Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32/sality.au Win32/sality.am Win32/Pramfro.F Removal please :(


  • Please log in to reply

#1
Nikiel

Nikiel

    New Member

  • Member
  • Pip
  • 3 posts
To all those who are willing to help I usually having those 3 viruses. The win32/sality.AM win32/sality.AU and win32/Pramfro.F, I tried many anti - malware/ anti - virus programs already but i cant totally eliminate them all, they keep duplicating always which i got usually many threats of viruses in my laptop. My task manager is disabled because of that and i cant open picture files and many more. Wish you could help me fix this one. Thanks to all hope you could help me :]
  • 0

Advertisements


#2
Nikiel

Nikiel

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
OTL logfile created on: 5/5/2011 6:10:13 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS

Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
PRC - [2011/05/05 06:32:44 | 001,004,544 | ---- | M] (Google Inc.) -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/05/04 20:27:25 | 000,382,704 | ---- | M] () -- C:\Program Files\cacaoweb\cacaoweb.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:42 | 000,226,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe
PRC - [2008/04/14 20:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe


========== Modules (SafeList) ==========

MOD - [2011/05/05 18:09:41 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\kiel xP\My Documents\Downloads\OTL.exe
MOD - [2010/08/24 00:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/03/26 23:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (gupdatem) Google Update Service (gupdatem)
SRV - File not found [Auto | Stopped] -- -- (gupdate) Google Update Service (gupdate)
SRV - [2011/05/04 06:10:37 | 003,274,328 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_3f211bc.dll -- (Akamai)
SRV - [2010/11/11 12:26:40 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/05/04 08:10:00 | 003,539,184 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/08/13 12:38:48 | 000,703,080 | ---- | M] (Fortinet Inc.) [Auto | Running] -- C:\WINDOWS\system32\FortiSSLVPNdaemon.exe -- (FortiSslvpnDaemon)
SRV - [2008/11/04 08:06:28 | 000,519,536 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 18:44:08 | 000,139,616 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006/10/26 14:03:08 | 000,227,104 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (asc3360pr)
DRV - [2011/05/05 16:30:38 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{850EBCBA-E9BC-4CD2-BD79-AA3D6F89E2CC}\MpKsld50583e0.sys -- (MpKsld50583e0)
DRV - [2011/02/23 17:04:30 | 000,013,496 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | Disabled | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/08/26 19:57:00 | 000,025,616 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Kiel\Local Settings\Temp\WHR58.tmp -- (GarenaPEngine)
DRV - [2009/07/21 17:53:06 | 000,036,384 | ---- | M] (Fortinet Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pppop.sys -- (pppop)
DRV - [2008/09/26 18:01:00 | 000,101,376 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/16 18:52:00 | 004,747,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/04/15 11:14:02 | 000,990,632 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/04/15 11:13:58 | 000,534,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008/03/29 08:38:16 | 000,625,024 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2860.sys -- (RT80x86)
DRV - [2008/03/27 17:18:12 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/03/11 19:37:00 | 000,036,864 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2008/03/10 18:18:42 | 000,057,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2008/02/04 17:57:44 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2008/02/04 17:57:30 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2007/09/20 11:59:14 | 000,156,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007/07/27 11:00:38 | 000,011,264 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
DRV - [2006/12/01 14:23:58 | 000,392,122 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM303.sys -- (ZSMC303)
DRV - [2006/04/25 10:57:42 | 000,428,160 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vmfilter303.sys -- (vmfilter303)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "facebook.com"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:6.8.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1319
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.12

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/19 07:03:08 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 08:28:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/29 16:33:42 | 000,000,000 | ---D | M]

[2010/09/13 11:52:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Extensions
[2011/04/25 02:00:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions
[2011/03/28 13:48:35 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/04/18 15:09:33 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/03/28 13:48:37 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\kiel xP\Application Data\Mozilla\Firefox\Profiles\7km9nr2a.default\extensions\[email protected]
[2011/05/04 12:01:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/18 17:15:24 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/18 03:16:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 12:44:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/10 05:34:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/12/19 07:03:08 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/09/18 17:04:35 | 000,000,000 | ---D | M] (IDM CC) -- C:\DOCUMENTS AND SETTINGS\KIEL XP\APPLICATION DATA\IDM\IDMMZCC3
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/12/17 12:43:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/08/16 17:42:02 | 000,070,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 17:42:12 | 000,091,448 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 17:42:08 | 000,020,800 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 08:41:08 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 08:41:08 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 08:41:08 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/08/16 17:44:46 | 000,427,312 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/08/16 17:42:04 | 000,023,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll

O1 HOSTS File: ([2011/05/05 12:58:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [cacaoweb] C:\Program Files\cacaoweb\cacaoweb.exe ()
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\idmmbc.dll (Tonec Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 124.106.4.2 124.106.5.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\kiel xP\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/05 15:48:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/05/05 15:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/05/05 15:31:48 | 000,000,000 | ---D | C] -- C:\_OTMoveIt
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/05/05 15:13:25 | 000,000,000 | ---D | C] -- C:\rsit
[2011/05/05 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\Malwarebytes
[2011/05/05 13:15:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/05 13:15:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/05/05 13:15:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/05 13:15:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/05 12:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 12:40:32 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/05 07:48:09 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/05 07:48:09 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/05 07:48:09 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/05 07:48:09 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/05 07:47:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/05 07:16:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/29 07:44:44 | 000,000,000 | ---D | C] -- C:\Downloads
[2011/04/25 12:24:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\My Documents\photo shop
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Yazobo Games
[2011/04/18 20:50:35 | 000,000,000 | ---D | C] -- C:\Program Files\Drag_Racer_v3
[2011/04/18 15:09:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/04/18 15:09:56 | 000,000,000 | ---D | C] -- C:\Program Files\cacaoweb
[2011/04/18 09:35:38 | 000,172,032 | ---- | C] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/18 06:05:41 | 000,000,000 | ---D | C] -- C:\Program Files\ProdigyRan
[2011/04/10 22:08:13 | 000,000,000 | ---D | C] -- C:\Program Files\Network Stumbler
[2011/04/09 14:25:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GameTop.com
[2011/04/09 14:25:38 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011/04/09 09:15:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/04/09 09:02:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Garena
[2011/04/09 09:01:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs
[2011/04/09 09:00:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/04/08 10:26:00 | 000,000,000 | ---D | C] -- C:\FarmHelper
[2011/04/06 14:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2008/06/27 14:48:49 | 015,523,560 | ---- | C] (Macrovision Corporation) -- C:\Program Files\U1 Setup.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:07 | 000,010,635 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:38 | 000,016,284 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:46:55 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/05 15:34:08 | 000,000,439 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/05/05 15:34:03 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/05/05 15:34:03 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/05 15:34:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/05 15:34:02 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/05/05 15:34:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/05 15:34:01 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 15:34:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/05/05 15:34:01 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/05/05 15:33:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/05 15:09:06 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1013.job
[2011/05/05 12:58:02 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/05 12:40:37 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/05 05:46:23 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1006.job
[2011/05/04 22:30:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/05/04 19:00:01 | 000,003,444 | ---- | M] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/05/04 12:46:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1011.job
[2011/05/04 10:51:46 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1009.job
[2011/05/03 23:45:28 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1010.job
[2011/05/03 11:34:41 | 000,002,302 | ---- | M] () -- C:\Documents and Settings\kiel xP\Desktop\Google Chrome.lnk
[2011/05/03 11:34:41 | 000,002,280 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/03 10:22:54 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1007.job
[2011/05/02 07:08:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1012.job
[2011/04/30 10:43:26 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/29 15:11:32 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/26 15:17:33 | 000,000,238 | ---- | M] () -- C:\WINDOWS\mafosav.INI
[2011/04/22 09:50:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2292948040-2665897855-3867185372-1008.job
[2011/04/18 15:28:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/18 09:35:38 | 000,172,032 | ---- | M] (Jin Hui E-mail: [email protected] Web: http://www.jcomsoft.com) -- C:\WINDOWS\System32\AniGIF.ocx
[2011/04/15 20:12:22 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/09 09:11:07 | 000,001,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/06 14:21:21 | 000,046,706 | ---- | M] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/05 16:30:37 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011/05/05 16:29:11 | 000,010,635 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repo.jpg
[2011/05/05 16:27:43 | 000,016,284 | ---- | C] () -- C:\Documents and Settings\kiel xP\Desktop\repomen.png
[2011/05/05 15:53:25 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/05 15:49:23 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/05/05 15:47:34 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/05/05 12:40:37 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/05 12:40:34 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011/05/05 07:48:09 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/05 07:48:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/05 07:48:09 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/05 07:48:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/05 07:48:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/04 19:00:01 | 000,003,444 | ---- | C] () -- C:\Documents and Settings\kiel xP\.recently-used.xbel
[2011/04/26 22:25:17 | 000,001,100 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2292948040-2665897855-3867185372-1009Core.job
[2011/04/15 20:12:22 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/04/13 22:06:13 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/04/13 22:06:13 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/04/09 14:35:11 | 000,000,238 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2011/04/09 09:11:07 | 000,001,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\League of Legends.lnk
[2011/04/09 09:02:46 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Garena Messenger.lnk
[2011/04/05 15:45:00 | 000,210,104 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/31 22:50:43 | 000,029,520 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/03/31 22:50:43 | 000,013,496 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/03/23 15:12:18 | 000,046,706 | ---- | C] () -- C:\Documents and Settings\kiel xP\Application Data\room.dat
[2010/10/11 16:08:27 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\setupfilter.exe
[2010/10/11 16:08:26 | 000,073,728 | ---- | C] () -- C:\WINDOWS\VMInstNT.exe
[2010/10/11 16:08:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\VM303UninstNT.exe
[2010/10/11 16:08:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\VMPipe.dll
[2010/09/28 18:57:48 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 06:31:27 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2010/09/13 11:47:17 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\kiel xP\Local Settings\Application Data\fusioncache.dat
[2010/08/20 20:22:46 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/07/13 21:34:38 | 000,000,162 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/06/08 07:10:17 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/04 18:08:23 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/06/03 16:08:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/07/23 06:28:41 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/07/23 06:28:06 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2008/06/27 20:04:38 | 000,005,312 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/06/27 15:53:45 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/06/27 14:17:15 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/06/27 14:17:15 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/06/27 14:17:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/06/27 14:17:15 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/06/27 14:17:15 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/06/27 13:40:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\INSTALLEEE.EXE
[2008/06/27 13:35:32 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hkcmd.exe
[2008/06/27 13:35:32 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxpers.exe
[2008/06/27 13:35:32 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2008/06/27 13:35:31 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\igfxtray.exe
[2008/06/27 13:30:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/06/27 13:26:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/06/27 13:13:14 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/06/27 13:13:13 | 000,470,094 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/06/27 13:13:13 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/06/27 13:13:13 | 000,081,454 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/06/27 13:13:13 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/06/27 13:13:13 | 000,004,562 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/06/27 13:13:12 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/06/27 13:13:12 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/06/27 13:13:10 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/06/27 13:13:10 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/06/27 13:13:08 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/06/27 13:13:06 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/06/27 06:20:40 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/06/27 06:19:44 | 000,361,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/15 04:58:40 | 002,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/03/20 21:58:30 | 000,000,173 | ---- | C] () -- C:\WINDOWS\explorer.exe.config
[2008/03/18 06:54:36 | 000,012,208 | ---- | C] () -- C:\WINDOWS\AsTrayLang.ini
[2003/12/05 17:55:36 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\EGameEncrypt.dll
[2003/09/23 20:14:42 | 001,099,264 | ---- | C] () -- C:\WINDOWS\System32\cygxml2-2.dll
[2003/09/15 16:24:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\EGamesPlugin.dll
[2003/08/10 22:59:20 | 000,980,992 | ---- | C] () -- C:\WINDOWS\System32\cygiconv-2.dll
[2003/08/09 08:28:16 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2002/03/17 08:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000011.DLL
[2001/11/15 04:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2010/12/20 02:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/06/27 06:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2011/05/05 07:36:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/20 03:49:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/14 20:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/07/23 06:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2011/04/12 14:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2011/03/31 22:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/05/05 07:35:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/07 06:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/09/17 06:26:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/08/21 16:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/04/18 15:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Speedbit
[2011/05/05 07:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/21 19:59:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2010/10/11 12:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/12/20 13:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\AVG10
[2011/05/05 17:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\cacaoweb
[2011/05/05 15:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\DMCache
[2011/04/04 07:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\fretsonfire
[2011/04/25 14:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\FrostWire
[2011/04/25 12:37:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\gtk-2.0
[2011/04/04 07:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\IDM
[2010/10/19 20:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\InterVideo
[2011/04/04 07:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\Kalydo
[2011/04/09 09:15:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\LolClient
[2011/01/14 21:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\ReviverSoft
[2011/04/06 20:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\kiel xP\Application Data\uTorrent
[2011/05/05 15:34:03 | 000,000,252 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job
[2011/05/05 15:53:25 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/05/05 18:33:47 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job
[2011/05/05 15:34:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE2D0492
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >
  • 0

#3
Nikiel

Nikiel

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
OTL Extras logfile created on: 5/5/2011 6:10:13 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\kiel xP\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,015.00 Mb Total Physical Memory | 221.00 Mb Available Physical Memory | 22.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 23.42 Gb Free Space | 29.26% Space Free | Partition Type: NTFS
Drive D: | 69.00 Gb Total Space | 29.78 Gb Free Space | 43.16% Space Free | Partition Type: NTFS

Computer Name: YOUR-TAVG2LL8Q1 | User Name: kiel xP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Value error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 ()
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" ()
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"58589:TCP" = 58589:TCP:*:Enabled:Pando Media Booster
"58589:UDP" = 58589:UDP:*:Enabled:Pando Media Booster
"8370:TCP" = 8370:TCP:*:Enabled:League of Legends Launcher
"8370:UDP" = 8370:UDP:*:Enabled:League of Legends Launcher
"1037:TCP" = 1037:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:ipsec -- (Yahoo! Inc.)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- ()
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- ()
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- (FrostWire Group)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- ()
"D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe" = D:\Looool\Garena Messenger\Apps\lolph\Game\League of Legends.exe:*:Enabled:League of Legends Game Client -- ()
"C:\Program Files\cacaoweb\cacaoweb.exe" = C:\Program Files\cacaoweb\cacaoweb.exe:*:Enabled:cacaoweb -- ()
"C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\kiel xP\Local Settings\Application Data\Google\Chrome\Application\chrome.exe:*:Enabled:ipsec -- (Google Inc.)
"C:\Program Files\Internet Download Manager\IDMan.exe" = C:\Program Files\Internet Download Manager\IDMan.exe:*:Enabled:ipsec -- ()
"C:\Program Files\EeePC\ACPI\AsEPCMon.exe" = C:\Program Files\EeePC\ACPI\AsEPCMon.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\Program Files\EeePC\ACPI\AsTray.exe" = C:\Program Files\EeePC\ACPI\AsTray.exe:*:Enabled:ipsec -- (ASUSTeK Computer Inc.)
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\glga.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ejyxp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\gnyrdb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\tepke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\drgmih.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winxyfgab.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rleb.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjibdyr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\cejx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\isak.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\eqogvs.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\hvgvhx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winlmeraw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvfeqck.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\mpivix.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\rvcd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\abts.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winukuabe.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winbodjd.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsbfdo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkfaxx.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvqbwp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winmsgsto.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winsqgjy.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ptke.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\axmqsi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhrcpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winunuqq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winvccaco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\aeijsw.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uipo.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\kvjg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wintjdqlg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winkaib.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winughkr.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\facg.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winefngk.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\wingdyyq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\jtjcem.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winarud.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\evco.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\skbvm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winhjxjc.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\vtvcf.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winnpbhm.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winjgxjhp.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\uorwq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\winqhgpa.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ayqbpq.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\pemqoi.exe:*:Enabled:ipsec
"C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe" = C:\DOCUME~1\KIELXP~1\LOCALS~1\Temp\ebdh.exe:*:Enabled:ipsec


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09040081-2C94-4A67-8E55-8483C019C7D2}" = Microsoft Encarta Premium 2009
"{0990B5DF-92C3-4AD6-A18D-BF3ADF311240}" = Super Hybrid Engine
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 24
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B39620B-F959-4C8A-AEEF-B5D29D8012D0}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8520 smartphone
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{362483B1-91EB-4CB4-B9BB-3B4B4C644404}" = A4 TECH PC Camera H
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher
"{67E321F8-2A04-44AB-8F28-A88A5F66732A}" = Battery Optimizer
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{85E3CFBC-9B1B-470C-AF72-54EACA0F1322}" = ECAP
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9510AB97-A36C-4352-8725-E72E5528FA1B}" = StarOffice 8 ASUS Edition
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34DCE59-0004-0000-2069-3F8A9926B752}" = FortiClient SSL VPN v4.0.2069
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AEB9948B-4FF2-47C9-990E-47014492A0FE}" = MSXML 6.0 Parser
"{AF2DE873-ECB3-4BF5-BA8D-6C61A0948DA5}" = SyQic Yoonic Engine - PLDT Watchpad
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{C7A8AA10-B632-42F8-9F57-A16FDCE0601E}" = Clock Screen Saver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DEB6ACEB-C418-4880-9133-1C5EB9AFBC79}" = Eee Storage
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AirAssault_is1" = Air Assault
"Akamai" = Akamai NetSession Interface
"ApecSoft AVI 3GP Joiner_is1" = AVI 3GP Joiner V2.20
"BlackBerry_{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"CCleaner" = CCleaner
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"City Racing_is1" = City Racing
"DarkRO" = DarkRO
"Drag_Racer_v3_is1" = Drag_Racer_v3
"Egyptoball_is1" = Egyptoball
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"FishTales_is1" = Fish Tales ver 1.0
"Free FLV Player" = Free FLV Player
"FrostWire" = FrostWire 4.21.3
"Game Booster_is1" = Game Booster
"Global Downloader" = Global Downloader
"Globe Broadband" = Globe Broadband
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"im" = Garena Messenger
"Internet Download Manager" = Internet Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Motoracing_is1" = Motoracing
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"Offroad_Racers_is1" = Offroad Racers
"Picasa 3" = Picasa 3
"PRJPRO" = Microsoft Office Project Professional 2007
"Professional Registry Doctor_is1" = Professional Registry Doctor v6.2.6.4
"RealChess_is1" = Real Chess
"RealPlayer 12.0" = RealPlayer
"Smart Defrag 2_is1" = Smart Defrag 2
"Super Mario Forever_is1" = Super Mario Forever
"uneavset" = ESET NOD32 register program
"VISPRO" = Microsoft Office Visio Professional 2007
"VLC media player" = VLC media player 1.1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"7320d782fe34ae98" = fb_haCk
"Google Chrome" = Google Chrome
"KalydoPlayer" = Kalydo Player 3.10.04

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/3/2011 10:19:22 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = .NET Runtime | ID = 1023
Description = Application: chrome.exe CoreCLR Version: 4.0.60129.0 Description: The
process was terminated due to an internal error in the .NET Runtime at IP 7928D256
(79150000) with exit code 8013150a.

Error - 5/3/2011 10:19:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
coreclr.dll, version 4.0.60129.0, fault address 0x0013d256.

Error - 5/3/2011 11:44:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application fd1.exe, version 3.0.0.0, faulting module fd1.exe,
version 3.0.0.0, fault address 0x0000f640.

Error - 5/3/2011 10:52:31 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Application Error | ID = 1000
Description = Faulting application yahoomessenger.exe, version 9.0.0.2162, faulting
module idmmbc.dll, version 5.18.2.0, fault address 0x0000d81b.

Error - 5/4/2011 8:26:17 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Chrome | ID = 1
Description =

Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 5/4/2011 4:28:18 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 5/4/2011 4:38:24 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 5/5/2011 12:50:28 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/5/2011 3:48:18 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = MPSampleSubmission | ID = 5000
Description =

[ OSession Events ]
Error - 1/4/2011 6:14:23 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/4/2011 6:29:45 AM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 901
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2/10/2011 3:31:06 PM | Computer Name = YOUR-TAVG2LL8Q1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16
seconds with 0 seconds of active time. This session ended with a crash.


< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP