1.) I am still not convinced that this is a malware issue (see my Reimage comments in my first post). However, I am willing to try almost anything to fix this issue at this point.
2.) OTL Text Log
OTL – Text
OTL logfile created on: 4/2/2010 1:56:21 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.83 Gb Total Space | 107.11 Gb Free Space | 74.47% Space Free | Partition Type: NTFS
Drive D: | 5.19 Gb Total Space | 1.17 Gb Free Space | 22.60% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-9K1AY6X2A2
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Administrator\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Glary Utilities\memdefrag.exe (Glarysoft Ltd)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\WebrootSecurity\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
PRC - C:\Program Files\reimage\Reimage PC Booster\reimageBooster.exe (reimage)
PRC - C:\Program Files\reimage\Reimage PC Booster\REI_Booster.exe (Reimage.com)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\davcdata.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Administrator\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\WINDOWS\ime\sptip.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ime\spgrmr.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Security Activity Dashboard Service) -- File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (WRConsumerService) -- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (Diskeeper) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (WebrootSpySweeperService) -- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (AGCoreService) -- C:\Program Files\AGI\core\4.0\AGCoreService.exe (AG Interactive)
SRV - (GoogleDesktopManager-090209-075101) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (SNMP) -- C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (W3SVC) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (WLSetupSvc) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (LVSrvLauncher) -- C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
========== Driver Services (SafeList) ========== DRV - (pwipf6) -- C:\WINDOWS\system32\drivers\pwipf6.sys (Privacyware/PWI, Inc.)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (DKRtWrt) -- C:\WINDOWS\system32\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV - (ssfmonm) -- C:\WINDOWS\system32\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssidrv) -- C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) -- C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) -- C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (PSI) -- C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (gmer) -- C:\WINDOWS\system32\drivers\gmer.sys (GMER)
DRV - (RTL8023xp) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Changer) -- C:\WINDOWS\system32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) -- C:\WINDOWS\system32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (LVMVDrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (LVcKap) -- C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam for Notebooks Pro(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (lvpopflt) -- C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (smbusp) Intel® -- C:\WINDOWS\system32\drivers\intelsmb.sys (Intel Corporation)
DRV - (drvmcdb) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (DUBE100B) -- C:\WINDOWS\system32\drivers\DUBE100B.sys (D-Link Corporation)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Ps2) -- C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AFS2K) -- C:\WINDOWS\system32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (EvcapMaui) -- C:\WINDOWS\system32\drivers\EvcapMau.sys (Emuzed, Inc.)
DRV - (Sunkfiltp) -- C:\WINDOWS\system32\drivers\sunkfiltp.sys (Alcor Micro Corp.)
DRV - (rtl8139) -- C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Sparrow) -- C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr=&q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl=en&ie=UTF-8&q=%s&btnG=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l=55&alpha=%s&S=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AddThis"
FF - prefs.js..browser.search.defaulturl: "http%3A//ixquick.com/do/toolbar%3Fcat%3Dweb%26language%3Denglish%26query%3D"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Dogpile"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.dogpile.com"FF - prefs.js..extensions.enabledItems:
[email protected]:1.11.7
FF - prefs.js..extensions.enabledItems: {9a94d785-2979-44e9-b331-9e09d0cc7cff}:1.300.306
FF - prefs.js..extensions.enabledItems:
[email protected]:4.0.3
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {4D1E692F-D179-413b-A987-EEEAAD85DDB3}:5.51.15.1
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0.12514
FF - prefs.js..extensions.enabledItems:
[email protected]:1.1
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.0.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.5.2
FF - prefs.js..extensions.enabledItems:
[email protected]:1.272
FF - prefs.js..extensions.enabledItems: {5FF97DB7-2EF7-4a7f-8E36-5214B5C5C65A}:3.6
FF - prefs.js..extensions.enabledItems: {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}:3.6
FF - prefs.js..keyword.URL: "
http://assist.infosp...t/main?domain="FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/03 16:45:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/02 01:52:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/02 01:52:54 | 000,000,000 | ---D | M]
[2008/06/17 21:20:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/04/02 01:53:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions
[2009/07/26 15:21:59 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/27 05:29:11 | 000,000,000 | ---D | M] (AddThis) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2009/03/18 02:24:29 | 000,000,000 | ---D | M] (MapQuest Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}
[2010/01/25 19:19:57 | 000,000,000 | ---D | M] (Aeon Big) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{5FF97DB7-2EF7-4a7f-8E36-5214B5C5C65A}
[2009/02/18 17:04:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}(2)
[2010/03/13 00:15:47 | 000,000,000 | ---D | M] (Ixquick Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{70F241F6-52AB-4D45-993E-C1C09920095B}(2)
[2009/07/03 22:24:21 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/02/18 16:58:30 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}(2)
[2010/01/25 19:21:06 | 000,000,000 | ---D | M] (Dogpile Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{9a94d785-2979-44e9-b331-9e09d0cc7cff}
[2007/02/22 22:34:36 | 000,000,000 | ---D | M] (StumbleUpon) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}(2)
[2009/02/18 17:04:46 | 000,000,000 | ---D | M] (PitchDark) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}(2)
[2009/02/18 16:59:50 | 000,000,000 | ---D | M] (Yoono) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}(2)
[2007/09/16 01:58:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{ded0fc70-7215-4802-afeb-b2982d3e7225}
[2007/09/16 01:58:13 | 000,000,000 | ---D | M] (SphereGnome) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{ded0fc70-7215-4802-afeb-b2982d3e7225}(2)
[2010/01/25 19:20:35 | 000,000,000 | ---D | M] (Aeon Clouds) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01}
[2008/09/06 00:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\2008-07-31
[2010/04/01 00:45:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\
[email protected][2007/02/22 22:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\foxmarks@kei(2).com
[2009/02/18 17:03:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\nasanightlaunch@example(2).com
[2010/03/25 16:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\
[email protected][2010/01/20 22:30:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\
[email protected][2010/03/31 23:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\
[email protected][2010/01/17 22:03:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\
[email protected][2007/09/13 19:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\extensions\{ded0fc70-7215-4802-afeb-b2982d3e7225}(2)\chrome(2)\mozapps\extensions
[2009/03/18 02:25:13 | 000,001,741 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\aol-search.xml
[2009/06/12 22:29:35 | 000,002,164 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\bing.xml
[2010/01/25 19:21:26 | 000,001,098 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\dogpile.xml
[2010/04/01 15:37:48 | 000,001,446 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\ixquick.xml
[2008/12/08 17:28:21 | 000,000,872 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\yahoo.gif
[2008/12/08 17:28:21 | 000,000,466 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\yahoo.src
[2008/12/08 17:28:20 | 000,001,767 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnd2hfhj.default\searchplugins\yahoo.xml
[2010/04/01 00:45:44 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/02 01:53:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\
[email protected][2007/09/16 01:49:27 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla(2).org
[2009/11/19 17:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2005/12/05 22:31:00 | 000,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2009/11/19 17:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2008/06/30 23:02:00 | 000,663,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009/06/16 20:43:49 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
O1 HOSTS File: ([2010/03/13 04:23:02 | 000,000,814 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - No CLSID value found.
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (DeskbarBHO) - {BFBB7543-916C-449a-9DC6-C9A516A6162F} - C:\Program Files\Ixquick Deskbar\deskbar.dll (Deskbar)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (MapQuest Toolbar) - {9302e698-7e00-43ab-b867-c6e759bc2ada} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll (MapQuest, Inc)
O3 - HKLM\..\Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (MapQuest Toolbar) - {9302E698-7E00-43AB-B867-C6E759BC2ADA} - C:\Program Files\MapQuest Toolbar\mapquesttb.dll (MapQuest, Inc)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Reimage PC Booster] C:\Program Files\Reimage\Reimage PC Booster\Postrebootexecuter.exe ()
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [Glary Memory Optimizer] C:\Program Files\Glary Utilities\memdefrag.exe (Glarysoft Ltd)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2009/11/17 20:29:05 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\3.1.5.7613\Launcher.exe (Webshots.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra Button: ReadNotify - {0050A87F-CF26-41AE-9C0A-C32307C941CB} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : ReadNotify - {0050A87F-CF26-41AE-9C0A-C32307C941CB} - Reg Error: Key error. File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} Reg Error: Value error. (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - Reg Error: Key error. File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\AutorunsDisabled - No CLSID value found
