OTL Report
OTL logfile created on: 8/25/2009 10:46:03 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Houseplant\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 84.59% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.63 Gb Total Space | 50.61 Gb Free Space | 36.51% Space Free | Partition Type: NTFS
Drive D: | 10.42 Gb Total Space | 5.21 Gb Free Space | 50.01% Space Free | Partition Type: NTFS
Drive E: | 149.05 Gb Total Space | 137.86 Gb Free Space | 92.49% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOUSEPLANT-PC
Current User Name: Houseplant
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe
PRC - [2008/10/29 02:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2007/09/26 01:24:42 | 00,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/08/15 14:28:42 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2007/11/09 18:24:28 | 00,212,992 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\STacSV.exe
PRC - [2009/08/15 14:29:03 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/15 14:28:57 | 00,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/15 14:28:33 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/08/15 14:29:03 | 00,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2008/01/20 22:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/11/09 18:22:22 | 00,409,600 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/01/17 23:31:22 | 01,033,512 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/07/13 14:03:10 | 00,292,128 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/08/15 14:28:52 | 02,007,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2008/01/20 22:25:11 | 00,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
PRC - [2009/06/15 12:33:00 | 02,471,208 | ---- | M] (RayV) -- C:\Program Files\RayV\RayV\RayV.exe
PRC - [2008/01/20 22:25:11 | 00,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
PRC - [2009/03/02 22:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2008/01/20 22:25:33 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2009/07/16 13:20:16 | 25,604,904 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2009/08/19 10:17:18 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Users\Houseplant\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PRC - [2008/01/20 22:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008/01/20 22:23:52 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/07/16 13:20:16 | 00,077,360 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
PRC - [2009/07/17 17:24:29 | 00,288,048 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2009/07/14 06:59:24 | 00,168,960 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmplayer.exe
PRC - [2008/01/17 23:31:32 | 00,095,528 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PRC - [2009/07/30 07:26:38 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/15 13:07:18 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/07/28 18:32:22 | 00,830,960 | ---- | M] (Google Inc.) -- C:\Users\Houseplant\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2009/07/28 18:32:22 | 00,830,960 | ---- | M] (Google Inc.) -- C:\Users\Houseplant\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2009/07/28 18:32:22 | 00,830,960 | ---- | M] (Google Inc.) -- C:\Users\Houseplant\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2009/07/28 18:32:22 | 00,830,960 | ---- | M] (Google Inc.) -- C:\Users\Houseplant\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2009/08/25 10:42:03 | 00,472,064 | ---- | M] ( ) -- C:\Users\Houseplant\Desktop\RootRepeal.exe
PRC - [2009/08/25 10:44:56 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Houseplant\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/09/26 01:24:42 | 00,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio [Auto | Running])
SRV - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/08/15 14:28:33 | 00,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc [Auto | Running])
SRV - [2009/08/15 14:28:42 | 00,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/27 14:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/20 22:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2008/01/20 22:23:49 | 01,013,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2008/06/19 21:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 21:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/07/13 14:02:50 | 00,542,496 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2008/06/19 21:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 17:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007/11/09 18:24:28 | 00,212,992 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\STacSV.exe -- (STacSV [Auto | Running])
SRV - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
SRV - [2008/01/20 22:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2008/01/20 22:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.c...h...TB&M=P-172X FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...TB&M=P-172X FX
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.c...h...TB&M=P-172X FX
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.c...h...TB&M=P-172X FX
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.8.4
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/03/31 14:53:25 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/07/30 16:09:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/15 20:25:52 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/15 20:25:24 | 00,000,000 | ---D | M]
[2009/08/15 20:25:56 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Extensions
[2009/08/15 20:25:56 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/25 03:09:04 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Firefox\Profiles\3thtjvxr.default\extensions
[2009/08/20 15:43:29 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Firefox\Profiles\3thtjvxr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/08/15 20:30:08 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Firefox\Profiles\3thtjvxr.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/08/15 20:33:00 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mozilla\Firefox\Profiles\3thtjvxr.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/08/15 21:11:23 | 00,001,554 | ---- | M] () -- C:\Users\Houseplant\AppData\Roaming\Mozilla\FireFox\Profiles\3thtjvxr.default\searchplugins\wowhead.xml
[2009/08/25 10:34:31 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/15 20:25:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/19 17:24:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2008/07/17 11:24:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/06 12:36:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/26 14:35:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/07/30 07:26:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/30 07:26:54 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/11/21 17:45:04 | 01,332,224 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/11/21 17:45:26 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/07/30 07:26:55 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/10/14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/06/13 23:59:22 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/13 23:59:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/04/16 13:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/07/30 03:24:20 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/30 03:24:20 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/30 03:24:20 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/30 03:24:20 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/30 03:24:20 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/30 03:24:20 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/30 03:24:20 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Windows\System32\BAE.dll (Gateway Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Gateway\traybar.exe (Chicony)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] C:\Users\Houseplant\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe (RayV)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\launcher.exe (soft thinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane...C_2.3.9.113.cab (CDownloadCtrl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2004/04/30 20:01:00 | 00,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
NetSvcs: FastUserSwitchingCompatibility - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: Nla - Service key not found. File not found
NetSvcs: Ntmssvc - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: SRService - Service key not found. File not found
NetSvcs: Wmi - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: LogonHours - Service key not found. File not found
NetSvcs: PCAudit - Service key not found. File not found
NetSvcs: helpsvc - Service key not found. File not found
NetSvcs: uploadmgr - Service key not found. File not found
========== Files/Folders - Created Within 14 Days ==========
[2009/08/25 10:44:35 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Users\Houseplant\Desktop\OTL.exe
[2009/08/25 10:42:29 | 00,000,015 | ---- | C] () -- C:\Users\Houseplant\Desktop\settings.dat
[2009/08/25 10:41:48 | 00,472,064 | ---- | C] ( ) -- C:\Users\Houseplant\Desktop\RootRepeal.exe
[2009/08/25 06:47:37 | 01,638,129 | -H-- | C] () -- C:\Users\Houseplant\AppData\Local\IconCache.db
[2009/08/24 15:58:36 | 00,000,000 | ---D | C] -- C:\Users\Houseplant\AppData\Roaming\Malwarebytes
[2009/08/24 15:58:32 | 00,000,829 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/24 15:58:30 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/24 15:58:29 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/08/24 15:58:29 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/08/24 15:58:29 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/24 15:55:09 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Users\Houseplant\Desktop\HiJackThis.exe
[2009/08/20 00:31:12 | 00,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009/08/20 00:31:09 | 00,000,000 | ---D | C] -- C:\Users\Houseplant\AppData\Roaming\skypePM
[2009/08/19 17:37:01 | 00,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2009/08/19 17:27:23 | 00,000,000 | ---D | C] -- C:\Users\Houseplant\AppData\Roaming\Skype
[2009/08/19 17:23:49 | 00,002,377 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/08/19 17:23:48 | 00,000,000 | R--D | C] -- C:\Program Files\Skype
[2009/08/19 17:23:48 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009/08/19 17:23:41 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2009/08/19 15:11:29 | 66,221,2391 | ---- | C] () -- C:\Users\Houseplant\Desktop\4a8c4f6d_prem_142_ArmsageddonCom.wmv
[2009/08/19 10:18:00 | 00,002,078 | ---- | C] () -- C:\Users\Houseplant\Desktop\Google Chrome.lnk
[2009/08/19 10:17:26 | 00,000,928 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000UA.job
[2009/08/19 10:17:25 | 00,000,876 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000Core.job
[2009/08/17 03:38:09 | 00,001,681 | ---- | C] () -- C:\Users\Houseplant\Desktop\CCleaner.lnk
[2009/08/17 03:38:08 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/08/16 17:07:55 | 88,402,6733 | R--- | C] () -- C:\Users\Houseplant\Desktop\4a887230_prem_142_1Gforce4warcraftmovies.wmv
[2009/08/15 20:25:53 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/08/15 20:25:27 | 00,001,735 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
========== Files - Modified Within 14 Days ==========
[2009/08/25 10:44:56 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\Houseplant\Desktop\OTL.exe
[2009/08/25 10:43:14 | 00,000,015 | ---- | M] () -- C:\Users\Houseplant\Desktop\settings.dat
[2009/08/25 10:42:03 | 00,472,064 | ---- | M] ( ) -- C:\Users\Houseplant\Desktop\RootRepeal.exe
[2009/08/25 10:33:10 | 00,028,314 | ---- | M] () -- C:\Users\Houseplant\AppData\Roaming\nvModes.001
[2009/08/25 10:32:39 | 00,350,192 | -H-- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/08/25 10:32:39 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/08/25 10:32:38 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/25 10:32:38 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/25 10:32:31 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/08/25 08:54:39 | 00,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2009/08/25 08:25:31 | 40,145,219 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2009/08/25 08:25:31 | 00,068,371 | ---- | M] () -- C:\Windows\System32\drivers\Avg\microavi.avg
[2009/08/25 08:22:00 | 00,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000UA.job
[2009/08/25 06:47:37 | 01,638,129 | -H-- | M] () -- C:\Users\Houseplant\AppData\Local\IconCache.db
[2009/08/24 15:58:32 | 00,000,829 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/24 15:55:09 | 00,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Users\Houseplant\Desktop\HiJackThis.exe
[2009/08/24 04:16:56 | 00,164,864 | ---- | M] () -- C:\Users\Houseplant\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/20 00:38:13 | 00,002,377 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/08/20 00:31:12 | 00,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2009/08/19 15:26:11 | 66,221,2391 | ---- | M] () -- C:\Users\Houseplant\Desktop\4a8c4f6d_prem_142_ArmsageddonCom.wmv
[2009/08/19 10:22:00 | 00,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000Core.job
[2009/08/19 10:18:00 | 00,002,078 | ---- | M] () -- C:\Users\Houseplant\Desktop\Google Chrome.lnk
[2009/08/17 03:38:09 | 00,001,681 | ---- | M] () -- C:\Users\Houseplant\Desktop\CCleaner.lnk
[2009/08/16 17:07:55 | 88,402,6733 | R--- | M] () -- C:\Users\Houseplant\Desktop\4a887230_prem_142_1Gforce4warcraftmovies.wmv
[2009/08/15 20:25:53 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/08/15 20:25:27 | 00,001,735 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/08/15 14:29:03 | 00,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2009/08/15 14:29:03 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2009/08/15 14:29:03 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2009/08/11 18:45:08 | 00,420,864 | ---- | M] () -- C:\Users\Houseplant\Desktop\Mutilate.xls
========== LOP Check ==========
[2009/08/24 15:58:36 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming
[2009/04/09 14:36:51 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\acccore
[2008/10/19 18:21:33 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Acreon
[2009/01/27 11:13:17 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Amazon
[2009/01/11 12:26:59 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Crayon Physics Deluxe
[2009/07/20 21:05:46 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\FreeCap
[2009/07/21 17:22:56 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\IGN_DLM
[2006/11/02 08:37:34 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Media Center Programs
[2009/04/30 14:36:34 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\mIRC
[2008/06/26 04:43:35 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Nexon
[2009/06/30 12:30:15 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Notepad++
[2009/06/07 17:53:08 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Octoshape
[2009/08/24 15:53:16 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\RayV
[2008/06/25 06:52:39 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Roxio
[2009/06/23 10:43:02 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\SampleView
[2009/05/11 14:47:49 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Template
[2009/08/25 10:48:32 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\uTorrent
[2008/07/24 21:32:39 | 00,000,000 | ---D | M] -- C:\Users\Houseplant\AppData\Roaming\Ventrilo
[2009/08/19 10:22:00 | 00,000,876 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000Core.job
[2009/08/25 08:22:00 | 00,000,928 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3225652679-431899379-1894677068-1000UA.job
[2009/08/25 10:32:39 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/08/25 08:54:40 | 00,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32\eventlog.dll >
< %systemroot%\system32\scecli.dll >
[2008/01/20 22:24:50 | 00,177,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
[2006/11/02 05:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\cngaudit.dll
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
< End of report >
OTL Extras Report
OTL Extras logfile created on: 8/25/2009 10:46:03 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\Houseplant\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 84.59% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.63 Gb Total Space | 50.61 Gb Free Space | 36.51% Space Free | Partition Type: NTFS
Drive D: | 10.42 Gb Total Space | 5.21 Gb Free Space | 50.01% Space Free | Partition Type: NTFS
Drive E: | 149.05 Gb Total Space | 137.86 Gb Free Space | 92.49% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOUSEPLANT-PC
Current User Name: Houseplant
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E39B12E-28BC-409F-BD8B-DF4EF16AD6E8}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{14C666AF-D747-4BA5-9A51-A8F37B2D652B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1B3B3C5D-3224-42F4-B3BD-4E919F5012DC}" = lport=10244 | protocol=6 | dir=in | app=system |
"{2174D599-A203-4E51-96AA-C11854395BA0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2AA9AC02-4724-4E70-A8CC-3413AB9E280C}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{3DCC4F04-7C03-40CC-A578-EA7F144600E3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{587CC032-31E2-4693-B163-183E8D0506DE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F4EA3C9-C7C4-49A4-B1F2-8AFDCB32FF0A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7FA112E1-D0E3-414A-9BBC-022A45BC84E3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8911DB79-6180-453D-9821-5DDB356DA54E}" = lport=3390 | protocol=6 | dir=in | app=system |
"{8D5EE3DC-889B-4F6E-9AB1-395FE3134A3E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A470DB4C-6AEB-47C4-B4C0-D04A03967132}" = lport=10244 | protocol=6 | dir=in | app=system |
"{A5B4D1F6-1D0A-4CFA-BA14-791A19684CFA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ADC4872B-FCF6-444C-80A0-7D5A8ED3A09D}" = rport=10244 | protocol=6 | dir=out | app=system |
"{B25EB211-BD93-4E67-A7DC-EB61E3AE8525}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B9E94AE4-EF04-4DC5-BA0C-920FF19EB428}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BB547636-9D6F-4DD9-B815-EFAB61A17212}" = lport=3390 | protocol=6 | dir=in | app=system |
"{BE774799-DD65-4C7B-A17B-A2D7073FA663}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{C37954F6-B51F-40E8-A664-25817920C1F9}" = rport=10244 | protocol=6 | dir=out | app=system |
"{CCC3F720-68BA-4A1F-A71D-853BFEA59010}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EA625B10-66DB-4E5C-AF4F-074255A5B84F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F185044D-2030-4324-8647-D822B94D7A52}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F232F967-F6B1-41A0-BDF8-E12BA8DA3735}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F4EDADEB-4F8E-4D00-9D73-5532323D3F99}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00548300-0C1F-4D90-BDF4-CB60DC36C130}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.dll |
"{1E3126CA-EE63-40D6-B5F5-30D5CBA32DDA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{22225148-FD57-42E8-BC4F-1C9E8D626F3C}" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.dll |
"{279D3D52-42CD-4425-A78B-F0721238FA4D}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{27AA3F27-CC98-4485-B5FC-5A84C4463A59}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{2A4F0B6C-6BAB-46E7-936C-F0402422267A}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{34903FFD-F1CF-4FDE-B747-9FFEC11E8B0E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{34EC973C-7889-45CB-94AD-536E9B9BAE7C}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{3550E09B-BD9C-4DCD-8434-5383F639A120}" = protocol=6 | dir=in | app=c:\users\houseplant\appdata\roaming\rayv\viewer\rayv.dll |
"{3E047F19-C5C4-48AA-9106-43DDBFE439C9}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.dll |
"{4F4CCD6C-EE08-4782-B284-A92998637D1D}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{4F7D1F48-F9F0-4338-B257-98AEBC0DC60A}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{76148E03-F32E-44F2-89DE-E078756F7C52}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{7926DED8-C948-47F1-821C-CEA5A06A574B}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{8545CAFB-7CC1-4DA7-A595-F5970FDD022E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{8F77FE9D-64A7-4222-B299-D332D2A4C3E0}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{93C3FA06-127D-407E-A0DE-2A79D1750365}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{A196A043-F0C6-4DCD-8D00-7BD004509F0E}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{B114348E-F85A-452B-B5F2-6921E3128739}" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.dll |
"{B43545EB-9CBF-4A32-BF04-0240297549EC}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{B8900D1E-3F61-417F-8516-67CDFBE55965}" = protocol=17 | dir=in | app=c:\users\houseplant\appdata\roaming\rayv\viewer\rayv.dll |
"{BAABC9C7-0393-4E7E-A314-8B1CB10252B9}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{C504F826-B8C5-458A-8D4E-50E5D9A0F3FC}" = protocol=6 | dir=in | app=c:\users\houseplant\appdata\roaming\rayv\viewer\rayv.dll |
"{CC069923-0F65-454A-853A-C8B2BF94D6F3}" = protocol=17 | dir=in | app=c:\users\houseplant\appdata\roaming\rayv\viewer\rayv.dll |
"{CDE4B48F-0A60-4F10-A1F3-CC4BF5A28F30}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{D9FCB2EE-C058-43B9-A0DF-A17C214E57AA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DC5B4EF9-C9F9-452D-BFF7-E51E7A74950D}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{DD454377-4784-4DD7-998E-09EB47B2DDE1}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{E5068754-515E-4B42-868F-946198D997B6}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E7ED7C30-B5F5-4860-A696-023EE795ECF0}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{EACF5822-DC24-4A26-BDDA-6EE267EAB9A4}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{F0E30EB7-2252-4BC8-9979-27A2D09870D8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FB6A0900-BB4F-43F8-9F49-79ADE73828C0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FCF586EF-7378-4A86-97AE-8302408E0255}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5400
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{39098402-3F7A-4257-A4AE-FC1181D1B40B}" = Camera Assistant Software for Gateway
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E9E3EE81-6E7F-47A3-8D38-3470256704DB}_is1" = Tortun 0.8
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AIM_6" = AIM 6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner (remove only)
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Download Manager" = Download Manager 2.3.9
"Fraps" = Fraps (remove only)
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IrfanView" = IrfanView (remove only)
"LHTTSENG" = L&H TTS3000 British English
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"RayV" = RayV
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.1
"WinGimp-2.0_is1" = GIMP 2.6.6
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"ZoneAlarm" = ZoneAlarm
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Octoshape Streaming Services" = Octoshape Streaming Services
"uTorrent" = µTorrent
"Wow Web Stats Client v2.4" = Wow Web Stats Client v2.4
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/18/2009 6:37:46 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/19/2009 9:54:40 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/19/2009 6:24:29 PM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/20/2009 4:54:22 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/21/2009 9:37:21 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/21/2009 9:41:03 AM | Computer Name = Houseplant-PC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe_wuauserv, version 6.0.6001.18000,
time stamp 0x47918b89, faulting module wuaueng.dll, version 7.2.6001.788, time
stamp 0x48f7aa6b, exception code 0xc0000005, fault offset 0x000d2252, process id
0x3d8, application start time 0x01c9f27556c5ed73.
Error - 6/21/2009 9:42:59 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/22/2009 9:24:43 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/23/2009 10:17:31 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/24/2009 9:41:51 AM | Computer Name = Houseplant-PC | Source = WinMgmt | ID = 10
Description =
[ Media Center Events ]
Error - 7/17/2008 11:22:54 AM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 7/24/2008 1:48:04 PM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 8/3/2008 1:43:31 PM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 11/29/2008 1:32:10 PM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.WaitForUploadComplete failed. Please
try to ping www.msn.com prior to filing a bug.; Win32 GetLastError returned 10000109
Process: DefaultDomain Object Name: Media Center Guide
Error - 12/15/2008 3:12:25 PM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 12/20/2008 11:50:25 AM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 1/8/2009 1:41:32 AM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Error - 1/28/2009 2:31:18 PM | Computer Name = Houseplant-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 6/9/2009 2:06:07 PM | Computer Name = Houseplant-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Error - 7/20/2009 10:20:42 PM | Computer Name = Houseplant-PC | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
[ System Events ]
Error - 8/25/2009 4:52:31 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 8/25/2009 4:54:38 AM | Computer Name = Houseplant-PC | Source = HTTP | ID = 15016
Description =
Error - 8/25/2009 4:55:19 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/25/2009 4:55:19 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/25/2009 7:01:08 AM | Computer Name = Houseplant-PC | Source = HTTP | ID = 15016
Description =
Error - 8/25/2009 7:01:45 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/25/2009 7:01:45 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/25/2009 10:32:39 AM | Computer Name = Houseplant-PC | Source = HTTP | ID = 15016
Description =
Error - 8/25/2009 10:33:17 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/25/2009 10:33:17 AM | Computer Name = Houseplant-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >
MBAM Report
Malwarebytes' Anti-Malware 1.40
Database version: 2690
Windows 6.0.6001 Service Pack 1
8/25/2009 10:53:48 AM
mbam-log-2009-08-25 (10-53-48).txt
Scan type: Quick Scan
Objects scanned: 83494
Time elapsed: 2 minute(s), 32 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I also have the RootRepeal log, but the file is extremely long. If I need to post that I most definitely will.