After I tried to delete it, it told me I had to download some root kit boot sector repair tool, and it failed miserably.
Edit: Operating System is Windows 7
I followed the Malware Removal Guide found right here and ran all of the recommended logs.
One issue I ran into before I post all the logs, is that when I ran GMER I got "C:\Windows\systems\config\system: The system cannot find the file specified" and then it did not allow me to check/uncheck anything besides the "Services" "Registry" "Files" "ADS" and "C:\" options. Everything else was grayed out and unselectable, so I was unable to get this log.
Here is my MBAM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4427
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8/14/2010 10:21:53 AM
mbam-log-2010-08-14 (10-21-53).txt
Scan type: Quick scan
Objects scanned: 142281
Time elapsed: 2 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997} (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome (Adware.ResultDns) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome.manifest (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\contents.rdf (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\install.rdf (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome\resultdns.jar (Adware.ResultDns) -> Quarantined and deleted successfully.
C:\Users\Cody\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Cody\Templates\memory.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
After Running MBAM, Avira still found the infection, so I ran MBAM again and it was clean. I then ran GMER (see issues above) and then OTL (found below)
OTL File
OTL logfile created on: 8/14/2010 10:38:22 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Cody\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 66.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 296.94 Gb Free Space | 63.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ANNIHILATION
Current User Name: Cody
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/08/14 10:37:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Cody\Desktop\OTL.exe
PRC - [2010/07/21 20:40:35 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/03/08 14:10:56 | 000,095,232 | ---- | M] () -- C:\Program Files (x86)\Warner Bros. Digital Copy Manager\Warner Bros. Digital Copy Manager.exe
PRC - [2010/02/26 01:10:20 | 021,979,992 | ---- | M] () -- C:\Users\Cody\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2009/12/27 23:25:28 | 000,386,872 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre6\bin\jucheck.exe
PRC - [2009/10/07 01:47:22 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/07/21 14:34:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2009/05/12 15:43:30 | 002,158,592 | ---- | M] () -- C:\Program Files (x86)\Vtune\TBPANEL.exe
PRC - [2009/04/07 14:53:32 | 000,030,440 | ---- | M] () -- C:\Program Files (x86)\dcmsvc\dcmsvc.exe
PRC - [2009/03/02 13:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
========== Modules (SafeList) ==========
MOD - [2010/08/14 10:37:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Cody\Desktop\OTL.exe
MOD - [2009/07/13 21:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2010/03/25 10:41:00 | 051,456,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV:64bit: - [2010/01/09 21:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV:64bit: - [2009/10/07 01:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/12/02 23:27:37 | 000,320,760 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/07/21 14:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2009/12/07 13:10:38 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2009/10/07 04:49:27 | 006,379,288 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech Webcam 250(UVC)
DRV:64bit: - [2009/10/07 04:47:44 | 000,327,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2009/10/07 04:45:37 | 000,271,640 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64)
DRV:64bit: - [2009/10/07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009/10/07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009/09/11 15:49:18 | 000,076,552 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2009/09/11 15:49:08 | 000,015,880 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2009/09/11 15:48:46 | 000,041,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2009/09/11 15:48:36 | 000,026,248 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2009/08/28 20:42:52 | 000,049,152 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2009/08/09 17:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/27 18:32:20 | 000,603,136 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/02/24 19:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV:64bit: - [2008/04/22 11:53:36 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV - [2007/03/16 10:11:20 | 000,015,648 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\TBPanelx64.sys -- (Cardex)
DRV - [2007/02/07 14:27:46 | 000,014,104 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\speedfan.sys -- (speedfan)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A2 FD 1E 98 EE 1A CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://highergroundp...m=hghellsgroup"
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: [email protected]:1.5.2
FF - prefs.js..extensions.enabledItems: {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:2.7.1.3
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/21 20:40:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/21 20:40:36 | 000,000,000 | ---D | M]
[2009/12/27 23:26:08 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Mozilla\Extensions
[2009/12/27 23:26:08 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Mozilla\Extensions\[email protected]
[2010/08/14 10:36:01 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Mozilla\Firefox\Profiles\5c9a9ypy.default\extensions
[2010/07/03 16:40:00 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Users\Cody\AppData\Roaming\Mozilla\Firefox\Profiles\5c9a9ypy.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
[2010/03/20 21:01:46 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Mozilla\Firefox\Profiles\5c9a9ypy.default\extensions\[email protected]
[2010/08/14 10:36:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files (x86)\XfireXO\tbXfir.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dcmsvc] C:\Program Files (x86)\dcmsvc\dcmsvc.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Cody\AppData\Roaming\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files (x86)\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Warner Bros.lnk = C:\Program Files (x86)\Warner Bros. Digital Copy Manager\Warner Bros. Digital Copy Manager.exe ()
O4 - Startup: C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{80f7e005-2229-11df-b797-00241dd79bff}\Shell - "" = AutoRun
O33 - MountPoints2\{80f7e005-2229-11df-b797-00241dd79bff}\Shell\AutoRun\command - "" = E:\Launcher.exe -- File not found
O33 - MountPoints2\{80f7e024-2229-11df-b797-00241dd79bff}\Shell - "" = AutoRun
O33 - MountPoints2\{80f7e024-2229-11df-b797-00241dd79bff}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010/08/14 10:37:24 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Cody\Desktop\OTL.exe
[2010/08/14 10:32:19 | 000,000,000 | ---D | C] -- C:\Users\Cody\Desktop\gmer
[2010/08/14 10:18:01 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/08/14 10:17:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2010/08/14 10:17:04 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Cody\Desktop\erunt_setup.exe
[2010/08/14 10:10:47 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\Cody\Desktop\TFC.exe
[2010/08/14 09:27:46 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\Windows Server
[2010/08/14 09:27:10 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\183C23F30C9C94C3DC7302BA6093E339
[2010/08/04 11:01:19 | 000,000,000 | ---D | C] -- C:\Users\Cody\Documents\My Digital Editions
[2010/08/04 11:01:08 | 000,000,000 | ---D | C] -- C:\Users\Cody\Documents\My Barnes & Noble eBooks
[2010/08/04 11:00:54 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\Barnes & Noble
[2010/08/04 11:00:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Barnes & Noble
[2010/08/04 11:00:10 | 020,428,216 | ---- | C] (Barnes & Noble, Inc.) -- C:\Users\Cody\Desktop\NOOKstudy.exe
[2010/07/29 13:26:17 | 000,000,000 | ---D | C] -- C:\Users\Cody\Documents\Guild Wars
[2010/07/29 13:25:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
[2010/07/29 13:25:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guild Wars
[2010/07/29 13:25:24 | 000,165,248 | ---- | C] (ArenaNet) -- C:\Users\Cody\Desktop\GwSetup.exe
[2010/07/27 08:48:38 | 000,000,000 | ---D | C] -- C:\Windows\.jagex_cache_32
[2010/07/23 18:54:49 | 000,000,000 | ---D | C] -- C:\Users\Cody\Documents\Dungeons and Dragons Online
[2010/07/23 18:50:48 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\Turbine
[2010/07/23 18:50:31 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\Turbine
[2010/07/23 18:44:33 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\ApplicationHistory
[2010/07/23 18:43:15 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\URTTEMP
[2010/07/23 18:36:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Turbine
[2010/07/23 17:06:32 | 000,000,000 | ---D | C] -- C:\Users\Cody\Desktop\DDO standard res install files
[2010/07/23 17:04:00 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\PMB Files
[2010/07/23 17:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2010/07/23 17:03:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2010/07/20 14:50:05 | 000,000,000 | ---D | C] -- C:\Users\Cody\Documents\CodeBlock
[2010/07/20 14:47:35 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\codeblocks
[2010/07/20 14:47:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CodeBlocks
[2010/07/20 14:44:50 | 074,027,949 | ---- | C] (The Code::Blocks Team) -- C:\Users\Cody\Desktop\codeblocks-10.05mingw-setup.exe
[2010/07/19 23:21:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Chart Controls
[2010/07/19 23:20:47 | 000,000,000 | ---D | C] -- C:\UDK
[2010/07/19 22:46:12 | 815,446,104 | ---- | C] (Epic Games, Inc.) -- C:\Users\Cody\Desktop\UDKInstall-2010-07-BETA.exe
[2010/07/19 20:08:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Combined Community Codec Pack
[2010/07/19 20:06:03 | 006,238,105 | ---- | C] (CCCP Project ) -- C:\Users\Cody\Desktop\Combined-Community-Codec-Pack-2009-09-09.exe
[2010/07/15 15:28:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/07/15 15:27:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2010/07/15 15:27:34 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/07/15 15:27:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2010/07/15 15:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2010/07/15 15:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2010/07/15 15:26:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2010/07/15 15:25:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2010/07/15 15:25:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2010/07/15 15:25:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2010/07/15 15:25:37 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010/07/15 15:25:27 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/07/15 14:20:01 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\Ubisoft
[2010/07/15 14:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2010/07/08 14:07:22 | 000,027,136 | ---- | C] (CPUID) -- C:\Windows\SysWow64\PCWizard.cpl
[2010/07/08 14:07:22 | 000,000,000 | ---D | C] -- C:\Windows\Java
[2010/07/08 14:07:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CPUID
[2010/07/06 12:32:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2010/07/06 12:32:16 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\uTorrent
[2010/07/03 16:40:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\XfireXO
[2010/07/03 16:40:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2010/07/03 16:39:56 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Roaming\Xfire
[2010/07/03 16:39:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2010/07/03 16:39:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xfire
[2010/07/03 00:52:52 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2010/07/03 00:52:47 | 000,000,000 | RH-D | C] -- C:\Users\Cody\AppData\Roaming\SecuROM
[2010/07/01 18:09:31 | 000,000,000 | ---D | C] -- C:\Users\Cody\Desktop\HG Web
[2010/06/28 19:53:56 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2010/06/28 19:49:23 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2010/06/28 19:45:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/06/28 19:45:44 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/06/28 19:44:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Media Player
[2010/06/28 17:59:18 | 000,000,000 | ---D | C] -- C:\IUware Online
[2010/06/28 16:41:26 | 000,000,000 | ---D | C] -- C:\Users\Cody\Desktop\Adobe CS5
[2010/06/25 19:47:00 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\Logitech
[2010/06/25 19:44:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logitech
[2010/06/19 09:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010/06/10 10:24:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2010/05/22 13:29:51 | 000,000,000 | ---D | C] -- C:\Users\Cody\AppData\Local\banxgcdjx
========== Files - Modified Within 90 Days ==========
[2010/08/14 10:39:33 | 003,670,016 | -HS- | M] () -- C:\Users\Cody\ntuser.dat
[2010/08/14 10:37:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Cody\Desktop\OTL.exe
[2010/08/14 10:31:58 | 000,284,915 | ---- | M] () -- C:\Users\Cody\Desktop\gmer.zip
[2010/08/14 10:31:09 | 000,015,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/14 10:31:09 | 000,015,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/14 10:24:00 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/08/14 10:23:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/08/14 10:23:46 | 3217,678,336 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/14 10:22:31 | 005,675,704 | -H-- | M] () -- C:\Users\Cody\AppData\Local\IconCache.db
[2010/08/14 10:18:26 | 000,727,362 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/14 10:18:26 | 000,623,890 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/08/14 10:18:26 | 000,107,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/08/14 10:17:27 | 000,000,924 | ---- | M] () -- C:\Users\Cody\Desktop\NTREGOPT.lnk
[2010/08/14 10:17:27 | 000,000,905 | ---- | M] () -- C:\Users\Cody\Desktop\ERUNT.lnk
[2010/08/14 10:17:09 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Cody\Desktop\erunt_setup.exe
[2010/08/14 10:10:49 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\Cody\Desktop\TFC.exe
[2010/08/14 10:03:32 | 000,524,288 | -HS- | M] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TMContainer00000000000000000002.regtrans-ms
[2010/08/14 10:03:32 | 000,524,288 | -HS- | M] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TMContainer00000000000000000001.regtrans-ms
[2010/08/14 10:03:32 | 000,065,536 | -HS- | M] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TM.blf
[2010/08/14 09:30:42 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2010/08/12 17:28:15 | 000,014,059 | ---- | M] () -- C:\Users\Cody\Documents\References.docx
[2010/08/11 19:02:06 | 000,019,513 | ---- | M] () -- C:\Users\Cody\Desktop\Chelsea%201edited[1].docx
[2010/08/11 18:23:57 | 000,020,238 | ---- | M] () -- C:\Users\Cody\Desktop\From Myth to Legend.docx
[2010/08/10 00:40:41 | 000,020,836 | ---- | M] () -- C:\Users\Cody\Desktop\TheSunAlsoRisespaperdraft.docx
[2010/08/04 11:00:56 | 000,001,206 | ---- | M] () -- C:\Users\Cody\Desktop\NOOKstudy.lnk
[2010/08/04 11:00:36 | 020,428,216 | ---- | M] (Barnes & Noble, Inc.) -- C:\Users\Cody\Desktop\NOOKstudy.exe
[2010/08/03 08:07:53 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2010/08/02 21:43:19 | 003,403,943 | ---- | M] () -- C:\Users\Cody\Desktop\chords,_capos,_charts_and_more_2.0.pdf
[2010/07/29 19:49:47 | 000,693,481 | ---- | M] () -- C:\Users\Cody\Desktop\Miracle, Cody IUPUI.pdf
[2010/07/29 13:25:25 | 000,165,248 | ---- | M] (ArenaNet) -- C:\Users\Cody\Desktop\GwSetup.exe
[2010/07/29 09:07:40 | 000,066,121 | ---- | M] () -- C:\Users\Cody\Desktop\m2000-s2300-30rebate-july2010.pdf
[2010/07/27 09:21:49 | 000,000,046 | ---- | M] () -- C:\Users\Cody\jagex_runescape_preferences.dat
[2010/07/27 09:20:08 | 000,000,099 | ---- | M] () -- C:\Users\Cody\jagex_runescape_preferences2.dat
[2010/07/27 08:50:29 | 000,000,000 | ---- | M] () -- C:\Users\Cody\jagex__preferences3.dat
[2010/07/26 23:50:03 | 182,740,992 | ---- | M] () -- C:\Users\Cody\Desktop\Cops S01E01.avi
[2010/07/25 06:32:37 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2010/07/23 18:50:32 | 000,000,092 | ---- | M] () -- C:\Users\Cody\AppData\Local\fusioncache.dat
[2010/07/23 18:44:25 | 000,743,126 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/22 21:23:56 | 000,018,676 | ---- | M] () -- C:\Users\Cody\Documents\JagJobResume.docx
[2010/07/20 16:46:08 | 000,000,220 | ---- | M] () -- C:\Users\Cody\Desktop\X-COM UFO Defense.url
[2010/07/20 14:46:28 | 074,027,949 | ---- | M] (The Code::Blocks Team) -- C:\Users\Cody\Desktop\codeblocks-10.05mingw-setup.exe
[2010/07/19 23:19:47 | 145,562,500 | ---- | M] () -- C:\Users\Cody\Desktop\WhizzleSourceFinal.zip
[2010/07/19 23:19:42 | 815,446,104 | ---- | M] (Epic Games, Inc.) -- C:\Users\Cody\Desktop\UDKInstall-2010-07-BETA.exe
[2010/07/19 22:41:41 | 000,000,196 | ---- | M] () -- C:\Users\Cody\Desktop\Alien Swarm - SDK.url
[2010/07/19 22:28:01 | 000,000,203 | ---- | M] () -- C:\Users\Cody\Desktop\Unreal Development Kit.url
[2010/07/19 22:25:07 | 000,000,219 | ---- | M] () -- C:\Users\Cody\Desktop\Alien Swarm.url
[2010/07/19 20:06:12 | 006,238,105 | ---- | M] (CCCP Project ) -- C:\Users\Cody\Desktop\Combined-Community-Codec-Pack-2009-09-09.exe
[2010/07/18 19:22:44 | 000,109,792 | ---- | M] () -- C:\Users\Cody\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/07/15 21:52:00 | 004,973,760 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/07/15 15:25:59 | 000,000,478 | ---- | M] () -- C:\Windows\win.ini
[2010/07/13 23:59:47 | 000,000,221 | ---- | M] () -- C:\Users\Cody\Desktop\Assassin's Creed.url
[2010/07/12 21:37:25 | 000,080,239 | ---- | M] () -- C:\Users\Cody\Desktop\Master Promissory Note.pdf
[2010/07/09 15:04:40 | 000,041,872 | ---- | M] () -- C:\Windows\SysWow64\xfcodec.dll
[2010/07/09 15:04:40 | 000,027,536 | ---- | M] () -- C:\Windows\SysNative\xfcodec64.dll
[2010/07/06 12:32:30 | 000,000,967 | ---- | M] () -- C:\Users\Cody\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/07/06 12:32:30 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/07/06 02:12:40 | 000,000,220 | ---- | M] () -- C:\Users\Cody\Desktop\Titan Quest Immortal Throne.url
[2010/07/03 16:39:55 | 000,000,999 | ---- | M] () -- C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2010/07/03 16:39:55 | 000,000,987 | ---- | M] () -- C:\Users\Cody\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2010/07/03 16:39:55 | 000,000,963 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2010/06/28 21:02:49 | 000,171,230 | ---- | M] () -- C:\Users\Cody\Documents\Forums.gif
[2010/06/27 19:40:02 | 000,011,380 | ---- | M] () -- C:\Users\Cody\Documents\HGEmail.docx
[2010/06/24 19:19:17 | 000,042,163 | ---- | M] () -- C:\Users\Cody\Desktop\LOST_SEASON_6_Complete.5631856.TPB.torrent
[2010/06/07 21:06:38 | 000,011,603 | ---- | M] () -- C:\Users\Cody\Documents\Appeal.docx
========== Files Created - No Company Name ==========
[2010/08/14 10:31:57 | 000,284,915 | ---- | C] () -- C:\Users\Cody\Desktop\gmer.zip
[2010/08/14 10:17:27 | 000,000,924 | ---- | C] () -- C:\Users\Cody\Desktop\NTREGOPT.lnk
[2010/08/14 10:17:27 | 000,000,905 | ---- | C] () -- C:\Users\Cody\Desktop\ERUNT.lnk
[2010/08/14 09:57:01 | 000,524,288 | -HS- | C] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TMContainer00000000000000000002.regtrans-ms
[2010/08/14 09:57:01 | 000,524,288 | -HS- | C] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TMContainer00000000000000000001.regtrans-ms
[2010/08/14 09:57:01 | 000,065,536 | -HS- | C] () -- C:\Users\Cody\ntuser.dat{b080b1a8-a7a3-11df-b7fc-00241dd79bff}.TM.blf
[2010/08/14 09:30:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/08/12 17:28:15 | 000,014,059 | ---- | C] () -- C:\Users\Cody\Documents\References.docx
[2010/08/11 19:02:03 | 000,019,513 | ---- | C] () -- C:\Users\Cody\Desktop\Chelsea%201edited[1].docx
[2010/08/11 18:23:56 | 000,020,238 | ---- | C] () -- C:\Users\Cody\Desktop\From Myth to Legend.docx
[2010/08/10 00:40:39 | 000,020,836 | ---- | C] () -- C:\Users\Cody\Desktop\TheSunAlsoRisespaperdraft.docx
[2010/08/04 11:00:56 | 000,001,206 | ---- | C] () -- C:\Users\Cody\Desktop\NOOKstudy.lnk
[2010/08/02 21:43:19 | 003,403,943 | ---- | C] () -- C:\Users\Cody\Desktop\chords,_capos,_charts_and_more_2.0.pdf
[2010/07/29 19:49:47 | 000,693,481 | ---- | C] () -- C:\Users\Cody\Desktop\Miracle, Cody IUPUI.pdf
[2010/07/29 09:07:40 | 000,066,121 | ---- | C] () -- C:\Users\Cody\Desktop\m2000-s2300-30rebate-july2010.pdf
[2010/07/27 08:50:29 | 000,000,099 | ---- | C] () -- C:\Users\Cody\jagex_runescape_preferences2.dat
[2010/07/27 08:50:29 | 000,000,000 | ---- | C] () -- C:\Users\Cody\jagex__preferences3.dat
[2010/07/27 08:48:50 | 000,000,046 | ---- | C] () -- C:\Users\Cody\jagex_runescape_preferences.dat
[2010/07/26 23:46:26 | 182,740,992 | ---- | C] () -- C:\Users\Cody\Desktop\Cops S01E01.avi
[2010/07/23 18:50:32 | 000,000,092 | ---- | C] () -- C:\Users\Cody\AppData\Local\fusioncache.dat
[2010/07/23 18:43:35 | 000,743,126 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/22 21:23:56 | 000,018,676 | ---- | C] () -- C:\Users\Cody\Documents\JagJobResume.docx
[2010/07/20 16:46:08 | 000,000,220 | ---- | C] () -- C:\Users\Cody\Desktop\X-COM UFO Defense.url
[2010/07/19 23:10:36 | 145,562,500 | ---- | C] () -- C:\Users\Cody\Desktop\WhizzleSourceFinal.zip
[2010/07/19 22:41:41 | 000,000,196 | ---- | C] () -- C:\Users\Cody\Desktop\Alien Swarm - SDK.url
[2010/07/19 22:28:01 | 000,000,203 | ---- | C] () -- C:\Users\Cody\Desktop\Unreal Development Kit.url
[2010/07/19 22:24:29 | 000,000,219 | ---- | C] () -- C:\Users\Cody\Desktop\Alien Swarm.url
[2010/07/13 23:59:47 | 000,000,221 | ---- | C] () -- C:\Users\Cody\Desktop\Assassin's Creed.url
[2010/07/12 21:37:24 | 000,080,239 | ---- | C] () -- C:\Users\Cody\Desktop\Master Promissory Note.pdf
[2010/07/09 15:04:40 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2010/07/09 15:04:40 | 000,027,536 | ---- | C] () -- C:\Windows\SysNative\xfcodec64.dll
[2010/07/06 12:32:30 | 000,000,967 | ---- | C] () -- C:\Users\Cody\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2010/07/06 12:32:30 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/07/06 02:12:40 | 000,000,220 | ---- | C] () -- C:\Users\Cody\Desktop\Titan Quest Immortal Throne.url
[2010/07/03 16:39:55 | 000,000,999 | ---- | C] () -- C:\Users\Cody\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2010/07/03 16:39:55 | 000,000,987 | ---- | C] () -- C:\Users\Cody\Application Data\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk
[2010/07/03 16:39:55 | 000,000,963 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2010/06/28 21:02:40 | 000,171,230 | ---- | C] () -- C:\Users\Cody\Documents\Forums.gif
[2010/06/27 19:34:20 | 000,011,380 | ---- | C] () -- C:\Users\Cody\Documents\HGEmail.docx
[2010/06/24 19:19:16 | 000,042,163 | ---- | C] () -- C:\Users\Cody\Desktop\LOST_SEASON_6_Complete.5631856.TPB.torrent
[2010/06/07 21:06:37 | 000,011,603 | ---- | C] () -- C:\Users\Cody\Documents\Appeal.docx
[2010/01/08 00:34:21 | 000,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/08/03 03:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2009/08/03 03:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009/08/03 03:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2009/08/03 03:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
========== LOP Check ==========
[2010/05/04 12:02:48 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\1304DBD39881998EFC670503810B716A
[2010/08/14 09:27:43 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\183C23F30C9C94C3DC7302BA6093E339
[2010/07/06 12:35:05 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Azureus
[2010/08/04 11:00:54 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Barnes & Noble
[2010/01/18 11:33:38 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Bioshock
[2010/03/08 14:11:04 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1
[2010/08/14 10:26:19 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Dropbox
[2010/03/07 12:17:54 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\GetRightToGo
[2009/12/02 20:35:33 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Leadertech
[2010/08/14 10:24:11 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\LimeWire
[2010/01/08 02:50:29 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2010/07/23 18:50:48 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Turbine
[2010/07/15 14:20:01 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\Ubisoft
[2010/08/03 12:41:00 | 000,000,000 | ---D | M] -- C:\Users\Cody\AppData\Roaming\uTorrent
[2010/07/09 09:48:37 | 000,032,636 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/08/14 10:23:46 | 3217,678,336 | -HS- | M] () -- C:\hiberfil.sys
[2006/12/01 23:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2010/08/14 10:23:50 | 4290,240,512 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras
OTL Extras logfile created on: 8/14/2010 10:38:22 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Cody\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 66.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 296.94 Gb Free Space | 63.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ANNIHILATION
Current User Name: Cody
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.js [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = jsfile] -- C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe (Adobe Systems, Inc.)
.txt [@ = txtfile] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3E4D62B-A496-4B18-8087-2589DAB25494}" =
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{96F1BA99-300F-4DD5-A26B-788EF63B53B1}" = Logitech Gaming Software 5.08
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9C243B9-03BD-44BA-A592-AB09630AE2D2}" = iTunes
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"UDK-f523935d-48c3-42aa-b78a-081f5a051daa" = Unreal Development Kit: 2010-07
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09F4655B-C804-4AD0-B7DF-078E338F8F85}" = League of Legends
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
"{0E6EC2D7-5C9B-28B7-C848-171EDACB9625}" = Warner Bros. Digital Copy Manager
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 16
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5
"{4EE9A620-46A0-4BCF-82AC-950D2BBED982}" = Belkin N Wireless USB Adapter Setup
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{A1BC7068-C1BA-410F-8B9A-DB807C803DE2}" = Adobe Creative Suite 5 Design Premium
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{C1583439-B034-4881-819C-D52A0587662B}" = Neverwinter Nights
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE12677C-F7D2-45A8-BBF9-0FC0B972EDC3}" = League of Legends
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E7DF4F40-A0CE-430E-8B3B-DB7C8DF1C1A2}" = ActivePerl 5.10.1 Build 1006
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AutoHotkey" = AutoHotkey 1.0.48.05
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1" = Warner Bros. Digital Copy Manager
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"dcmsvc_is1" = dcmsvc 1.0
"ERUNT_is1" = ERUNT 1.1j
"EVEREST Corporate Edition_is1" = EVEREST Corporate Edition v5.30
"Guild Wars" = Guild Wars
"kSolo" = kSolo Recorder
"LimeWire" = LimeWire 5.4.6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"mIRC" = mIRC
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"Neverwinter Nights Kingmaker" = BioWare Premium Module: Neverwinter Nights Kingmaker
"NOOKstudy" = NOOKstudy
"OpenAL" = OpenAL
"PC Wizard 2010_is1" = PC Wizard 2010.1.94
"PCSX2-beta-r1888" = PCSX2 - Playstation 2 Emulator
"SpeedFan" = SpeedFan (remove only)
"Steam App 13260" = Unreal Development Kit
"Steam App 15100" = Assassin's Creed
"Steam App 17460" = Mass Effect
"Steam App 18820" = Zero Gear
"Steam App 24980" = Mass Effect 2
"Steam App 440" = Team Fortress 2
"Steam App 4550" = Titan Quest: Immortal Throne
"Steam App 630" = Alien Swarm
"Steam App 640" = Alien Swarm - SDK
"Steam App 7670" = BioShock
"Steam App 7760" = X-COM: UFO Defense
"Steam App 8980" = Borderlands
"uTorrent" = µTorrent
"Vtune_is1" = Vtune 7.5
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"CodeBlocks" = CodeBlocks
"Dropbox" = Dropbox
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/10/2010 9:31:25 AM | Computer Name = Annihilation | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 8/10/2010 1:21:57 PM | Computer Name = Annihilation | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 8/10/2010 10:17:29 PM | Computer Name = Annihilation | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 8/10/2010 10:17:29 PM | Computer Name = Annihilation | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 8/11/2010 5:52:22 PM | Computer Name = Annihilation | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 8/11/2010 5:52:22 PM | Computer Name = Annihilation | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .
Error - 8/11/2010 6:11:04 PM | Computer Name = Annihilation | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.
Error - 8/11/2010 6:15:04 PM | Computer Name = Annihilation | Source = Application Error | ID = 1000
Description = Faulting application name: rundll32.exe, version: 6.1.7600.16385,
time stamp: 0x4a5bc637 Faulting module name: xfire_toucan_43094.dll, version: 1.0.0.43094,
time stamp: 0x4c376f00 Exception code: 0xc0000005 Fault offset: 0x00074d89 Faulting
process id: 0xc88 Faulting application start time: 0x01cb39a2a59258d4 Faulting application
path: C:\Windows\SysWOW64\rundll32.exe Faulting module path: C:\Program Files (x86)\Xfire\xfire_toucan_43094.dll
Report
Id: e39292d6-a595-11df-907a-00241dd79bff
Error - 8/11/2010 8:49:03 PM | Computer Name = Annihilation | Source = Application Hang | ID = 1002
Description = The program nwmain.exe version 1.6.9.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 17b0 Start Time:
01cb39aca6881532 Termination Time: 31 Application Path: C:\NeverwinterNights\NWN\nwmain.exe
Report
Id: 65bd2ec7-a5ab-11df-907a-00241dd79bff
Error - 8/11/2010 11:45:28 PM | Computer Name = Annihilation | Source = Application Error | ID = 1000
Description = Faulting application name: ePSXe.exe, version: 0.0.0.0, time stamp:
0x483816fa Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp:
0x4a5bdb3b Exception code: 0xc0000374 Fault offset: 0x000cdcbb Faulting process id:
0x14b8 Faulting application start time: 0x01cb39c66525df71 Faulting application path:
C:\Users\Cody\Desktop\Playstation 2 Awesomeness\epsxe170\ePSXe.exe Faulting module
path: C:\Windows\SysWOW64\ntdll.dll Report Id: 0b98e5ae-a5c4-11df-907a-00241dd79bff
[ Media Center Events ]
Error - 12/6/2009 1:39:53 PM | Computer Name = Annihilation | Source = Microsoft-Windows-Media Center Extender | ID = 121
Description =
Error - 12/6/2009 1:41:59 PM | Computer Name = Annihilation | Source = Microsoft-Windows-Media Center Extender | ID = 543
Description =
[ System Events ]
Error - 5/22/2010 1:40:58 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The NVIDIA Stereoscopic 3D Driver Service service failed to start
due to the following error: %%2
Error - 5/22/2010 1:46:53 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/22/2010 2:12:59 PM | Computer Name = Annihilation | Source = BROWSER | ID = 8032
Description =
Error - 5/23/2010 4:23:02 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/24/2010 10:05:57 AM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/24/2010 11:45:03 PM | Computer Name = Annihilation | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:43:41 PM on ?5/?24/?2010 was unexpected.
Error - 5/24/2010 11:45:08 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/24/2010 11:54:50 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/25/2010 9:33:13 AM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
Error - 5/26/2010 11:26:46 PM | Computer Name = Annihilation | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2
< End of report >
Any help would be fantastic, thanks a ton.
Edited by strykerofchaos, 14 August 2010 - 08:56 AM.