Win32/sality.au Win32/sality.am Win32/Pramfro.F Removal please :(
Started by
Nikiel
, May 05 2011 03:59 AM
#1
Posted 05 May 2011 - 03:59 AM
#2
Posted 05 May 2011 - 04:40 AM
OTL logfile created on: 5/5/2011 6:10:13 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS
Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
PRC - [2011/05/05 06:32:44 | 001,004,544 | ---- | M] (Google Inc.) -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/05/04 20:27:25 | 000,382,704 | ---- | M] () -- C:\Program Files\cacaoweb\cacaoweb.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:42 | 000,226,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe
PRC - [2008/04/14 20:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (SafeList) ==========
MOD - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
MOD - [2010/08/24 00:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/26 23:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (gupdatem) Google Update Service (gupdatem)
SRV - File not found [Auto | Stopped] -- -- (gupdate) Google Update Service (gupdate)
SRV - [2011/05/04 06:10:37 | 003,274,328 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_3f211bc.dll -- (Akamai)
SRV - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/05/04 08:10:00 | 003,539,184 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) [Auto | Running] -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe -- (FortiSslvpnDaemon)
SRV - [2008/11/04 08:06:28 | 000,519,536 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 18:44:08 | 000,139,616 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006/10/26 14:03:08 | 000,227,104 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (asc3360pr)
DRV - [2011/05/05 16:30:38 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{850EBCBA-E9BC-4CD2-BD79-AA3D6F89E2CC}\MpKsld50583e0.sys -- (MpKsld50583e0)
DRV - [2011/02/23 17:04:30 | 000,013,496 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/08/26 19:57:00 | 000,025,616 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Kiel\Local Settings\Temp\WHR58.tmp -- (GarenaPEngine)
DRV - [2009/07/21 17:53:06 | 000,036,384 | ---- | M] (Fortinet Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pppop.sys -- (pppop)
DRV - [2008/09/26 18:01:00 | 000,101,376 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/16 18:52:00 | 004,747,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/04/15 11:14:02 | 000,990,632 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/04/15 11:13:58 | 000,534,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008/03/29 08:38:16 | 000,625,024 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2860.sys -- (RT80x86)
DRV - [2008/03/27 17:18:12 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/03/11 19:37:00 | 000,036,864 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2008/03/10 18:18:42 | 000,057,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2008/02/04 17:57:44 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2008/02/04 17:57:30 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2007/09/20 11:59:14 | 000,156,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007/07/27 11:00:38 | 000,011,264 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
DRV - [2006/12/01 14:23:58 | 000,392,122 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM303.sys -- (ZSMC303)
DRV - [2006/04/25 10:57:42 | 000,428,160 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vmfilter303.sys -- (vmfilter303)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "facebook.com"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:6.8.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.12
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/19 07:03:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 08:28:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/29 16:33:42 | 000,000,000 | ---D | M]
[2010/09/13 11:52:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Extensions
[2011/04/25 02:00:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions
[2011/03/28 13:48:35 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/04/18 15:09:33 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/03/28 13:48:37 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/05/04 12:01:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/18 17:15:24 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/18 03:16:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 12:44:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/10 05:34:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/12/19 07:03:08 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/09/18 17:04:35 | 000,000,000 | ---D | M] (IDM CC) -- C:\DOCUMENTS AND SETTINGS\KIEL XP\APPLICATION DATA\IDM\IDMMZCC3
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/12/17 12:43:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/08/16 17:42:02 | 000,070,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 17:42:12 | 000,091,448 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 17:42:08 | 000,020,800 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 08:41:08 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 08:41:08 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 08:41:08 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/08/16 17:44:46 | 000,427,312 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/08/16 17:42:04 | 000,023,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
O1 HOSTS File: ([2011/05/05 12:58:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cacaoweb] C:\Program Files\cacaoweb\cacaoweb.exe ()
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 124.106.4.2 124.106.5.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/05 15:48:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/05/05 15:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/05/05 15:31:48 | 000,000,000 | ---D | C] -- C:\_OTMoveIt
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\rsit
[2011/05/05 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\Malwarebytes
[2011/05/05 13:15:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/05 13:15:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/05/05 13:15:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/05 13:15:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/05 12:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 12:40:32 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/05 07:48:09 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/05 07:48:09 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/05 07:48:09 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/05 07:48:09 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/05 07:47:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/05 07:16:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/29 07:44:44 | 000,000,000 | ---D | C] -- C:\Downloads
[2011/04/25 12:24:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\My Documents\photo shop
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yazobo Games
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\Drag_Racer_v3
[2011/04/18 15:09:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/04/18 15:09:56 | 000,000,000 | ---D | C] -- C:\Program Files\cacaoweb
[2011/04/18 09:35:38 | 000,172,032 | ---- | C] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/18 06:05:41 | 000,000,000 | ---D | C] -- C:\Program Files\ProdigyRan
[2011/04/10 22:08:13 | 000,000,000 | ---D | C] -- C:\Program Files\Network Stumbler
[2011/04/09 14:25:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GameTop.com
[2011/04/09 14:25:38 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011/04/09 09:15:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/04/09 09:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Garena
[2011/04/09 09:01:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/04/09 09:00:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/04/08 10:26:00 | 000,000,000 | ---D | C] -- C:\FarmHelper
[2011/04/06 14:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2008/06/27 14:48:49 | 015,523,560 | ---- | C] (Macrovision Corporation) -- C:\Program Files\U1 Setup.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:07 | 000,010,635 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:38 | 000,016,284 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:46:55 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/05 15:34:08 | 000,000,439 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/05/05 15:34:03 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/05/05 15:34:03 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/05 15:34:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/05/05 15:34:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/05 15:34:01 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 15:34:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/05/05 15:34:01 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/05/05 15:33:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/05 15:09:06 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 12:58:02 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/05 12:40:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/05 05:46:23 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/04 22:30:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/05/04 19:00:01 | 000,003,444 | ---- | M] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/05/04 12:46:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/04 10:51:46 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/03 23:45:28 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/03 11:34:41 | 000,002,302 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\Google Chrome.lnk
[2011/05/03 11:34:41 | 000,002,280 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/03 10:22:54 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/02 07:08:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/04/30 10:43:26 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/29 15:11:32 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/26 15:17:33 | 000,000,238 | ---- | M] () -- C:\WINDOWS\mafosav.INI
[2011/04/22 09:50:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/04/18 15:28:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/18 09:35:38 | 000,172,032 | ---- | M] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/15 20:12:22 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/09 09:11:07 | 000,001,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/06 14:21:21 | 000,046,706 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/05 16:30:37 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:11 | 000,010,635 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:43 | 000,016,284 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:47:34 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/05/05 12:40:37 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/05 12:40:34 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/05/05 07:48:09 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/05 07:48:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/05 07:48:09 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/05 07:48:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/05 07:48:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/04 19:00:01 | 000,003,444 | ---- | C] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/04/26 22:25:17 | 000,001,100 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/04/15 20:12:22 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/13 22:06:13 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/13 22:06:13 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/04/09 14:35:11 | 000,000,238 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2011/04/09 09:11:07 | 000,001,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/05 15:45:00 | 000,210,104 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/31 22:50:43 | 000,029,520 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/03/31 22:50:43 | 000,013,496 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/03/23 15:12:18 | 000,046,706 | ---- | C] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[2010/10/11 16:08:27 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\setupfilter.exe
[2010/10/11 16:08:26 | 000,073,728 | ---- | C] () -- C:\WINDOWS\VMInstNT.exe
[2010/10/11 16:08:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\VM303UninstNT.exe
[2010/10/11 16:08:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\VMPipe.dll
[2010/09/28 18:57:48 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 06:31:27 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2010/09/13 11:47:17 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\fusioncache.dat
[2010/08/20 20:22:46 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/07/13 21:34:38 | 000,000,162 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/06/08 07:10:17 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/04 18:08:23 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/06/03 16:08:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/07/23 06:28:41 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/07/23 06:28:06 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/06/27 20:04:38 | 000,005,312 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/06/27 15:53:45 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/06/27 14:17:15 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/06/27 14:17:15 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/06/27 14:17:15 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/06/27 14:17:15 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/06/27 13:40:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\INSTALLEEE.EXE
[2008/06/27 13:35:32 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hkcmd.exe
[2008/06/27 13:35:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxpers.exe
[2008/06/27 13:35:32 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2008/06/27 13:35:31 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\igfxtray.exe
[2008/06/27 13:30:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/06/27 13:26:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/06/27 13:13:14 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/06/27 13:13:13 | 000,470,094 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/06/27 13:13:13 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/06/27 13:13:13 | 000,081,454 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/06/27 13:13:13 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/06/27 13:13:13 | 000,004,562 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/06/27 13:13:12 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/06/27 13:13:12 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/06/27 13:13:10 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/06/27 13:13:10 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/06/27 13:13:08 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/06/27 13:13:06 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/06/27 06:20:40 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/06/27 06:19:44 | 000,361,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/15 04:58:40 | 002,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/03/20 21:58:30 | 000,000,173 | ---- | C] () -- C:\WINDOWS\explorer.exe.config
[2008/03/18 06:54:36 | 000,012,208 | ---- | C] () -- C:\WINDOWS\AsTrayLang.ini
[2003/12/05 17:55:36 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\EGameEncrypt.dll
[2003/09/23 20:14:42 | 001,099,264 | ---- | C] () -- C:\WINDOWS\System32\cygxml2-2.dll
[2003/09/15 16:24:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\EGamesPlugin.dll
[2003/08/10 22:59:20 | 000,980,992 | ---- | C] () -- C:\WINDOWS\System32\cygiconv-2.dll
[2003/08/09 08:28:16 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2002/03/17 08:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000011.DLL
[2001/11/15 04:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2010/12/20 02:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/06/27 06:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2011/05/05 07:36:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/20 03:49:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/14 20:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/07/23 06:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2011/04/12 14:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/03/31 22:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/05/05 07:35:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/07 06:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/09/17 06:26:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/08/21 16:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/04/18 15:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/05/05 07:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/21 19:59:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2010/10/11 12:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/12/20 13:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\AVG10
[2011/05/05 17:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 15:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\DMCache
[2011/04/04 07:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\fretsonfire
[2011/04/25 14:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\FrostWire
[2011/04/25 12:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\gtk-2.0
[2011/04/04 07:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\IDM
[2010/10/19 20:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\InterVideo
[2011/04/04 07:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\Kalydo
[2011/04/09 09:15:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/01/14 21:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\ReviverSoft
[2011/04/06 20:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\uTorrent
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE2D0492
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS
Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
PRC - [2011/05/05 06:32:44 | 001,004,544 | ---- | M] (Google Inc.) -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/05/04 20:27:25 | 000,382,704 | ---- | M] () -- C:\Program Files\cacaoweb\cacaoweb.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:42 | 000,226,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe
PRC - [2008/04/14 20:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (SafeList) ==========
MOD - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
MOD - [2010/08/24 00:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/26 23:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (gupdatem) Google Update Service (gupdatem)
SRV - File not found [Auto | Stopped] -- -- (gupdate) Google Update Service (gupdate)
SRV - [2011/05/04 06:10:37 | 003,274,328 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_3f211bc.dll -- (Akamai)
SRV - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/05/04 08:10:00 | 003,539,184 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) [Auto | Running] -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe -- (FortiSslvpnDaemon)
SRV - [2008/11/04 08:06:28 | 000,519,536 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 18:44:08 | 000,139,616 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006/10/26 14:03:08 | 000,227,104 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (asc3360pr)
DRV - [2011/05/05 16:30:38 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{850EBCBA-E9BC-4CD2-BD79-AA3D6F89E2CC}\MpKsld50583e0.sys -- (MpKsld50583e0)
DRV - [2011/02/23 17:04:30 | 000,013,496 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/08/26 19:57:00 | 000,025,616 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Kiel\Local Settings\Temp\WHR58.tmp -- (GarenaPEngine)
DRV - [2009/07/21 17:53:06 | 000,036,384 | ---- | M] (Fortinet Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pppop.sys -- (pppop)
DRV - [2008/09/26 18:01:00 | 000,101,376 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/16 18:52:00 | 004,747,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/04/15 11:14:02 | 000,990,632 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/04/15 11:13:58 | 000,534,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008/03/29 08:38:16 | 000,625,024 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2860.sys -- (RT80x86)
DRV - [2008/03/27 17:18:12 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/03/11 19:37:00 | 000,036,864 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2008/03/10 18:18:42 | 000,057,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2008/02/04 17:57:44 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2008/02/04 17:57:30 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2007/09/20 11:59:14 | 000,156,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007/07/27 11:00:38 | 000,011,264 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
DRV - [2006/12/01 14:23:58 | 000,392,122 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM303.sys -- (ZSMC303)
DRV - [2006/04/25 10:57:42 | 000,428,160 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vmfilter303.sys -- (vmfilter303)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "facebook.com"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:6.8.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.12
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/19 07:03:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 08:28:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/29 16:33:42 | 000,000,000 | ---D | M]
[2010/09/13 11:52:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Extensions
[2011/04/25 02:00:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions
[2011/03/28 13:48:35 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/04/18 15:09:33 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/03/28 13:48:37 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/05/04 12:01:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/18 17:15:24 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/18 03:16:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 12:44:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/10 05:34:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/12/19 07:03:08 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/09/18 17:04:35 | 000,000,000 | ---D | M] (IDM CC) -- C:\DOCUMENTS AND SETTINGS\KIEL XP\APPLICATION DATA\IDM\IDMMZCC3
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/12/17 12:43:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/08/16 17:42:02 | 000,070,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 17:42:12 | 000,091,448 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 17:42:08 | 000,020,800 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 08:41:08 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 08:41:08 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 08:41:08 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/08/16 17:44:46 | 000,427,312 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/08/16 17:42:04 | 000,023,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
O1 HOSTS File: ([2011/05/05 12:58:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cacaoweb] C:\Program Files\cacaoweb\cacaoweb.exe ()
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 124.106.4.2 124.106.5.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/05 15:48:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/05/05 15:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/05/05 15:31:48 | 000,000,000 | ---D | C] -- C:\_OTMoveIt
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\rsit
[2011/05/05 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\Malwarebytes
[2011/05/05 13:15:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/05 13:15:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/05/05 13:15:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/05 13:15:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/05 12:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 12:40:32 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/05 07:48:09 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/05 07:48:09 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/05 07:48:09 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/05 07:48:09 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/05 07:47:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/05 07:16:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/29 07:44:44 | 000,000,000 | ---D | C] -- C:\Downloads
[2011/04/25 12:24:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\My Documents\photo shop
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yazobo Games
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\Drag_Racer_v3
[2011/04/18 15:09:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/04/18 15:09:56 | 000,000,000 | ---D | C] -- C:\Program Files\cacaoweb
[2011/04/18 09:35:38 | 000,172,032 | ---- | C] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/18 06:05:41 | 000,000,000 | ---D | C] -- C:\Program Files\ProdigyRan
[2011/04/10 22:08:13 | 000,000,000 | ---D | C] -- C:\Program Files\Network Stumbler
[2011/04/09 14:25:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GameTop.com
[2011/04/09 14:25:38 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011/04/09 09:15:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/04/09 09:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Garena
[2011/04/09 09:01:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/04/09 09:00:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/04/08 10:26:00 | 000,000,000 | ---D | C] -- C:\FarmHelper
[2011/04/06 14:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2008/06/27 14:48:49 | 015,523,560 | ---- | C] (Macrovision Corporation) -- C:\Program Files\U1 Setup.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:07 | 000,010,635 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:38 | 000,016,284 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:46:55 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/05 15:34:08 | 000,000,439 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/05/05 15:34:03 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/05/05 15:34:03 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/05 15:34:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/05/05 15:34:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/05 15:34:01 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 15:34:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/05/05 15:34:01 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/05/05 15:33:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/05 15:09:06 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 12:58:02 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/05 12:40:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/05 05:46:23 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/04 22:30:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/05/04 19:00:01 | 000,003,444 | ---- | M] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/05/04 12:46:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/04 10:51:46 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/03 23:45:28 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/03 11:34:41 | 000,002,302 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\Google Chrome.lnk
[2011/05/03 11:34:41 | 000,002,280 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/03 10:22:54 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/02 07:08:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/04/30 10:43:26 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/29 15:11:32 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/26 15:17:33 | 000,000,238 | ---- | M] () -- C:\WINDOWS\mafosav.INI
[2011/04/22 09:50:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/04/18 15:28:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/18 09:35:38 | 000,172,032 | ---- | M] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/15 20:12:22 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/09 09:11:07 | 000,001,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/06 14:21:21 | 000,046,706 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/05 16:30:37 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:11 | 000,010,635 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:43 | 000,016,284 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:47:34 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/05/05 12:40:37 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/05 12:40:34 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/05/05 07:48:09 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/05 07:48:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/05 07:48:09 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/05 07:48:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/05 07:48:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/04 19:00:01 | 000,003,444 | ---- | C] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/04/26 22:25:17 | 000,001,100 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/04/15 20:12:22 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/13 22:06:13 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/13 22:06:13 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/04/09 14:35:11 | 000,000,238 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2011/04/09 09:11:07 | 000,001,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/05 15:45:00 | 000,210,104 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/31 22:50:43 | 000,029,520 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/03/31 22:50:43 | 000,013,496 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/03/23 15:12:18 | 000,046,706 | ---- | C] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[2010/10/11 16:08:27 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\setupfilter.exe
[2010/10/11 16:08:26 | 000,073,728 | ---- | C] () -- C:\WINDOWS\VMInstNT.exe
[2010/10/11 16:08:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\VM303UninstNT.exe
[2010/10/11 16:08:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\VMPipe.dll
[2010/09/28 18:57:48 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 06:31:27 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2010/09/13 11:47:17 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\fusioncache.dat
[2010/08/20 20:22:46 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/07/13 21:34:38 | 000,000,162 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/06/08 07:10:17 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/04 18:08:23 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/06/03 16:08:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/07/23 06:28:41 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/07/23 06:28:06 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/06/27 20:04:38 | 000,005,312 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/06/27 15:53:45 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/06/27 14:17:15 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/06/27 14:17:15 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/06/27 14:17:15 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/06/27 14:17:15 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/06/27 13:40:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\INSTALLEEE.EXE
[2008/06/27 13:35:32 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hkcmd.exe
[2008/06/27 13:35:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxpers.exe
[2008/06/27 13:35:32 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2008/06/27 13:35:31 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\igfxtray.exe
[2008/06/27 13:30:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/06/27 13:26:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/06/27 13:13:14 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/06/27 13:13:13 | 000,470,094 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/06/27 13:13:13 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/06/27 13:13:13 | 000,081,454 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/06/27 13:13:13 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/06/27 13:13:13 | 000,004,562 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/06/27 13:13:12 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/06/27 13:13:12 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/06/27 13:13:10 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/06/27 13:13:10 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/06/27 13:13:08 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/06/27 13:13:06 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/06/27 06:20:40 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/06/27 06:19:44 | 000,361,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/15 04:58:40 | 002,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/03/20 21:58:30 | 000,000,173 | ---- | C] () -- C:\WINDOWS\explorer.exe.config
[2008/03/18 06:54:36 | 000,012,208 | ---- | C] () -- C:\WINDOWS\AsTrayLang.ini
[2003/12/05 17:55:36 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\EGameEncrypt.dll
[2003/09/23 20:14:42 | 001,099,264 | ---- | C] () -- C:\WINDOWS\System32\cygxml2-2.dll
[2003/09/15 16:24:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\EGamesPlugin.dll
[2003/08/10 22:59:20 | 000,980,992 | ---- | C] () -- C:\WINDOWS\System32\cygiconv-2.dll
[2003/08/09 08:28:16 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2002/03/17 08:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000011.DLL
[2001/11/15 04:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2010/12/20 02:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/06/27 06:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2011/05/05 07:36:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/20 03:49:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/14 20:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/07/23 06:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2011/04/12 14:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/03/31 22:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/05/05 07:35:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/07 06:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/09/17 06:26:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/08/21 16:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/04/18 15:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/05/05 07:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/21 19:59:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2010/10/11 12:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/12/20 13:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\AVG10
[2011/05/05 17:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 15:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\DMCache
[2011/04/04 07:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\fretsonfire
[2011/04/25 14:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\FrostWire
[2011/04/25 12:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\gtk-2.0
[2011/04/04 07:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\IDM
[2010/10/19 20:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\InterVideo
[2011/04/04 07:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\Kalydo
[2011/04/09 09:15:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/01/14 21:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\ReviverSoft
[2011/04/06 20:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\uTorrent
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE2D0492
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
#3
Posted 05 May 2011 - 04:40 AM
OTL Extras logfile created on: 5/5/2011 6:10:13 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS
Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 ()
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster
"8370:TCP" = 8370:TCP:*:Enabled:League of Legends Launcher
"8370:UDP" = 8370:UDP:*:Enabled:League of Legends Launcher
"1037:TCP" = 1037:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:ipsec -- (Yahoo! Inc.)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- ()
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- ()
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- (FrostWire Group)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- ()
"D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe" = D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe:*:Enabled:League of Legends Game Client -- ()
"C:\Program Files\cacaoweb\cacaoweb.exe" = C:\Program Files\cacaoweb\cacaoweb.exe:*:Enabled:cacaoweb -- ()
"C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:ipsec -- (Google Inc.)
"C:\Program Files\Internet Download Manager\IDMan.exe" = C:\Program Files\Internet Download Manager\IDMan.exe:*:Enabled:ipsec -- ()
"C:\Program Files\EeePC\ACPI\AsEPCMon.exe" = C:\Program Files\EeePC\ACPI\AsEPCMon.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\Program Files\EeePC\ACPI\AsTray.exe" = C:\Program Files\EeePC\ACPI\AsTray.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe:*:Enabled:ipsec
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09040081-2C94-4A67-8E55-8483C019C7D2}" = Microsoft Encarta Premium 2009
"{0990B5DF-92C3-4AD6-A18D-BF3ADF311240}" = Super Hybrid Engine
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java 6 Update 24
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B39620B-F959-4C8A-AEEF-B5D29D8012D0}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8520 smartphone
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362483B1-91EB-4CB4-B9BB-3B4B4C644404}" = A4 TECH PC Camera H
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{67E321F8-2A04-44AB-8F28-A88A5F66732A}" = Battery Optimizer
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{85E3CFBC-9B1B-470C-AF72-54EACA0F1322}" = ECAP
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9510AB97-A36C-4352-8725-E72E5528FA1B}" = StarOffice 8 ASUS Edition
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34DCE59-0004-0000-2069-3F8A9926B752}" = FortiClient SSL VPN v4.0.2069
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AF2DE873-ECB3-4BF5-BA8D-6C61A0948DA5}" = SyQic Yoonic Engine - PLDT Watchpad
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{C7A8AA10-B632-42F8-9F57-A16FDCE0601E}" = Clock Screen Saver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DEB6ACEB-C418-4880-9133-1C5EB9AFBC79}" = Eee Storage
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AirAssault_is1" = Air Assault
"Akamai" = Akamai NetSession Interface
"ApecSoft AVI 3GP Joiner_is1" = AVI 3GP Joiner V2.20
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"CCleaner" = CCleaner
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"City Racing_is1" = City Racing
"DarkRO" = DarkRO
"Drag_Racer_v3_is1" = Drag_Racer_v3
"Egyptoball_is1" = Egyptoball
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"FishTales_is1" = Fish Tales ver 1.0
"Free FLV Player" = Free FLV Player
"FrostWire" = FrostWire 4.21.3
"Game Booster_is1" = Game Booster
"Global Downloader" = Global Downloader
"Globe Broadband" = Globe Broadband
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"im" = Garena Messenger
"Internet Download Manager" = Internet Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Motoracing_is1" = Motoracing
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"Offroad_Racers_is1" = Offroad Racers
"Picasa 3" = Picasa 3
"PRJPRO" = Microsoft Office Project Professional 2007
"Professional Registry Doctor_is1" = Professional Registry Doctor v6.2.6.4
"RealChess_is1" = Real Chess
"RealPlayer 12.0" = RealPlayer
"Smart Defrag 2_is1" = Smart Defrag 2
"Super Mario Forever_is1" = Super Mario Forever
"uneavset" = ESET NOD32 register program
"VISPRO" = Microsoft Office Visio Professional 2007
"VLC media player" = VLC media player 1.1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"7320d782fe34ae98" = fb_haCk
"Google Chrome" = Google Chrome
"KalydoPlayer" = Kalydo Player 3.10.04
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/3/2011 10:19:22 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = .NET Runtime | ID = 1023
Description = Application: chrome.exe CoreCLR Version: 4.0.60129.0 Description: The
process was terminated due to an internal error in the .NET Runtime at IP 7928D256
(79150000) with exit code 8013150a.
Error - 5/3/2011 10:19:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
coreclr.dll, version 4.0.60129.0, fault address 0x0013d256.
Error - 5/3/2011 11:44:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application fd1.exe, version 3.0.0.0, faulting module fd1.exe,
version 3.0.0.0, fault address 0x0000f640.
Error - 5/3/2011 10:52:31 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application yahoomessenger.exe, version 9.0.0.2162, faulting
module idmmbc.dll, version 5.18.2.0, fault address 0x0000d81b.
Error - 5/4/2011 8:26:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Chrome | ID = 1
Description =
Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).
Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 5/4/2011 4:38:24 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 5/5/2011 12:50:28 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved
Error - 5/5/2011 3:48:18 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = MPSampleSubmission | ID = 5000
Description =
[ OSession Events ]
Error - 1/4/2011 6:14:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/4/2011 6:29:45 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 901
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2/10/2011 3:31:06 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.
< End of report >
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS
Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 ()
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster
"8370:TCP" = 8370:TCP:*:Enabled:League of Legends Launcher
"8370:UDP" = 8370:UDP:*:Enabled:League of Legends Launcher
"1037:TCP" = 1037:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:ipsec -- (Yahoo! Inc.)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- ()
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- ()
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- (FrostWire Group)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- ()
"D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe" = D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe:*:Enabled:League of Legends Game Client -- ()
"C:\Program Files\cacaoweb\cacaoweb.exe" = C:\Program Files\cacaoweb\cacaoweb.exe:*:Enabled:cacaoweb -- ()
"C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:ipsec -- (Google Inc.)
"C:\Program Files\Internet Download Manager\IDMan.exe" = C:\Program Files\Internet Download Manager\IDMan.exe:*:Enabled:ipsec -- ()
"C:\Program Files\EeePC\ACPI\AsEPCMon.exe" = C:\Program Files\EeePC\ACPI\AsEPCMon.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\Program Files\EeePC\ACPI\AsTray.exe" = C:\Program Files\EeePC\ACPI\AsTray.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe:*:Enabled:ipsec
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09040081-2C94-4A67-8E55-8483C019C7D2}" = Microsoft Encarta Premium 2009
"{0990B5DF-92C3-4AD6-A18D-BF3ADF311240}" = Super Hybrid Engine
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java 6 Update 24
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B39620B-F959-4C8A-AEEF-B5D29D8012D0}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8520 smartphone
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362483B1-91EB-4CB4-B9BB-3B4B4C644404}" = A4 TECH PC Camera H
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{67E321F8-2A04-44AB-8F28-A88A5F66732A}" = Battery Optimizer
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{85E3CFBC-9B1B-470C-AF72-54EACA0F1322}" = ECAP
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9510AB97-A36C-4352-8725-E72E5528FA1B}" = StarOffice 8 ASUS Edition
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34DCE59-0004-0000-2069-3F8A9926B752}" = FortiClient SSL VPN v4.0.2069
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AF2DE873-ECB3-4BF5-BA8D-6C61A0948DA5}" = SyQic Yoonic Engine - PLDT Watchpad
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{C7A8AA10-B632-42F8-9F57-A16FDCE0601E}" = Clock Screen Saver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DEB6ACEB-C418-4880-9133-1C5EB9AFBC79}" = Eee Storage
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AirAssault_is1" = Air Assault
"Akamai" = Akamai NetSession Interface
"ApecSoft AVI 3GP Joiner_is1" = AVI 3GP Joiner V2.20
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"CCleaner" = CCleaner
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"City Racing_is1" = City Racing
"DarkRO" = DarkRO
"Drag_Racer_v3_is1" = Drag_Racer_v3
"Egyptoball_is1" = Egyptoball
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"FishTales_is1" = Fish Tales ver 1.0
"Free FLV Player" = Free FLV Player
"FrostWire" = FrostWire 4.21.3
"Game Booster_is1" = Game Booster
"Global Downloader" = Global Downloader
"Globe Broadband" = Globe Broadband
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"im" = Garena Messenger
"Internet Download Manager" = Internet Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Motoracing_is1" = Motoracing
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"Offroad_Racers_is1" = Offroad Racers
"Picasa 3" = Picasa 3
"PRJPRO" = Microsoft Office Project Professional 2007
"Professional Registry Doctor_is1" = Professional Registry Doctor v6.2.6.4
"RealChess_is1" = Real Chess
"RealPlayer 12.0" = RealPlayer
"Smart Defrag 2_is1" = Smart Defrag 2
"Super Mario Forever_is1" = Super Mario Forever
"uneavset" = ESET NOD32 register program
"VISPRO" = Microsoft Office Visio Professional 2007
"VLC media player" = VLC media player 1.1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"7320d782fe34ae98" = fb_haCk
"Google Chrome" = Google Chrome
"KalydoPlayer" = Kalydo Player 3.10.04
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/3/2011 10:19:22 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = .NET Runtime | ID = 1023
Description = Application: chrome.exe CoreCLR Version: 4.0.60129.0 Description: The
process was terminated due to an internal error in the .NET Runtime at IP 7928D256
(79150000) with exit code 8013150a.
Error - 5/3/2011 10:19:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
coreclr.dll, version 4.0.60129.0, fault address 0x0013d256.
Error - 5/3/2011 11:44:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application fd1.exe, version 3.0.0.0, faulting module fd1.exe,
version 3.0.0.0, fault address 0x0000f640.
Error - 5/3/2011 10:52:31 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application yahoomessenger.exe, version 9.0.0.2162, faulting
module idmmbc.dll, version 5.18.2.0, fault address 0x0000d81b.
Error - 5/4/2011 8:26:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Chrome | ID = 1
Description =
Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).
Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 5/4/2011 4:38:24 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.
Error - 5/5/2011 12:50:28 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved
Error - 5/5/2011 3:48:18 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = MPSampleSubmission | ID = 5000
Description =
[ OSession Events ]
Error - 1/4/2011 6:14:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.
Error - 1/4/2011 6:29:45 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 901
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2/10/2011 3:31:06 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.
< End of report >
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users