O20 - AppInit_DLLs: (c:\progra~1\google\google~2\goec62~1.dll) - c:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O30 - LSA: Authentication Packages - (OWS\S) - File not found
O30 - LSA: Security Packages - (rosoft Shared\Windows Live\ecur) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/15 20:31:51 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe -- [2002/09/10 21:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/05/21 20:39:24 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: LanmanServer - File not found
NetSvcs: LanmanWorkstation - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)
========== Files/Folders - Created Within 30 Days ========== [2010/04/02 00:27:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/28 02:22:26 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2010/03/19 19:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\3-19-10 Scan Logs
[2010/03/17 21:53:42 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/03/17 21:53:42 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010/03/16 00:05:15 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2010/03/16 00:01:50 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/03/16 00:01:18 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010/03/14 08:09:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/03/14 07:50:15 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities
[2010/03/14 07:33:02 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2010/03/14 03:09:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/13 05:54:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/03/13 04:28:59 | 000,108,880 | ---- | C] (Privacyware/PWI, Inc.) -- C:\WINDOWS\System32\drivers\pwipf6.sys
[2010/03/13 04:13:56 | 001,563,008 | ---- | C] (Webroot Software, Inc.) -- C:\WINDOWS\WRSetup.dll
[2010/03/13 00:21:12 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2010/03/11 20:07:42 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/03/07 06:58:17 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareGuard
[2010/03/07 06:50:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2010/03/07 06:50:42 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/03/07 06:41:28 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2010/03/03 17:12:57 | 000,203,776 | ---- | C] (Iterated Systems, Inc.) -- C:\WINDOWS\System32\clrviddc.dll
[2010/03/03 16:44:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2010/03/02 23:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/02/23 23:08:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/02/23 23:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/02/23 23:04:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/19 21:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/05 03:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2009/12/04 01:59:21 | 004,989,816 | ---- | C] (Webroot Software, Inc.) -- C:\Program Files\Common Files\wruninstall.exe
[2009/12/04 01:59:14 | 000,712,072 | ---- | C] (Ask.com) -- C:\Program Files\Common Files\GenericSB.dll
[2009/07/01 02:23:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/07/01 02:11:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/04 00:48:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/02/18 16:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\agi
[2009/02/18 16:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\agi
[2008/09/28 02:57:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Trend Micro
[2008/09/18 00:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Trend Micro
[2008/07/27 15:53:40 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/11/01 13:39:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2006/09/14 13:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
========== Files - Modified Within 30 Days ========== [2010/04/02 01:54:11 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/02 01:40:08 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/04/02 01:35:38 | 000,012,712 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/02 01:35:12 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/02 01:34:32 | 000,000,328 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/02 01:34:30 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/02 01:34:30 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1413038736-614172877-2008263415-500.job
[2010/04/02 01:34:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/02 01:34:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/02 01:32:57 | 014,680,064 | ---- | M] () -- C:\Documents and Settings\Administrator\ntuser.dat
[2010/04/02 01:32:57 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/04/02 00:50:18 | 007,001,202 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/04/02 00:29:34 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/02 00:20:45 | 000,001,615 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/01 23:00:10 | 000,001,746 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_LE9294F1191DE48CFA4B4FF790F3BF861.job
[2010/04/01 16:04:28 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1413038736-614172877-2008263415-500.job
[2010/03/29 17:00:04 | 000,001,742 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_L76ACFF3080CC4EF49735590A605EA80E.job
[2010/03/28 20:44:31 | 000,029,184 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\The Left just does not understand.doc
[2010/03/27 16:00:09 | 000,001,732 | ---- | M] () -- C:\WINDOWS\tasks\wrSpySweeper_L85ADAE8969AB41209763B0C6C57BE5D4.job
[2010/03/23 14:27:20 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Glary Utilities.lnk
[2010/03/21 20:41:35 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\ObamaCare Is HC Deform.doc
[2010/03/21 18:31:10 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Did you forget what the Left Wing SEIU union thugs did to Ken Gladney.doc
[2010/03/21 03:28:32 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\instruction at 0x7342611a referenced memory at 0x7342611a.doc
[2010/03/19 18:50:35 | 000,000,622 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2010/03/19 18:50:35 | 000,000,603 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2010/03/17 21:53:42 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/03/17 21:53:42 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2010/03/17 01:23:43 | 000,030,208 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\0x7342611a Error.doc
[2010/03/16 00:01:41 | 000,000,878 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/03/14 22:00:00 | 000,000,400 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2010/03/14 18:19:20 | 000,000,082 | ---- | M] () -- C:\WINDOWS\control.ini
[2010/03/14 08:44:48 | 000,000,661 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\SpywareGuard.lnk
[2010/03/14 03:59:51 | 000,000,638 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/03/14 03:53:01 | 000,466,052 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/14 03:53:01 | 000,084,656 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/13 04:23:02 | 000,000,814 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/03/13 04:07:24 | 000,108,880 | ---- | M] (Privacyware/PWI, Inc.) -- C:\WINDOWS\System32\drivers\pwipf6.sys
[2010/03/13 02:04:09 | 000,002,423 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Diskeeper 2010.lnk
[2010/03/10 20:59:07 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/03/10 20:09:14 | 000,343,899 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\MarchPrayers.pdf
[2010/03/08 18:16:32 | 000,177,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/08 06:40:10 | 000,000,498 | ---- | M] () -- C:\Documents and Settings\Administrator\Compress.res
[2010/03/05 19:35:46 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\MATHR Member Marketing Profile - BrianDomenoski.doc
[2010/03/05 07:19:43 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Short History of Marriage.doc
[2010/03/05 04:22:17 | 000,346,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecsext.dll
[2010/03/05 04:20:50 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\oleaccrc.dll
[2010/03/05 04:20:45 | 001,306,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml6(3).dll
[2010/03/05 04:20:45 | 001,306,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml6(2).dll
[2010/03/05 04:20:24 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mscms(2).dll
[2010/03/05 04:19:37 | 000,691,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcomm(2).dll
[2010/03/05 04:09:09 | 000,000,266 | ---- | M] () -- C:\WINDOWS\reimage.ini
[2010/03/05 04:06:07 | 004,657,152 | ---- | M] () -- C:\WINDOWS\debugpack.cmp
[2010/03/05 03:44:51 | 000,914,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet(6).dll
[2010/03/05 03:44:50 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\winhttp(8).dll
[2010/03/05 03:44:50 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\winhttp(7).dll
[2010/03/05 03:44:49 | 000,712,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecs.dll
[2010/03/05 03:44:48 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\_000002_.tmp.dll
[2010/03/05 03:44:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdigest(5).dll
[2010/03/05 03:44:45 | 001,206,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\urlmon(6).dll
[2010/03/05 03:44:44 | 000,117,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\t2embed(2).dll
[2010/03/05 03:44:43 | 008,461,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\shell32(5).dll
[2010/03/05 03:44:43 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\shsvcs(3).dll
[2010/03/05 03:44:39 | 001,499,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\shdocvw(3).dll
[2010/03/05 03:44:30 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\secur32(7).dll
[2010/03/05 03:44:22 | 000,399,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\rpcss(5).dll
[2010/03/05 03:44:21 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\rpcrt4(5).dll
[2010/03/05 03:44:20 | 001,435,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\query(3).dll
[2010/03/05 03:44:15 | 000,284,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\pdh(3).dll
[2010/03/05 03:44:13 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\netapi32(5).dll
[2010/03/05 03:44:12 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxclu(6).dll
[2010/03/05 03:43:52 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msctfime(5).ime
[2010/03/05 03:43:51 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msasn1(5).dll
[2010/03/05 03:43:30 | 000,726,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jscript(5).dll
[2010/03/05 03:43:30 | 000,726,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jscript(4).dll
[2010/03/05 03:43:30 | 000,299,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\kerberos(5).dll
[2010/03/05 03:43:25 | 000,246,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\es(3).dll
[2010/03/05 03:43:22 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\atl(5).dll
[2010/03/03 17:12:57 | 000,203,776 | ---- | M] (Iterated Systems, Inc.) -- C:\WINDOWS\System32\clrviddc.dll
[2010/03/03 16:45:32 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/03/03 16:44:45 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/03/03 16:44:45 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/03/03 16:42:55 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll
[2010/03/03 16:42:54 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll
[2010/03/03 16:42:54 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
========== Files Created - No Company Name ========== [2010/04/02 00:29:34 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/02 00:20:45 | 000,001,615 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/03/28 20:15:57 | 000,029,184 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\The Left just does not understand.doc
[2010/03/23 14:27:20 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Glary Utilities.lnk
[2010/03/21 18:31:10 | 000,028,672 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Did you forget what the Left Wing SEIU union thugs did to Ken Gladney.doc
[2010/03/21 17:06:48 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\ObamaCare Is HC Deform.doc
[2010/03/19 18:50:35 | 000,000,622 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\NTREGOPT.lnk
[2010/03/19 18:50:35 | 000,000,603 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ERUNT.lnk
[2010/03/18 19:47:37 | 000,032,768 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\instruction at 0x7342611a referenced memory at 0x7342611a.doc
[2010/03/17 22:15:20 | 000,001,742 | ---- | C] () -- C:\WINDOWS\tasks\wrSpySweeper_L76ACFF3080CC4EF49735590A605EA80E.job
[2010/03/16 00:01:41 | 000,000,878 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/03/14 07:50:30 | 000,000,328 | ---- | C] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2010/03/14 06:05:56 | 000,030,208 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\0x7342611a Error.doc
[2010/03/13 05:52:12 | 000,000,661 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\SpywareGuard.lnk
[2010/03/13 04:22:54 | 000,001,746 | ---- | C] () -- C:\WINDOWS\tasks\wrSpySweeper_LE9294F1191DE48CFA4B4FF790F3BF861.job
[2010/03/13 04:22:53 | 000,001,732 | ---- | C] () -- C:\WINDOWS\tasks\wrSpySweeper_L85ADAE8969AB41209763B0C6C57BE5D4.job
[2010/03/10 20:09:14 | 000,343,899 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\MarchPrayers.pdf
[2010/03/08 06:02:36 | 000,000,498 | ---- | C] () -- C:\Documents and Settings\Administrator\Compress.res
[2010/03/05 19:35:46 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\MATHR Member Marketing Profile - BrianDomenoski.doc
[2010/03/05 07:18:45 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Short History of Marriage.doc
[2010/03/04 14:10:08 | 014,680,064 | ---- | C] () -- C:\Documents and Settings\Administrator\ntuser.dat
[2010/03/03 16:46:02 | 000,000,294 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1413038736-614172877-2008263415-500.job
[2010/03/03 16:46:01 | 000,000,302 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1413038736-614172877-2008263415-500.job
[2009/11/06 13:00:28 | 000,031,088 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2009/08/17 09:30:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\uoadyk.sys
[2009/05/29 17:44:55 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/05/29 17:44:52 | 000,819,200 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/04/19 19:08:32 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
[2009/04/19 19:08:31 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
[2009/04/19 19:06:57 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2009/04/19 19:06:56 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2009/04/19 19:06:54 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2009/03/26 00:02:46 | 000,000,808 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Launch Internet Explorer Browser.lnk
[2009/03/15 01:52:15 | 000,000,266 | ---- | C] () -- C:\WINDOWS\reimage.ini
[2009/03/14 02:00:00 | 000,223,232 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll
[2009/03/14 01:59:58 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\SQLiteWrapper.dll
[2008/09/28 02:40:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\HPMProp.INI
[2008/09/14 00:36:15 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008/07/16 23:35:28 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2008/01/25 20:44:32 | 000,010,088 | ---- | C] () -- C:\WINDOWS\msvrc20.dll
[2007/11/06 15:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/09/19 19:29:59 | 000,000,031 | ---- | C] () -- C:\WINDOWS\sbewin32.INI
[2007/09/08 04:21:47 | 000,000,080 | ---- | C] () -- C:\WINDOWS\SuperUtil.ini
[2007/09/08 03:44:30 | 000,269,824 | ---- | C] () -- C:\WINDOWS\System32\baksm.dll
[2007/07/18 17:42:42 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/05/06 20:57:20 | 000,002,041 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\HPCOM_48BitScanUpdate.log
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/03 08:59:04 | 000,058,163 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/12/10 03:40:08 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/10/30 20:23:07 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2006/10/30 01:00:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\besched.dll
[2006/09/03 18:12:09 | 000,000,196 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2006/09/01 16:28:01 | 000,000,072 | ---- | C] () -- C:\WINDOWS\wb.ini
[2006/09/01 15:18:37 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\wbload.dll
[2006/08/24 19:08:13 | 000,001,353 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/08/20 23:48:50 | 000,000,278 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/20 03:49:21 | 000,011,669 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/08/20 03:49:20 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/08/19 01:43:56 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/19 00:04:09 | 000,036,864 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/18 23:24:48 | 000,002,150 | ---- | C] () -- C:\WINDOWS\System32\tmmute.ini
[2006/03/15 07:00:00 | 002,458,112 | ---- | C] () -- C:\WINDOWS\System32\wmvcore.dll
[2005/02/23 02:07:26 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\rnlsp(2)(2)(2).dll
[2004/08/09 23:11:42 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/10/02 01:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
[2003/10/02 01:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll
[2003/08/26 21:22:43 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/08/16 00:22:46 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/08/16 00:14:14 | 000,025,449 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2003/08/16 00:13:42 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/08/16 00:13:08 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/08/15 23:55:23 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2003/08/15 23:33:36 | 000,102,789 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2003/08/15 23:24:16 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/08/15 23:21:32 | 000,098,384 | ---- | C] () -- C:\WINDOWS\System32\EzRating.dll
[2003/08/15 22:39:52 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/08/15 22:39:52 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/08/15 22:39:32 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/08/15 20:36:19 | 000,000,045 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/08/15 20:17:54 | 000,000,573 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ========== [2009/11/14 14:50:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\agi
[2007/09/19 19:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Backup MyPC
[2008/09/07 17:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Bit9
[2009/11/06 02:06:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\CBS Interactive
[2009/03/03 17:07:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/07/09 22:56:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.adobe.px.Uploader.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1
[2009/03/04 00:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GlarySoft
[2009/05/05 20:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IObit
[2006/08/30 19:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech
[2009/04/19 19:03:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MightyKey
[2008/03/29 21:23:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\My CuteForm RunTime
[2009/03/01 17:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\net.twitterlocal.onair.A589D10E991C524019173F7ADEB73C85B538C40C.1
[2007/10/28 05:02:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OfficeUpdate12
[2007/11/09 23:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Opera
[2008/09/07 17:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PC Magazine Utilities
[2008/02/06 00:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PrevxCSI
[2008/09/13 23:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Registry Booster
[2003/08/16 00:14:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SampleView
[2009/09/24 23:52:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SRI
[2009/10/17 22:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Stamps.com Internet Postage
[2009/02/20 23:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/05/29 00:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Uniblue
[2006/08/27 18:29:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Webshots
[2008/09/13 16:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2009/02/20 02:30:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Search
[2009/11/13 22:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\agi
[2009/02/22 18:31:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2010/02/21 22:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2010/02/01 23:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/03/18 02:23:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MapQuest Toolbar
[2006/09/10 20:20:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/11/18 21:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SRI
[2010/03/18 19:54:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/28 14:17:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
[2010/04/02 00:29:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/16 00:01:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009/09/14 14:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/28 14:14:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{942E4254-C25C-44BA-94FC-8777923F9E7B}
[2009/05/28 14:15:09 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{B3ABAF49-C1FD-4E23-A5C8-1D0530D54991}
[2009/05/28 14:13:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{E18C8A94-0667-4A02-B59B-9CB3A8F22628}
[2010/04/02 01:40:08 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/04/02 01:34:32 | 000,000,328 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
[2010/03/14 22:00:00 | 000,000,400 | ---- | M] () -- C:\WINDOWS\Tasks\SmartDefrag.job
[2010/03/29 17:00:04 | 000,001,742 | ---- | M] () -- C:\WINDOWS\Tasks\wrSpySweeper_L76ACFF3080CC4EF49735590A605EA80E.job
[2010/03/27 16:00:09 | 000,001,732 | ---- | M] () -- C:\WINDOWS\Tasks\wrSpySweeper_L85ADAE8969AB41209763B0C6C57BE5D4.job
[2010/04/01 23:00:10 | 000,001,746 | ---- | M] () -- C:\WINDOWS\Tasks\wrSpySweeper_LE9294F1191DE48CFA4B4FF790F3BF861.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2007/05/30 17:19:04 | 000,710,432 | ---- | M] (Microsoft Corporation) -- C:\Q820121_WXP_SP2_x86_ENU.exe
[2007/05/30 17:19:06 | 000,131,360 | ---- | M] (Microsoft Corporation) -- C:\Q820121_WXP_SP2_x86_ENU_Symbols.exe
[2009/02/15 13:49:42 | 000,077,824 | ---- | M] () -- C:\REIPostRebootExecuter.exe
[2009/02/11 11:34:32 | 000,442,368 | ---- | M] () -- C:\REIReiFTPWatchDog.exe
[2009/08/04 08:41:00 | 000,083,232 | ---- | M] () -- C:\REI_SendEvents.exe
< MD5 for: AGP440.SYS >[2006/03/15 07:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
[2008/04/14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\ReinstallBackups\0021\DriverFiles\i386\AGP440.SYS
[2004/08/03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2006/03/15 07:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2003/07/30 14:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:atapi.sys
[2008/04/14 05:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003/08/28 21:05:30 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtUninstallQ331958$\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2006/03/15 07:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 05:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2006/03/15 07:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 05:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2006/03/15 07:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2006/03/15 07:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 05:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2008/04/14 05:41:52 | 001,267,200 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
[2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2009/11/06 13:00:28 | 000,031,088 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\wrLZMA.dll
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2007/05/21 14:39:24 | 000,786,432 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/05/21 19:29:22 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2007/05/21 14:39:24 | 033,030,144 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/05/21 14:39:25 | 005,242,880 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ========== @Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
3.) Extras OTL
OTL Extras logfile created on: 4/2/2010 1:56:21 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.83 Gb Total Space | 107.11 Gb Free Space | 74.47% Space Free | Partition Type: NTFS
Drive D: | 5.19 Gb Total Space | 1.17 Gb Free Space | 22.60% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-9K1AY6X2A2
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1723:TCP" = 1723:TCP:*:Enabled:@xpsp2res.dll,-22015
"1701:UDP" = 1701:UDP:*:Enabled:@xpsp2res.dll,-22016
"500:UDP" = 500:UDP:*:Enabled:@xpsp2res.dll,-22017
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"5910:TCP" = 5910:TCP:*:Enabled:vnc5910
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program -- (Microsoft Corporation)
"C:\WINDOWS\LMID1.tmp\lmi_rescue.exe" = C:\WINDOWS\LMID1.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\WINDOWS\LMI128.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI128.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue -- File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Documents and Settings\Administrator\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe" = C:\Documents and Settings\Administrator\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe:*:Enabled:Abacast Distributed On-Demand -- File not found
"C:\Documents and Settings\Administrator\Local Settings\Application Data\Abacast\Abaclient.exe" = C:\Documents and Settings\Administrator\Local Settings\Application Data\Abacast\Abaclient.exe:*:Enabled:Abaclient -- File not found
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
"C:\Program Files\Real\RealOne Player\realplay.exe" = C:\Program Files\Real\RealOne Player\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Documents and Settings\Administrator\Local Settings\Application Data\CrossLoop\vncviewer.exe" = C:\Documents and Settings\Administrator\Local Settings\Application Data\CrossLoop\vncviewer.exe:*:Enabled:vncviewer.exe -- (UltraVNC)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1E2F8094-9DCD-4B87-ADB3-25CC5A0442FF}" = Roxio Backup MyPC
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Spy Sweeper
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23C3F5C0-566B-478B-AAB6-197ADAD0C945}" = Uniblue SpeedUpMyPC 2009
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{364EC092-93CF-4DDC-9D7A-7278452028E0}" = Logitech QuickCam
"{37A5E5C0-1704-5E2A-9A29-9B9F53EFD666}" = Adobe Photoshop.com Uploader
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4CB2511D-A074-40E0-A5ED-A875EBBDDF49}" = BotHunter
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{62BFB4C2-8C4E-4D91-BD7D-81C06EAAC3C0}" = Windows Rights Management Client with Service Pack 2
"{6314D540-E3C1-4F30-AEEB-4154C93375C3}" = HP Driver Diagnostics
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72E67064-A144-42A6-BC85-12276B2D5D42}" = 2400_2500Help
"{76BC2442-0002-47FA-9617-43BAD82BEF4C}" = Bonjour
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{782A8AEE-0722-4E08-BB72-34C218CF166B}" = Uniblue PowerSuite 2009
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8B957F8D-FBDE-4DB4-99E7-192487575050}" = 23_24_2500Tour
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{981FAFFC-35E9-42E0-9C58-9AADE646F92A}" = Diskeeper 2010 Home
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{996A2FAA-7514-4628-9D12-A8FC34A0016E}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AD84892-7664-479C-8F95-7A25B964B04D}" = 2400_2500trb
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{a454c267-70b9-3bfc-af15-628bcc82d578}" = Webshots Desktop
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2009.10.22
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{B5C3B892-0849-476C-9F46-B12F84819D57}" = Apple Mobile Device Support
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BDDA03FF-47BE-4aa9-B4FA-06EA477A6B38}" = Think Right Now 1.7
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D9C8DEF8-D07B-4164-BEF0-6D879A70C212}" = Microsoft Easy Assist v2
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}" = Uniblue RegistryBooster 2009
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBCFA617-1856-4BE2-BA3C-BADD374757E7}" = 2500
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"CCleaner" = CCleaner
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CrossLoop_is1" = CrossLoop 2.70
"ERUNT_is1" = ERUNT 1.1j
"Glary Utilities_is1" = Glary Utilities 2.21.0.863
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{E05895C5-FE97-4334-8D73-B0089FD07CE3}" = Multimedia Card Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MapQuest Toolbar" = MapQuest Toolbar
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QcDrv" = Logitech® Camera Driver
"RealPlayer 12.0" = RealPlayer
"Reimage PC Booster" = Reimage PC Booster
"ReimageAgent" = Reimage real-time monitor
"SBEWIN32.EXE" =
"Secunia PSI" = Secunia PSI
"SGTRAY.EXE" =
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SpywareGuard_is1" = SpywareGuard v2.2
"Startup Cop Pro_is1" = Startup Cop Pro 3.0
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"Uniblue PowerSuite 2009" = Uniblue PowerSuite 2009
"Uniblue RegistryBooster 2009" = Uniblue RegistryBooster 2009
"Uniblue SpeedUpMyPC 2009" = Uniblue SpeedUpMyPC 2009
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.0.0.320
"ixquickDB.ixquickDBDeskbar" = Ixquick Deskbar
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 4/1/2010 2:32:21 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 5:42:30 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 4:07:31 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 5:05:01 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application outlook.exe, version 11.0.8312.0, stamp 4a403990,
faulting module ntdll.dll, version 5.1.2600.5755, stamp 49901d48, debug? 0, fault
address 0x00010a19.
Error - 4/1/2010 8:44:50 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 8:56:52 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 9:01:42 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/1/2010 9:12:38 PM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/2/2010 1:54:32 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
Error - 4/2/2010 2:37:04 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 agcoreservice.exe, P2 4.0.0.0, P3 4ae9ae20,
P4 mscorlib, P5 2.0.0.0, P6 4a7cd8f7, P7 1b2a, P8 c, P9 system.io.filenotfoundexception,
P10 NIL.
[ System Events ]
Error - 4/2/2010 2:34:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = NetDDE | ID = 12
Description = Initialization of "NDDENB32" DLL failed
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the AG Core Services service
to connect.
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7000
Description = The AG Core Services service failed to start due to the following
error: %%1053
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7003
Description = The Alerter service depends on the following nonexistent service:
LanmanWorkstation
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7003
Description = The Computer Browser service depends on the following nonexistent
service: LanmanServer
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7000
Description = The OPURNQUV service failed to start due to the following error: %%2
Error - 4/2/2010 2:35:29 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7000
Description = The Security Activity Dashboard Service service failed to start due
to the following error: %%2
Error - 4/2/2010 2:35:37 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = WMPNetworkSvc | ID = 866312
Description = A new media server was not initialized because WMCreateDeviceRegistration()
encountered error '0xc00d2711'. The Windows Media DRM components on your computer
might be corrupted. Verify that protected files play correctly in Windows Media
Player, and then restart the WMPNetworkSvc service.
Error - 4/2/2010 2:35:38 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = WMPNetworkSvc | ID = 866312
Description = A new media server was not initialized because WMCreateDeviceRegistration()
encountered error '0xc00d2711'. The Windows Media DRM components on your computer
might be corrupted. Verify that protected files play correctly in Windows Media
Player, and then restart the WMPNetworkSvc service.
Error - 4/2/2010 2:37:01 AM | Computer Name = YOUR-9K1AY6X2A2 | Source = Service Control Manager | ID = 7022
Description = The Webroot Spy Sweeper Engine service hung on starting.
< End of report >
4.)
PC is running with the same problems; no improvement has occurred.