a66}
[2008/12/01 09:32:51 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{40520fe7-6336-4df2-bab1-1f1f8e11bf27}
[2009/03/30 11:42:32 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2009/07/13 17:04:29 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/13 09:04:36 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2008/10/10 18:09:45 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{d596c130-b00a-11db-abbd-0800200c9a66}
[2009/07/13 17:04:01 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}
[2009/05/13 09:04:44 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\{F645A8C9-E969-42D9-B3F3-F325537222FD}
[2009/07/13 17:04:14 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]
[2009/03/14 21:24:39 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]
[2009/07/13 17:04:22 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions
[2009/07/13 17:04:26 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\chatzilla
[2009/07/13 17:04:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\Console2
[2009/07/13 17:04:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\downthemall
[2009/07/13 17:04:22 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\emusic
[2009/07/13 17:04:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\fullerscreen
[2009/07/13 17:04:26 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\sage
[2009/07/13 17:04:25 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\toolkit
[2009/07/13 17:04:21 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\global\extensions\webdeveloper
[2009/07/13 17:04:24 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\mozilla\Firefox\Profiles\w4lz4j3c.default\extensions\[email protected]\chrome\mozapps\extensions
[2009/07/23 17:36:37 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/07/22 09:06:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/14 11:20:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/15 21:15:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/07/22 09:06:16 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/22 09:06:16 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/07/22 09:06:19 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/19 12:33:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 12:33:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 12:33:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 12:33:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 12:33:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 12:33:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 12:33:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\TELUS\TELUS security services\pkR.dll (TELUS)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QlbCtrl.exe] File not found
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Tsa.exe] C:\Program Files\TELUS\TELUS security advisor\Tsa.exe (TELUS)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found
O4 - Startup: C:\Users\Kitten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/24 23:20:48 | 00,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\Windows\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 14 Days ==========

[2009/07/23 19:31:00 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe
[2009/07/23 19:26:53 | 00,000,014 | ---- | C] () -- C:\Windows\System32\settings.dat
[2009/07/23 19:26:05 | 00,462,508 | ---- | C] () -- C:\Users\Kitten\Desktop\RootRepeal.zip
[2009/07/23 19:17:58 | 00,000,000 | ---D | C] -- C:\Users\Kitten\AppData\Roaming\Malwarebytes
[2009/07/23 19:17:43 | 00,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/23 19:17:38 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/07/23 19:17:33 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/07/23 19:17:32 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/07/23 19:17:31 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/23 19:16:38 | 03,775,200 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Kitten\Desktop\mbam-setup.exe
[2009/07/14 14:17:27 | 00,000,246 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2009/07/14 14:05:59 | 00,000,766 | ---- | C] () -- C:\Windows\System\CRIcon.ico
[2009/07/13 09:49:30 | 00,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch

========== Files - Modified Within 14 Days ==========

[1 C:\Users\Kitten\Desktop\*.tmp files]
[2009/07/23 19:37:59 | 30,138,9344 | ---- | M] () -- C:\Windows\System32\drivers\fidbox.dat
[2009/07/23 19:37:39 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/07/23 19:37:39 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/07/23 19:31:08 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Kitten\Desktop\OTL.exe
[2009/07/23 19:28:40 | 00,000,014 | ---- | M] () -- C:\Windows\System32\settings.dat
[2009/07/23 19:26:17 | 00,462,508 | ---- | M] () -- C:\Users\Kitten\Desktop\RootRepeal.zip
[2009/07/23 19:17:43 | 00,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/23 19:17:00 | 03,775,200 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Kitten\Desktop\mbam-setup.exe
[2009/07/23 16:23:46 | 00,042,654 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009/07/23 16:23:46 | 00,042,654 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009/07/23 13:38:16 | 00,000,246 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2009/07/23 13:37:33 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/07/23 13:37:24 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/07/23 13:13:31 | 04,019,384 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx
[2009/07/23 13:12:09 | 02,087,093 | -H-- | M] () -- C:\Users\Kitten\AppData\Local\IconCache.db
[2009/07/20 22:43:31 | 00,000,472 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/07/19 19:55:29 | 00,018,944 | ---- | M] () -- C:\Users\Kitten\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/19 17:08:57 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/07/19 17:08:57 | 00,600,378 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/07/19 17:08:57 | 00,105,852 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/07/16 03:11:55 | 00,325,304 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 13:55:08 | 00,000,246 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/07/23 19:17:58 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming
[2008/10/28 14:04:42 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\CyberLink
[2009/07/16 11:37:30 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\gtk-2.0
[2009/07/23 17:05:52 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\LimeWire
[2006/11/02 05:37:34 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Media Center Programs
[2009/03/18 23:30:25 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Neopets Toolbar
[2009/01/14 17:38:03 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\OpenOffice.org
[2008/12/18 17:47:12 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\Roxio
[2009/01/05 15:50:28 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\TELUS
[2008/11/14 00:36:20 | 00,000,000 | ---D | M] -- C:\Users\Kitten\AppData\Roaming\WildTangent
[2009/07/20 22:43:31 | 00,000,472 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/23 13:37:33 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/07/23 13:13:10 | 00,032,586 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >


Extras.txt:


OTL Extras logfile created on: 23/07/2009 7:31:14 PM - Run 1
OTL by OldTimer - Version 3.0.10.2 Folder = C:\Users\Kitten\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18783)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.20 Gb Available Physical Memory | 60.17% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 176.49 Gb Total Space | 127.35 Gb Free Space | 72.16% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 1.45 Gb Free Space | 14.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KITTEN-LAPTOP
Current User Name: Kitten
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5F6120BC-3238-4E95-821C-74C215417330}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E7FD2062-6DDA-4E16-A14C-6894B8DFC2E4}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{035E6C05-5819-453E-B021-D405A000E6B9}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{057509AF-B2A3-4370-B773-8E7908C8AF0C}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{0E3508F8-00B5-4ECF-A32B-A2F2535E3BE0}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{1378A3D2-157A-46A2-8CE7-DCE7CC4062FF}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{3EC5547E-F450-4C7A-90C1-B84D97B9E6CF}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{78946C39-7433-4430-8B05-9EAF59BB895A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{83D84E26-4EDD-4C3D-B5C3-37AB286E5C7E}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{8CCEE29B-8F38-40CC-9808-FBC764CCFC63}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{902C1511-41EA-4F94-8EAA-2178A9826391}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{92F5A740-C6A2-4E1D-901F-4F9CADF08992}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{95039E0D-7034-494D-957D-286DA49A7218}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{A0F1928E-7339-4F6A-82E2-9BCB0ABAE115}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{B90E297B-AF2D-44A9-BEF8-65E48FF7F58C}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{C6E58109-6DA8-40CC-8C76-8A21CA658770}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{C8C404FA-74F4-47B3-B849-CA3DA33510EB}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{D9BF988D-14C4-41E8-9410-882DDAAF9EE0}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"TCP Query User{7E85BBC6-5E36-4E9B-995A-EB9BE94ACBD3}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{B77B0F61-0E19-4558-821B-A5404F1ADD87}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{212F5777-1190-4DEF-8E4D-6B2F313B45E7}" = PerfectDisk
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{30383EB1-E954-4CA3-B7DE-9C3A68B69D26}" = RPS Privacy Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3249C40F-A3BF-4ECC-9824-2F3EB9BFE6A1}" = RPS Ksdk
"{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{35CB5932-AE03-491E-9674-DF8E1F38D253}" = RPS Performance Tool
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{364EC092-93CF-4DDC-9D7A-7278452028E0}" = Logitech QuickCam
"{3686AE6A-D426-402A-9A49-973867C92BC4}" = RPS App Detector
"{380357CA-29F4-4B3C-B401-32C057E6B59B}" = HP Smart Web Printing
"{3838AF48-56E2-4E52-8482-D17CABF63441}" = RPS CRT
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4229B337-0C40-4181-9C41-CAC4C5952A7A}" = RPS Burn
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A9849CA-E11C-4F24-8BB1-97C717A1C898}" = LightScribe System Software
"{4C68AB1C-95CB-4699-BBDE-EC4FA2931E3A}" = RPS Security Cleanup
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{55DBDE34-2CAE-455C-A1CD-D91F5EE8E4E0}" = TELUS security services
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5D995085-1609-40D6-85CD-654C13430EE1}" = RPS ParentalControl
"{5DE9ADA1-B9F0-45C5-947F-12E667B01F69}" = RPS Diagnostic Utility
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{77E1B36B-2C8F-4D89-ABF0-F3FC85516AC5}" = RPS Ad Blocker
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{929A59BE-1E16-41EF-88CA-1006DE77D480}" = RPS AntiSpyware
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A296E88E-8459-4CF7-A7C8-AA65A04CAF75}" = RPS Zip
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B21DE8E2-03E6-4CFD-A94D-95CC42CD49C8}" = RPS Backup
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B640E7CC-7091-4A24-AE76-2140065D2054}" = HP User Guides 0110
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D0C5C43F-C534-4A35-AC67-98E64242A3FF}" = RPS AntiFraud
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E1374244-A8FE-4FDF-B823-184061FE16C5}" = RPS PopupBlocker
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{EED7DDDC-A01A-4A0D-884A-272C02E96903}" = RPS Firewall
"{F06D2782-4C7B-4778-901D-79D63E1B9BB9}" = RPS AntiVirus
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F31E534B-4199-4552-8154-5C130710D68E}" = HP Total Care Advisor
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FDDA11D6-00DE-4957-8761-F97145F438B7}" = RPS RpsCore
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"Action Replay Code Manager_is1" = Action Replay Code Manager
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LimeWire" = LimeWire 5.1.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.12)" = Mozilla Firefox (3.0.12)
"Neopets" = Neopets
"NVIDIA Drivers" = NVIDIA Drivers
"QcDrv" = Logitech® Camera Driver
"RadialpointClientGateway_is1" = TELUS security advisor 2.0.21
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WildTangent hp Master Uninstall" = My HP Games
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.4.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"Zune" = Zune

