Thanks for your help hammerman, I appreciate it a lot.
After the MalwareBytes scan, the system was running smooth, but the virus came back a few hours later.
Here are my RootRepeal, Malwarebytes, and OTLLogs logs below:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/30 04:37
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: 00000918
Image Path: 00000918
Address: 0xA9F3E000 Size: 71424 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA962D000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
ServiceTable Hooked [0x83cab8b8]!
Hidden Services
-------------------
Service Name: ikkplxessfxos
Image Path: C:\WINDOWS\system32\drivers\rpdjoctkj.sys
==EOF==
--------------------------------------------------------------------------------------------------
curslib.dll
str.sys
Malwarebytes' Anti-Malware 1.41
Database version: 3257
Windows 5.1.2600 Service Pack 2
11/29/2009 1:02:52 PM
mbam-log-2009-11-29 (13-02-52).txt
Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 349975
Time elapsed: 1 hour(s), 15 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 64
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\curslib.dll (Spyware.Passwords) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\homeview (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AVR (Rogue.AdvancedVirusRemover) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Plate (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\AAS\Lounge Lizard 3.0\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\Arturia\CS-80V\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\EA SPORTS\FIFA 09\rld-fi9k.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Program Files\Propellerhead\Recycle\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\Steinberg\VSTplugins\vstationuninstall\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\Trend Micro\HijackThis\backups\backup-20091123-213631-576-F4C5E.exe.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Waves\DiamondUninstall\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\Edirol\Super Quartet Log\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP444\A0147590.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP444\A0147591.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP444\A0147592.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP447\A0152608.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP447\A0153608.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP447\A0154608.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP447\A0156608.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP447\A0156615.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP449\A0165712.dll (Trojan.Fakeinit) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP450\A0166703.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP450\A0170731.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP450\A0172731.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0175731.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0176731.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0176738.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0177738.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0180740.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP451\A0180753.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP452\A0180875.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP452\A0180876.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{3713EE44-C8DB-4CC0-8FAA-B74FA3314EF7}\RP452\A0180909.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aqphgfjv.sur (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\giwovumo.dll_old (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\grpbytrr.vvw (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lylnxhth.tho (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rdolib.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\azgfctgw.fgk (Trojan.Fakeinit) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cpumonom.kup (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\curslib.dll (Spyware.Passwords) -> Delete on reboot.
C:\WINDOWS\system32\hhpfgqof.jiq (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\odcjnloe.dtx (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urvqoofr.akc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogon86.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wincert.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yxhhfdot.vfi (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kanelewu.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\FL3\FLREINSTALL\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\FL3\FLREINSTALL\FLREIN~1\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\FL3\FLStudio5\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\VST\Edirol\Super Quartet Log\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\VST\KORG Legacy DIGITAL\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\VST\ReValver\ReValver Live.exe (Malware.Packer) -> Quarantined and deleted successfully.
D:\VST\VstPlugins\Halion 3\Documentation\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\VST\VstPlugins\Nomad Factory RAL\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\VST\Waves\DIAMOND UNINSTALL\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
D:\Downloads\bpssr.exe (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
D:\Downloads\EvID4226Patch223d-en\EvID4226Patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
E:\transferred\Spectrasonics.Stylus.RMX.Keygen.H2O.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
E:\Vstplugins\KORG Legacy DIGITAL\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk (Rogue.AdvancedVirusRemover) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\9g2234wesdf3dfgjf23 (Worm.KoobFace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\flags.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uses32.dat (Malware.Trace) -> Quarantined and deleted successfully.
-------------------------------------------------------------------------------------------------------
OTL logfile created on: 11/30/2009 4:39:01 AM - Run 1
OTL by OldTimer - Version 3.1.11.3 Folder = D:\Downloads\NexDownloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 15.10 Gb Free Space | 21.81% Space Free | Partition Type: NTFS
Drive D: | 117.19 Gb Total Space | 1.44 Gb Free Space | 1.23% Space Free | Partition Type: NTFS
Drive E: | 115.69 Gb Total Space | 2.27 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
Drive F: | 2.10 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DAVE-07511676E2
Current User Name: Dave
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2009/11/30 04:35:47 | 00,536,064 | ---- | M] (OldTimer Tools) -- D:\Downloads\NexDownloads\OTL.exe
PRC - [2009/11/29 13:10:03 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/11/29 13:10:03 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/19 00:23:16 | 00,049,968 | ---- | M] (AOL LLC) -- C:\Program Files\AIM6\aim6.exe
PRC - [2009/02/03 23:41:54 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
PRC - [2008/12/20 12:26:09 | 07,678,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/11/06 12:33:00 | 00,041,264 | ---- | M] (AOL LLC) -- C:\Program Files\AIM6\aolsoftware.exe
PRC - [2008/11/02 03:38:58 | 00,167,936 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2008/09/05 23:29:58 | 00,917,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WgaTray.exe
PRC - [2008/07/23 16:04:20 | 05,625,344 | ---- | M] () -- C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
PRC - [2007/10/24 13:37:26 | 00,245,760 | ---- | M] (Avid Technology, Inc.) -- C:\WINDOWS\system32\mafwTray.exe
PRC - [2007/06/29 17:54:16 | 00,073,728 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
PRC - [2007/06/13 05:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/11/13 23:05:34 | 00,061,440 | ---- | M] (Digidesign, A Division of Avid Technology, Inc.) -- C:\Program Files\Digidesign\Drivers\MMERefresh.exe
PRC - [2006/07/10 15:49:34 | 01,093,632 | ---- | M] () -- C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
PRC - [2006/04/07 15:02:24 | 01,343,488 | ---- | M] (AWS Convergence Technologies, Inc.) -- C:\Program Files\AWS\WeatherBug\Weather.exe
PRC - [2005/12/18 14:18:56 | 00,307,200 | ---- | M] (Team H2O) -- C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
PRC - [2005/10/18 15:00:10 | 00,241,152 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe
========== Modules (SafeList) ========== MOD - [2009/11/30 04:35:47 | 00,536,064 | ---- | M] (OldTimer Tools) -- D:\Downloads\NexDownloads\OTL.exe
MOD - [2006/08/25 10:45:55 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2009/11/29 13:10:03 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/09/23 21:59:24 | 01,695,368 | ---- | M] (NanJing Nagasoft Co, LTD.) -- C:\WINDOWS\system32\Nagasoft\vjocx.dll -- (vvdsvc)
SRV - [2009/07/20 10:51:52 | 00,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009/05/17 21:04:00 | 00,098,488 | ---- | M] (SiSoftware) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2009/02/03 23:41:54 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller)
SRV - [2009/02/03 20:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart)
SRV - [2007/06/29 17:54:16 | 00,073,728 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
SRV - [2007/01/04 16:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/11/13 23:05:34 | 00,061,440 | ---- | M] (Digidesign, A Division of Avid Technology, Inc.) -- C:\Program Files\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2006/11/13 20:59:52 | 00,122,880 | ---- | M] (Digidesign, A Division of Avid Technology, Inc.) -- C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe -- (digiSPTIService)
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/10/18 15:00:10 | 00,241,152 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Pro Football Reference"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2009/09/30 14:34:38 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2009/09/30 14:34:41 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/30 14:34:38 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/11/10 00:55:16 | 00,000,000 | ---D | M]
[2009/11/29 16:31:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions
[2009/01/17 04:19:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/29 09:48:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/11/20 12:20:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/03/20 01:51:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/01/27 04:08:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2009/11/30 04:26:28 | 00,001,087 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\baseball-referencecom.xml
[2009/01/28 23:40:59 | 00,006,280 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\btjunkie.xml
[2009/02/11 16:47:15 | 00,001,591 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\dictionary.xml
[2009/11/30 04:26:28 | 00,001,973 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\mycroft-project.xml
[2009/11/30 04:26:28 | 00,002,721 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\pro-football-reference.xml
[2009/01/28 23:38:26 | 00,001,032 | ---- | M] () -- C:\Documents and Settings\Dave\Application Data\Mozilla\Firefox\Profiles\6jufizyb.default\searchplugins\wikipedia-eng.xml
[2009/11/29 16:31:47 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/12/01 03:16:20 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/04 14:47:59 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2008/12/20 12:26:14 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\
[email protected][2008/12/20 12:26:14 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\
[email protected][2008/12/20 12:26:05 | 00,067,688 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jar50.dll
[2008/12/20 12:26:06 | 00,054,368 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2008/12/20 12:26:06 | 00,034,944 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\myspell.dll
[2008/12/20 12:26:07 | 00,046,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2008/12/20 12:26:07 | 00,172,136 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: (750 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 virustotal.com
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan.com
O1 - Hosts: 127.0.0.1 www.virscan.com
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1
http://virscan.comO1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1
http://virusscan.jotti.org/O1 - Hosts: 127.0.0.1 virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 scanner.novirusthanks.org/
O1 - Hosts: 127.0.0.1
http://scanner.novirusthanks.org/O1 - Hosts: 127.0.0.1 www.scanner.novirusthanks.org/
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe (Digidesign, A Division of Avid Technology, Inc.)
O4 - HKLM..\Run: [H2O] C:\Program Files\Syncrosoft\POS\H2O\cledx.exe (Team H2O)
O4 - HKLM..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\mafwTray.exe (Avid Technology, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\Dave\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/27 22:52:59 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/06/28 21:22:26 | 00,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/11/29 23:02:38 | 00,000,000 | ---D | M] - E:\autorunbackups -- [ NTFS ]
O32 - AutoRun File - [2007/05/01 11:23:41 | 00,000,148 | R--- | M] () - F:\AUTORUN.inf -- [ UDF ]
O32 - AutoRun File - [2007/07/03 21:32:31 | 00,000,000 | R--D | M] - F:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2007/07/03 21:32:31 | 00,634,880 | R--- | M] (Electronic Arts Inc.) - F:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2007/07/03 21:23:42 | 00,585,728 | R--- | M] (Electronic Arts Inc.) - F:\AutoRunGUI.dll -- [ UDF ]
O33 - MountPoints2\{53a31d51-1015-11de-b037-00173165702c}\Shell\AutoRun\command - "" = podcastready.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/11/27 22:52:39 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (58831718991265792)
========== Files/Folders - Created Within 14 Days ========== [2009/11/29 20:15:49 | 00,000,000 | -H-D | C] -- C:\VJVod_Cache
[2009/11/29 15:24:06 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Nagasoft
[2009/11/29 13:10:00 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/11/29 10:44:54 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/11/29 10:44:53 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/11/29 10:44:52 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/11/29 10:30:39 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/11/29 10:27:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/11/29 10:27:30 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/11/28 22:53:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dave\Desktop\Vinyl Room
[2009/11/25 13:08:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dave\Application Data\Malwarebytes
[2009/11/25 13:08:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/11/24 00:13:05 | 00,000,000 | ---D | C] -- C:\Program Files\MagicISO
[2009/11/23 05:42:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dave\My Documents\MelodynePlugin
[2009/11/23 05:28:04 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Celemony
[2009/11/20 16:39:41 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/11/20 16:39:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/11/20 16:37:30 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\Documents and Settings\Dave\*.tmp files -> C:\Documents and Settings\Dave\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2009/11/30 04:37:23 | 00,521,942 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/11/30 04:37:23 | 00,441,454 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/11/30 04:37:23 | 00,071,264 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/11/30 04:33:47 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009/11/30 04:33:23 | 00,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/11/30 04:33:07 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/30 04:33:05 | 00,121,808 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2009/11/30 04:33:05 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/30 04:28:30 | 10,485,760 | ---- | M] () -- C:\Documents and Settings\Dave\ntuser.dat
[2009/11/30 04:28:30 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Dave\ntuser.ini
[2009/11/29 22:04:17 | 00,000,471 | ---- | M] () -- C:\WINDOWS\System32\Datei4
[2009/11/29 22:04:17 | 00,000,471 | ---- | M] () -- C:\WINDOWS\System32\Datei2
[2009/11/29 22:04:17 | 00,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei3
[2009/11/29 22:04:17 | 00,000,470 | ---- | M] () -- C:\WINDOWS\System32\Datei1
[2009/11/29 22:04:17 | 00,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei7
[2009/11/29 22:04:17 | 00,000,469 | ---- | M] () -- C:\WINDOWS\System32\Datei5
[2009/11/29 22:04:17 | 00,000,468 | ---- | M] () -- C:\WINDOWS\System32\Datei0
[2009/11/29 22:04:17 | 00,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei9
[2009/11/29 22:04:17 | 00,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei8
[2009/11/29 22:04:17 | 00,000,467 | ---- | M] () -- C:\WINDOWS\System32\Datei10
[2009/11/29 22:04:17 | 00,000,465 | ---- | M] () -- C:\WINDOWS\System32\Datei6
[2009/11/29 13:05:11 | 00,237,600 | ---- | M] () -- C:\WINDOWS\System32\drivers\str.sys
[2009/11/29 10:44:56 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/29 10:27:46 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\Dave\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/11/29 10:27:30 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\NTREGOPT.lnk
[2009/11/29 10:27:30 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\ERUNT.lnk
[2009/11/29 06:30:36 | 03,707,952 | -H-- | M] () -- C:\Documents and Settings\Dave\Local Settings\Application Data\IconCache.db
[2009/11/29 02:38:55 | 00,002,193 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/11/29 00:39:04 | 00,165,376 | ---- | M] () -- C:\Documents and Settings\Dave\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/26 22:11:31 | 04,927,808 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\01 WhateverUWantDirty.mp3
[2009/11/25 22:03:14 | 00,000,095 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2009/11/25 15:21:39 | 00,085,504 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Inherit.exe
[2009/11/25 03:00:50 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/11/24 01:41:19 | 19,325,5424 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\bootXP.iso
[2009/11/24 00:44:53 | 00,001,486 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\MagicISO.lnk
[2009/11/23 21:58:55 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\6334.exe
[2009/11/23 21:38:55 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\18467.exe
[2009/11/23 05:41:05 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/20 16:37:31 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\HijackThis.lnk
[2009/11/20 01:19:00 | 02,699,125 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Young Swift - Trouble.mp3
[2009/11/19 16:22:42 | 04,599,351 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Ester_Dean_ft_Chris_Brown-Drop_it_Low-(Al_Sween_Remix)(Clean).mp3
[2009/11/19 16:13:29 | 00,006,278 | -HS- | M] () -- C:\WINDOWS\E88D4.exe
[2009/11/19 01:11:20 | 01,408,104 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\scratch2.mp3
[2009/11/18 23:27:17 | 95,233,254 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\dnb.mp3
[2009/11/18 20:41:35 | 00,625,058 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\scratch.mp3
[2009/11/17 21:39:36 | 07,165,910 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\182Reup.mp3
[2009/11/17 20:29:24 | 00,000,219 | ---- | M] () -- C:\WINDOWS\System32\lsprst7.tgz
[2009/11/17 20:29:24 | 00,000,205 | ---- | M] () -- C:\WINDOWS\System32\lsprst7.dll
[2009/11/17 20:29:24 | 00,000,087 | ---- | M] () -- C:\WINDOWS\System32\ssprs.tgz
[2009/11/17 20:29:24 | 00,000,073 | ---- | M] () -- C:\WINDOWS\System32\ssprs.dll
[2009/11/17 18:48:46 | 02,866,650 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Charlie_bit_me_Auto-Tuned.flv
[2009/11/17 17:57:48 | 00,000,799 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/11/17 17:42:26 | 03,931,034 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Yup-2.mp3
[2009/11/17 00:37:58 | 02,154,917 | ---- | M] () -- C:\Documents and Settings\Dave\Desktop\Yup.mp3
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\Documents and Settings\Dave\*.tmp files -> C:\Documents and Settings\Dave\*.tmp -> ]
========== Files Created - No Company Name ========== [2009/11/29 13:05:09 | 00,237,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\str.sys
[2009/11/29 10:44:56 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/29 10:27:46 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\Dave\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/11/29 10:27:30 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\NTREGOPT.lnk
[2009/11/29 10:27:30 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\ERUNT.lnk
[2009/11/27 00:35:49 | 04,927,808 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\01 WhateverUWantDirty.mp3
[2009/11/25 15:21:46 | 00,085,504 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Inherit.exe
[2009/11/24 01:41:15 | 19,325,5424 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\bootXP.iso
[2009/11/24 00:13:05 | 00,001,486 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\MagicISO.lnk
[2009/11/23 21:58:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\6334.exe
[2009/11/23 21:38:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\18467.exe
[2009/11/20 16:37:31 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\HijackThis.lnk
[2009/11/20 03:18:00 | 02,699,125 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Young Swift - Trouble.mp3
[2009/11/19 16:27:32 | 04,599,351 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Ester_Dean_ft_Chris_Brown-Drop_it_Low-(Al_Sween_Remix)(Clean).mp3
[2009/11/19 01:11:16 | 01,408,104 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\scratch2.mp3
[2009/11/18 23:24:59 | 95,233,254 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\dnb.mp3
[2009/11/18 20:41:33 | 00,625,058 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\scratch.mp3
[2009/11/18 02:00:28 | 00,006,278 | -HS- | C] () -- C:\WINDOWS\E88D4.exe
[2009/11/17 21:38:10 | 07,165,910 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\182Reup.mp3
[2009/11/17 18:48:27 | 02,866,650 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Charlie_bit_me_Auto-Tuned.flv
[2009/11/17 17:39:53 | 03,931,034 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Yup-2.mp3
[2009/11/16 17:57:41 | 02,154,917 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Yup.mp3
[2009/11/16 16:52:54 | 05,260,479 | ---- | C] () -- C:\Documents and Settings\Dave\Desktop\Sebastian - Wobbley (Al Sween Remix).mp3
[2009/10/15 03:36:43 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2009/09/30 14:35:00 | 00,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/09/05 20:09:27 | 00,870,128 | ---- | C] () -- C:\Documents and Settings\Dave\Application Data\mcs.rma
[2009/09/05 20:09:27 | 00,000,004 | ---- | C] () -- C:\Documents and Settings\Dave\Application Data\B07C9A
[2009/07/25 23:00:10 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\qtmlClient.dll
[2009/07/25 23:00:05 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\DigiPlatformSupport.dll
[2009/07/15 09:08:35 | 00,000,095 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/05/31 22:26:19 | 10,440,704 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\sandra.mda
[2009/05/18 19:24:13 | 00,625,152 | ---- | C] () -- C:\WINDOWS\System32\mp3tsshx.dll
[2009/04/21 23:19:06 | 00,172,173 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/04/14 17:44:36 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/01/11 04:11:53 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ArtFfct.dll
[2009/01/11 04:11:52 | 12,550,144 | ---- | C] () -- C:\WINDOWS\CS-80V(10 voices).dll
[2009/01/06 01:26:09 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/12/22 21:35:42 | 00,157,184 | ---- | C] () -- C:\WINDOWS\System32\xnrar.dll
[2008/12/21 05:16:49 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008/12/21 05:16:48 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/12/21 05:16:48 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/12/21 05:16:48 | 00,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/12/21 05:16:47 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/21 05:16:47 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/12/03 18:51:28 | 00,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/11/30 05:32:54 | 00,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2008/11/30 05:32:54 | 00,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2008/11/30 05:32:54 | 00,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2008/11/30 05:32:54 | 00,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2008/11/30 05:32:54 | 00,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2008/11/30 00:20:36 | 00,000,316 | ---- | C] () -- C:\WINDOWS\System32\Remover.ini
[2008/11/29 19:16:17 | 00,165,376 | ---- | C] () -- C:\Documents and Settings\Dave\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/28 13:47:20 | 00,000,127 | ---- | C] () -- C:\Documents and Settings\Dave\Local Settings\Application Data\fusioncache.dat
[2008/11/28 13:46:05 | 00,010,496 | ---- | C] () -- C:\WINDOWS\System32\ATKOSDMini.DLL
[2008/11/28 13:46:05 | 00,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2008/11/28 13:46:04 | 00,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2008/11/28 13:46:04 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2008/11/28 13:46:04 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2008/11/28 13:46:04 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2008/11/28 13:46:04 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2008/11/28 13:46:04 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2008/11/28 13:46:04 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2008/11/28 13:46:04 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2008/11/27 23:29:19 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2008/11/27 23:29:19 | 00,012,400 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2008/11/27 23:29:17 | 00,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2008/11/27 23:29:17 | 00,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2008/11/27 23:24:30 | 00,029,322 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2008/11/27 23:24:17 | 00,028,545 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/11/27 23:24:14 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/11/27 23:24:09 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/10/25 19:02:54 | 00,000,566 | ---- | C] () -- C:\WINDOWS\System32\SP207.ini
[2007/07/12 07:04:02 | 00,002,354 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
========== LOP Check ========== [2008/11/29 23:28:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2008/12/21 05:15:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NETGEAR
[2009/07/25 23:12:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2008/11/29 23:50:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/03/08 03:14:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2009/10/29 03:24:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/17 22:40:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/11/29 23:28:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\acccore
[2008/11/30 02:16:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Applied Acoustics Systems
[2009/10/08 21:39:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\com.imeem.DesktopUploader.6C3F108F466C0F04F30B58747CAA4DF34281133B.1
[2009/07/25 23:14:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Digidesign
[2009/01/23 01:01:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\DisplayTune
[2009/03/16 22:19:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\eMusic
[2009/06/02 22:21:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\FileZilla
[2008/12/16 17:03:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\GetRightToGo
[2009/01/14 20:19:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Leadertech
[2009/07/25 23:12:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\PACE Anti-Piracy
[2009/03/08 03:14:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Propellerhead Software
[2009/03/21 21:43:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\SanDisk
[2008/11/30 02:01:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Steinberg
[2009/11/29 01:43:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\uTorrent
[2008/12/05 21:29:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Viewpoint
[2008/11/30 02:12:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\Waves Audio
[2009/11/30 02:16:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dave\Application Data\WeatherBug
[2009/11/30 04:33:47 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\agp440.sys
< MD5 for: ATAPI.SYS >[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\atapi.sys
[2004/08/03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys
[2004/08/03 17:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
[2004/08/03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0027\DriverFiles\i386\atapi.sys
[2004/08/03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0028\DriverFiles\i386\atapi.sys
[2004/08/03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\eventlog.dll
[2006/02/28 06:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 06:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: IASTOR.SYS >[2008/02/21 16:10:19 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\NLDRV\003\iastor.sys
[2008/02/22 10:11:41 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\WINDOWS\NLDRV\005\iastor.sys
[2007/04/25 09:13:45 | 00,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\001\iastor.sys
< MD5 for: NETLOGON.DLL >[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 06:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 06:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >[2006/02/28 06:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 06:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\scecli.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 1306 bytes -> C:\Program Files\WindowsUpdate:YEjse8VqpGCY6zYAxc4ZM7xHIoMT
@Alternate Data Stream - 1223 bytes -> C:\Program Files\Common Files\Microsoft Shared:gkSoqRDQrpP9UnFCaMpXp5
@Alternate Data Stream - 1220 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:Ko07KgivPWGdvWqfeO7y0KwZm
@Alternate Data Stream - 1213 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:H6PpsVWEz4wVTsTGE9joXRRkfpA
@Alternate Data Stream - 1185 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:uEBHUxwBQBwhnwrsM
@Alternate Data Stream - 1160 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:PrNt97IWIqCWHYlE3Ir
@Alternate Data Stream - 1056 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:f9UsAUbJUZk99gjkDTYbNi37B
@Alternate Data Stream - 1048 bytes -> C:\Program Files\WindowsUpdate:WiVBGBaFbqOxTVa7u40a9pegukeE3
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C69EAC3C
< End of report >
______________________________________________________________________________
OTL Extras logfile created on: 11/30/2009 4:39:01 AM - Run 1
OTL by OldTimer - Version 3.1.11.3 Folder = D:\Downloads\NexDownloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 15.10 Gb Free Space | 21.81% Space Free | Partition Type: NTFS
Drive D: | 117.19 Gb Total Space | 1.44 Gb Free Space | 1.23% Space Free | Partition Type: NTFS
Drive E: | 115.69 Gb Total Space | 2.27 Gb Free Space | 1.96% Space Free | Partition Type: NTFS
Drive F: | 2.10 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DAVE-07511676E2
Current User Name: Dave
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\games\MLB05\mvp2005.exe" = D:\games\MLB05\mvp2005.exe:*:Enabled:mvp2005 -- ()
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"C:\Program Files\Steinberg\Cubase SX 3\Cubasesx3.exe" = C:\Program Files\Steinberg\Cubase SX 3\Cubasesx3.exe:*:Enabled:Cubase SX -- (Steinberg)
"D:\Program Files\TVAnts\Tvants.exe" = D:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts -- (Zhejiang University)
"C:\Program Files\EA SPORTS\Madden NFL 08\Updater.exe" = C:\Program Files\EA SPORTS\Madden NFL 08\Updater.exe:*:Enabled:Updater -- ()
"C:\Program Files\EA SPORTS\Madden NFL 08\mainapp.exe" = C:\Program Files\EA SPORTS\Madden NFL 08\mainapp.exe:*:Enabled:Madden NFL 08 -- (EA - Salt Lake)
"E:\New Folder\utorrent.exe" = E:\New Folder\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"E:\Program Files\SopCast\adv\SopAdver.exe" = E:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (www.sopcast.com)
"E:\Program Files\SopCast\SopCast.exe" = E:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (www.sopcast.com)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Documents and Settings\Dave\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Dave\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player -- (Octoshape ApS)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- File not found
"C:\Program Files\Steam\steamapps\jasonnigguardo\counter-strike source\hl2.exe" = C:\Program Files\Steam\steamapps\jasonnigguardo\counter-strike source\hl2.exe:*:Enabled:hl2 -- ()
"C:\Program Files\Steam\steamapps\jasonnigguardo\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\jasonnigguardo\counter-strike\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3c\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"D:\Program Files\StreamTorrent 1.0\StreamTorrent.exe" = D:\Program Files\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent P2P Media Player -- (StreamTorrent Team)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"E:\games\SF4\StreetFighterIV.exe" = E:\games\SF4\StreetFighterIV.exe:*:Enabled:STREET FIGHTER IV -- (CAPCOM U.S.A., INC.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{0863885D-E64B-9E5A-9747-03321A2D2A49}" = CCC Help Korean
"{0C40E716-2558-01E2-4797-484E4CCB2500}" = Catalyst Control Center Localization All
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{10FDD69C-2428-0FFB-12A2-2A6907D6282F}" = CCC Help Japanese
"{139DEC1F-D380-EB76-B0DF-88BC99B3B7BB}" = Catalyst Control Center Graphics Light
"{15733AD1-1CEF-459A-9245-0924FC63BDD5}" = HP My Display
"{20e0baa7-c13c-4930-a3ca-50a1d475e4ed}" = Nero 9 Essentials
"{2315B23D-3E21-4920-837D-AE6460934ECB}" = FIFA 09
"{2347E903-6299-A99F-C46C-05EB55912539}" = CCC Help Chinese Traditional
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17
"{2B3A996D-CCBF-3D62-B0AD-EA05553D3CEE}" = CCC Help Chinese Standard
"{2FEA102C-F535-4513-009B-57B165013C18}" = Tiger Woods PGA TOUR 08
"{300D2ECE-DA75-1623-871F-935A205FC450}" = CCC Help German
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = Ai Suite
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35AD8A37-8ECE-4E97-A34E-B15BFEF0E2F2}" = Basic Webcam
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{407FC95C-EB27-4CAF-9548-9E30ACFE5072}" = Movie Joiner v4
"{4BF8A8A5-B3EA-6073-0457-669CC1E929C8}" = CCC Help Hungarian
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{501C0FDB-DCA5-E211-956C-26ADC4C54B66}" = Catalyst Control Center Core Implementation
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F85CF9-B9EF-6C77-8095-A2CF95738099}" = CCC Help Danish
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{59ABBDF0-E1E5-48AF-85FB-F523A08C3490}" = STREET FIGHTER IV
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{63A17691-ABC0-E86F-5D7A-A2F7EE36145E}" = CCC Help Dutch
"{64B20B36-AEE7-4DD4-897C-C5DA5C218F60}" = Logitech Gaming Software 5.02
"{6501E9B8-77C7-7D81-7F1A-4C2D7E36B403}" = CCC Help Italian
"{71D4305B-56E6-4971-A799-FB7678A1D1AB}" = ASUS ATI Driver
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72A5824D-08E9-9A96-2104-19E4FE86E5FA}" = CCC Help Spanish
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7907CAB0-6C4F-C554-34EA-93EAC98B42F9}" = CCC Help Turkish
"{82982D26-D60E-27D8-361F-F14A8F6440E7}" = Catalyst Control Center HydraVision Full
"{82D48AB1-8E7F-4AA5-A5FA-47FA58A48110}" = Free Bomb Factory Plug-Ins 7.3
"{87934EAD-CE6F-16C6-6004-73E092AA15A6}" = Catalyst Control Center Graphics Previews Common
"{89B80F72-CCD0-95C3-21CB-89BA03D98155}" = CCC Help Finnish
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C49987B-689E-469D-86AE-8E325A038701}" = Melodyne plugin
"{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{906D95BA-4515-59A5-F2E4-072B1E73BB75}" = CCC Help English
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{950D9352-AAD8-49F1-AC10-C7FE64283C13}" = Mp3/Tag Studio 3.5 (beta 20)
"{9D8BE52A-2C9A-91F2-310E-560CCE4FD247}" = CCC Help Russian
"{A0D62771-4353-8D52-44B8-0FCFF07D5FF1}" = ccc-core-preinstall
"{A15B3CF2-7FB7-4102-BBC9-9680B7F0825F}" = InterLok Driver Kit
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3AE78AD-093F-57F1-280D-A31B0C1C1425}" = CCC Help Greek
"{A3BC1DBD-64D6-4EBC-0091-24C811662D40}" = Madden NFL 08
"{A41A9C99-0029-783E-40C3-3AA0D1A6535D}" = CCC Help Polish
"{A680CE58-7B2C-9A45-D05F-5AC22DFA2F76}" = CCC Help Portuguese
"{A7C292D9-0CAA-4FED-AEA9-77724F61B52C}" = Melodyne plugin
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A97B911E-8B1F-3B0F-F3D1-63B04084CC0F}" = Skins
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AD3AE2EE-E0DB-7818-3F05-7E8B2FB22C49}" = CCC Help Norwegian
"{AFE354A5-640F-4A23-94C8-0B441E8967CA}" = Digidesign Shared Plug-Ins 7.3
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B414174C-97E4-9E8B-018E-AC77055D0107}" = CCC Help Thai
"{B6D0AACC-1F01-A901-5348-FF3599EFE70D}" = CCC Help French
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B98604A2-5229-CBE6-98A4-A6D7C63B7458}" = ccc-utility
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1" = SiSoftware Sandra Lite 2009.SP3c
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBD1A47D-691E-56C2-AC6A-1B3F80E3EC14}" = CCC Help Swedish
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D34313F7-B5E2-D3AF-FBB1-EF3ED1DEF5AB}" = CCC Help Czech
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{D9CF5E60-42B1-489B-A0E2-9A6EE3DEB969}" = Firewire Family
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{E3A6437F-DE5B-6F3E-7BB3-39185D0BBDCE}" = ccc-core-static
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB1446FB-A3EF-D04D-C224-EEC74F11805F}" = Catalyst Control Center Graphics Full New
"{EC6C29B8-DEB6-47F7-AD1D-DEAE109A5801}" = Digidesign Pro Tools M-Powered 7.3.1cs4
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F354FE7E-783D-6880-F7DB-C61197C799E3}" = imeem Uploader
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{FE931AAE-B6D9-8A02-60C7-EF4862306F58}" = Catalyst Control Center Graphics Full Existing
"7-Zip" = 7-Zip 4.65
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2008
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"All ATI Software" = ATI - Software Uninstall Utility
"Antares Auto-Tune v4.39" = Antares Auto-Tune v4.39
"Applied Acoustics Lounge Lizard EP VSTi DXi v3.0" = Applied Acoustics Lounge Lizard EP VSTi DXi v3.0
"Arturia CS-80V v1.5" = Arturia CS-80V v1.5
"ASIO4ALL" = ASIO4ALL
"ATI Display Driver" = ATI Display Driver
"Autobahn" = MLB.TV NexDef Plug-in
"Basement Arts Reflex v1.03 VSTi" = Basement Arts Reflex v1.03 VSTi
"Cleanse Uninstaller Pro 2008 " = Cleanse Uninstaller Pro 2008
"Collab" = Collab
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.imeem.DesktopUploader.6C3F108F466C0F04F30B58747CAA4DF34281133B.1" = imeem Uploader
"Edirol HQ Orchestral VSTi v1.03" = Edirol HQ Orchestral VSTi v1.03
"Edirol SuperQuartet v1.5" = Edirol SuperQuartet v1.5
"eMusic Download Manager" = eMusic Download Manager 4.1.1
"ERUNT_is1" = ERUNT 1.1j
"FileZilla Client" = FileZilla Client 3.2.2.1
"FL Studio 8" = FL Studio 8
"FL Studio_is1" = FL Studio v7.0
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007 Trial
"HS2_is1" = Steinberg Hypersonic 2
"IL Download Manager" = IL Download Manager
"InstallShield_{35AD8A37-8ECE-4E97-A34E-B15BFEF0E2F2}" = Basic Webcam
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.5.0 Full
"Korg Legacy Collection VSTi v1.0.02" = Korg Legacy Collection VSTi v1.0.02
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"Native Instruments B4 II" = Native Instruments B4 II
"Native Instruments Guitar Rig 3" = Native Instruments Guitar Rig 3
"Nero - Burning Rom!UninstallKey" = Nero 6 Demo
"Novation V-Station for Cubase SX3 VSTi v1.41" = Novation V-Station for Cubase SX3 VSTi v1.41
"PoiZone" = PoiZone
"PowerISO" = PowerISO
"RealPlayer 12.0" = RealPlayer
"Reason4_is1" = Reason 4.0
"ReCycle v2.1" = ReCycle v2.1
"SHOUTcastDSP" = SHOUTcast Source DSP 1.9.0 (remove only)
"SopCast" = SopCast 3.0.3
"Steam App 10" = Counter-Strike
"Steam App 240" = Counter-Strike: Source
"Steam App 440" = Team Fortress 2
"Steinberg Cubase SX 3" = Steinberg Cubase SX 3
"StreamTorrent 1.0" = Stream Torrent 1.0
"Synapse Junglist VSTi v3.2" = Synapse Junglist VSTi v3.2
"SyncroSoft Emu" = SyncroSoft Emu (Remove only)
"Syncrosoft's License Control" = Syncrosoft's License Control
"Toxic Biohazard" = Toxic Biohazard
"TVAnts 1.0" = TVAnts 1.0
"V CAST Music with Rhapsody" = V CAST Music with Rhapsody
"Veetle TV" = Veetle TV 0.9.15
"VexcastPlayer2.0" = VexcastPlayer2.0
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.2
"Waves Diamond Bundle v5.2" = Waves Diamond Bundle v5.2
"Waves SSL Collection v1.2" = Waves SSL Collection v1.2
"WeatherBug" = WeatherBug
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Sansa Updater" = Sansa Updater
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 7/25/2009 11:52:09 PM | Computer Name = DAVE-07511676E2 | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.5.4.2165, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/27/2009 2:52:53 AM | Computer Name = DAVE-07511676E2 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.8.20081.21709, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 11/30/2009 5:28:06 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 11/30/2009 5:28:06 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7034
Description = The Digidesign MME Refresh Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 11/30/2009 5:33:20 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058
Error - 11/30/2009 5:33:20 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7000
Description = The Nsynas32 service failed to start due to the following error: %%2
Error - 11/30/2009 5:33:20 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2
Error - 11/30/2009 5:33:30 AM | Computer Name = DAVE-07511676E2 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 11/30/2009 5:33:30 AM | Computer Name = DAVE-07511676E2 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 11/30/2009 5:33:42 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7028
Description = The ikkplxessfxos Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 11/30/2009 5:38:23 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7028
Description = The ikkplxessfxos Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 11/30/2009 5:39:01 AM | Computer Name = DAVE-07511676E2 | Source = Service Control Manager | ID = 7028
Description = The ikkplxessfxos Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
< End of report >