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 14/07/2009 5:02:13 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0
Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String
path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare
share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri
uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,
String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,
XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String
targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String
path) ValidateDocument failed SecurityStates.xml

Error - 14/07/2009 5:02:13 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0
Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String
path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare
share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri
uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,
String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,
XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String
targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String
path) ValidateDocument failed SecurityOffers.xml

Error - 14/07/2009 5:05:23 PM | Computer Name = Kitten-Laptop | Source = VSS | ID = 8194
Description =

Error - 14/07/2009 5:07:18 PM | Computer Name = Kitten-Laptop | Source = HP AdvisorUpdate | ID = 0
Description = Could not find a part of the path 'C:\_pack6\hp-advisor\src\HPAdvisor\Shared\Content\xsd\HPAdvisor.xsd'.
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String
path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare
share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri
uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri,
String role, Type ofObjectToReturn) at System.Xml.XmlReader.Create(String inputUri,
XmlReaderSettings settings, XmlParserContext inputContext) at System.Xml.Schema.XmlSchemaSet.Add(String
targetNamespace, String schemaUri) at HPAdvisor.Common.Content.CategoryCollection.ValidateDocument(String
path) ValidateDocument failed HPPrintersStates.xml

Error - 15/07/2009 2:25:02 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

Error - 16/07/2009 6:11:56 AM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

Error - 17/07/2009 12:06:06 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

Error - 17/07/2009 3:44:33 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

Error - 19/07/2009 7:10:14 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

Error - 19/07/2009 7:53:25 PM | Computer Name = Kitten-Laptop | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 15/03/2009 11:06:00 PM | Computer Name = Kitten-Laptop | Source = bowser | ID = 8003
Description =

Error - 16/03/2009 1:39:00 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016
Description =

Error - 16/03/2009 1:40:32 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000
Description =

Error - 16/03/2009 1:40:32 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009
Description =

Error - 16/03/2009 11:28:08 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016
Description =

Error - 16/03/2009 11:29:40 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000
Description =

Error - 16/03/2009 11:29:40 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009
Description =

Error - 17/03/2009 12:41:16 PM | Computer Name = Kitten-Laptop | Source = HTTP | ID = 15016
Description =

Error - 17/03/2009 12:42:48 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7000
Description =

Error - 17/03/2009 12:42:48 PM | Computer Name = Kitten-Laptop | Source = Service Control Manager | ID = 7009
Description =


< End of report >
  • 0

Advertisements


#2
CameraKitten

CameraKitten

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Bump
  • 0

#3
CameraKitten

CameraKitten

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
What kind of help site is this that doesn't help people when they do what the helpsite says to do? You can't even post something like "I dont know try this" or something? Delete my account, please. This is pathetic.
  • 0

#4
Octagonal

Octagonal

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,528 posts
While we try to help everyone as quickly as possible, our malware team is vastly outnumbered by people needing help. Some of our experts work from the older topics towards the newer ones and some take on newer topics rather than older ones. We encourage the former practice, but that's not always practical.

Some of the helpers are more comfortable with certain infections and seek them out...still other helpers will look for the tougher infections to take on. This may explain, at least partially, the seemingly random nature of how topics are selected. We DO try to get to everyone in a timely manner, but as you've seen, the Malware Forum presents a pretty formidable workload for the number of staff members we have.

Take a look at this topic which gives instructions when your topic is at least three days old and you haven't received help.

That topic is also pinned at the top of this forum.

If you still require help then follow those instructions, if not then this topic will be closed as you request.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP