I believe I've been hijacked. Every so often, I try to access one website but am taken to another. This happens when I navigate to the page either directly or through a search engine like Google. I just had a problem with "Vista Security 2012." I downloaded a registry fix and was able to browse the internet again but I don't know if I completely fixed the problem. I ran Malwarebytes like I usually do and it says my system is clean. But my Firefox browser is still hijacked. I ran OTL and post the log here for your review. Many thanks for your time!
OTL Log:
OTL logfile created on: 12/17/2011 2:26:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Lawrence\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.64% Memory free
4.23 Gb Paging File | 2.31 Gb Available in Paging File | 54.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 16.09 Gb Free Space | 16.48% Space Free | Partition Type: NTFS
Drive D: | 51.39 Gb Total Space | 14.60 Gb Free Space | 28.41% Space Free | Partition Type: NTFS
Computer Name: LAWRENCE-PC | User Name: Lawrence | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/17 14:25:32 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Lawrence\Downloads\OTL.exe
PRC - [2011/12/16 06:54:17 | 000,508,928 | ---- | M] () -- C:\Windows\svcs.exe
PRC - [2011/11/08 22:59:53 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/09/24 18:56:11 | 000,273,528 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/08/23 20:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/08/19 01:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/12 12:18:42 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/07/28 15:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/06/15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2011/02/14 05:55:16 | 000,043,520 | R--- | M] () -- C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
PRC - [2011/01/26 22:55:56 | 000,393,216 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011/01/26 22:55:26 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011/01/20 01:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010/05/20 23:28:00 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/05/20 23:27:58 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/06/03 23:55:16 | 000,025,600 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\Ctxfihlp.exe
PRC - [2009/06/03 23:49:56 | 001,213,440 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CTxfispi.exe
PRC - [2009/04/10 22:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/02/23 10:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/01/18 23:33:19 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PING.EXE
PRC - [2005/03/09 19:50:18 | 000,018,944 | ---- | M] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\libusbd-nt.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/08 22:59:51 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/10/13 02:34:08 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll
MOD - [2011/10/13 02:34:00 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
MOD - [2011/10/13 02:33:48 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
MOD - [2011/10/13 02:32:18 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll
MOD - [2011/10/13 02:31:58 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
MOD - [2011/10/13 02:31:49 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
MOD - [2011/10/13 02:30:50 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/10/13 02:30:23 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/08/17 21:11:49 | 006,277,280 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/08/12 12:18:56 | 000,342,552 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 12:18:56 | 000,128,536 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 12:18:56 | 000,029,208 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 12:18:54 | 007,956,504 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 12:18:54 | 002,145,304 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/07/28 15:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 15:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/04 03:51:59 | 000,008,192 | ---- | M] () -- C:\Program Files\Java\jre6\bin\jp2native.dll
MOD - [2011/02/14 05:55:16 | 000,043,520 | R--- | M] () -- C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
MOD - [2011/01/26 22:12:00 | 000,023,040 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2010/07/06 20:26:46 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010/05/04 14:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2010/04/16 13:20:06 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2009/06/03 23:55:20 | 000,002,560 | ---- | M] () -- C:\Windows\CTXFIRES.DLL
MOD - [2009/04/10 22:28:22 | 000,223,232 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2009/04/10 22:28:22 | 000,223,232 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2009/03/26 14:46:42 | 000,148,480 | ---- | M] () -- C:\Windows\System32\APOMngr.DLL
========== Win32 Services (SafeList) ==========
SRV - [2011/12/16 06:54:17 | 000,508,928 | ---- | M] () [Auto | Running] -- C:\Windows\svcs.exe -- (NetworkLog)
SRV - [2011/11/09 17:47:46 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/08/19 01:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/04/27 14:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/01/26 22:55:26 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2010/08/04 13:15:41 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/02/23 10:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2005/03/09 19:50:18 | 000,018,944 | ---- | M] (http://libusb-win32.sourceforge.net) [Auto | Running] -- C:\Windows\System32\libusbd-nt.exe -- (libusbd)
========== Driver Services (SafeList) ==========
DRV - [2011/12/16 15:50:32 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{331F5D0B-A6DA-48B7-9C32-7E699FCF1966}\MpKsl8e432ab8.sys -- (MpKsl8e432ab8)
DRV - [2011/12/15 22:20:28 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{331F5D0B-A6DA-48B7-9C32-7E699FCF1966}\MpKsl7f412780.sys -- (MpKsl7f412780)
DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/08/19 01:26:50 | 004,334,624 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech QuickCam Pro 9000(UVC)
DRV - [2011/08/19 01:26:46 | 000,315,808 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2011/05/27 14:22:17 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/04/27 14:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/18 12:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2011/04/14 06:59:03 | 000,075,264 | ---- | M] () [File_System | Unknown | Running] -- C:\Windows\System32\drivers\dfsc.sys -- (DfsC)
DRV - [2011/01/26 23:36:16 | 007,566,848 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011/01/26 22:13:12 | 000,238,592 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010/05/06 01:21:36 | 000,105,488 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2010/03/22 02:04:40 | 000,262,176 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/06/04 01:48:12 | 001,177,624 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2009/06/04 01:48:00 | 000,095,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\emupia2k.sys -- (emupia)
DRV - [2009/06/04 01:47:50 | 000,158,744 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2009/06/04 01:47:42 | 000,014,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2009/06/04 01:47:34 | 000,130,072 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2009/06/04 01:47:24 | 000,347,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2009/06/04 01:47:14 | 000,526,232 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2009/06/04 01:47:06 | 000,511,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2009/06/04 01:46:56 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS)
DRV - [2009/06/04 01:46:56 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV - [2009/06/04 01:46:42 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS)
DRV - [2009/06/04 01:46:42 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV - [2009/06/04 01:46:34 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CT20XUT.SYS -- (CT20XUT.SYS)
DRV - [2009/06/04 01:46:34 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CT20XUT.sys -- (CT20XUT)
DRV - [2008/12/26 11:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vcsvad.sys -- (VCSVADHWSer) Avnex Virtual Audio Device (WDM)
DRV - [2008/01/18 06:43:16 | 000,016,128 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Lycosa.sys -- (LycoFltr)
DRV - [2005/03/09 19:50:16 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=15007
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\Search Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/08/10 21:48:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/24 18:56:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/23 17:42:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/23 17:42:01 | 000,000,000 | ---D | M]
[2010/09/25 12:12:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lawrence\AppData\Roaming\mozilla\Extensions
[2010/09/25 12:12:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lawrence\AppData\Roaming\mozilla\Extensions\[email protected]
[2011/10/12 22:56:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lawrence\AppData\Roaming\mozilla\Firefox\Profiles\oehiqy60.default\extensions
[2011/04/13 16:05:44 | 000,000,000 | ---D | M] (BlockSite) -- C:\Users\Lawrence\AppData\Roaming\mozilla\Firefox\Profiles\oehiqy60.default\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
[2011/11/08 22:59:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/09/24 18:56:48 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/11/08 22:59:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/06 11:07:58 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/08 22:59:53 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VMM Mode Selection] C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKCU..\Run: [{67660D82-8B53-D17F-473A-5B4D38BA2AE4}] C:\Users\Lawrence\AppData\Roaming\Yzadog\ukymemd.exe ()
O4 - HKCU..\Run: [Animated Wallpaper] C:\Users\Lawrence\Downloads\gray_storm_demo.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Impulse Now.lnk = File not found
O4 - Startup: C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
O4 - Startup: C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE6CDB5-71B4-4D45-A708-1332C0E8B3AD}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WBSrv: DllName - (C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll) - File not found
O22 - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - Deskscapes - C:\Program Files\Stardock\Object Desktop\DeskScapes3\deskscapes.dll (Stardock Corporation)
O22 - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - Stardock Vista ControlPanel Extension - C:\Program Files\Stardock\Object Desktop\DeskScapes\DesktopControlPanel.dll (Stardock)
O22 - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - StardockDreamController - C:\Program Files\Stardock\Object Desktop\DeskScapes\DreamControl.dll (Stardock)
O24 - Desktop WallPaper: C:\Users\Lawrence\AppData\Local\stardock\deskwall.bmp
O24 - Desktop BackupWallPaper: C:\Users\Lawrence\AppData\Local\stardock\deskwall.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 13:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{5ef86691-924a-11e0-a51b-6c626d4ca3bf}\Shell - "" = AutoRun
O33 - MountPoints2\{5ef86691-924a-11e0-a51b-6c626d4ca3bf}\Shell\AutoRun\command - "" = I:\TL-Bootstrap.exe
O33 - MountPoints2\{c07d90f3-ec9a-11e0-8ae3-6c626d4ca3bf}\Shell - "" = AutoRun
O33 - MountPoints2\{c07d90f3-ec9a-11e0-8ae3-6c626d4ca3bf}\Shell\AutoRun\command - "" = I:\TL-Bootstrap.exe
O33 - MountPoints2\{fea31454-a338-11df-8755-6c626d4ca3bf}\Shell\open\command - "" = F:\USER-368F2FDD2D\USER-368F2FDD2D\USER-368F2FDD2Dv12
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/13 07:16:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firestorm-Release
[2011/12/13 07:15:11 | 000,000,000 | ---D | C] -- C:\Program Files\Firestorm-Release
[2011/12/10 20:42:56 | 000,000,000 | ---D | C] -- C:\Users\Lawrence\Documents\FullReport.do_files
[2011/12/10 03:00:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/12/09 01:33:26 | 000,000,000 | ---D | C] -- C:\Users\Lawrence\AppData\Local\Logitech® Webcam Software
[2011/12/09 01:12:32 | 000,000,000 | ---D | C] -- C:\ProgramData\LogiShrd
[2011/12/09 01:11:17 | 000,000,000 | ---D | C] -- C:\Users\Lawrence\AppData\Roaming\Leadertech
[2011/12/09 01:08:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Logitech
[2011/12/09 01:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LWS
[2011/12/09 01:07:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2011/12/09 01:07:40 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2011/12/09 01:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2011/12/06 09:32:06 | 000,000,000 | ---D | C] -- C:\Users\Lawrence\Documents\loadUCPPage.do_files
[2011/11/23 17:41:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/11/23 17:41:32 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/11/23 17:38:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/23 17:36:45 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/11/23 17:36:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/11/23 17:31:40 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2009/06/03 23:57:38 | 000,060,928 | ---- | C] ( ) -- C:\Windows\System32\a3d.dll
[2009/06/03 23:32:54 | 000,012,800 | ---- | C] ( ) -- C:\Windows\System32\killapps.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/17 13:50:25 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/17 13:50:25 | 000,004,784 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/16 16:58:49 | 000,642,462 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/16 16:58:49 | 000,119,614 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/16 15:50:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/16 15:50:19 | 2146,689,024 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/16 15:49:49 | 161,407,053 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/12/16 06:54:17 | 000,508,928 | ---- | M] () -- C:\Windows\svcs.exe
[2011/12/15 22:04:57 | 000,054,760 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000000-00001102-00000005-00311102}.rfx
[2011/12/15 22:04:57 | 000,054,760 | ---- | M] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000000-00001102-00000005-00311102}.rfx
[2011/12/15 22:04:57 | 000,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000000-00001102-00000005-00311102}.rfx
[2011/12/15 21:56:36 | 000,000,930 | ---- | M] () -- C:\Users\Lawrence\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/12/15 21:56:36 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/15 21:48:30 | 000,207,872 | ---- | M] () -- C:\Users\Lawrence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/15 21:25:53 | 000,011,630 | -HS- | M] () -- C:\Users\Lawrence\AppData\Local\657405y0j711t125n073v2rlu0r2
[2011/12/15 21:25:53 | 000,011,630 | -HS- | M] () -- C:\ProgramData\657405y0j711t125n073v2rlu0r2
[2011/12/15 03:22:54 | 000,262,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/13 07:16:54 | 000,001,108 | ---- | M] () -- C:\Users\Public\Desktop\Firestorm-Release.lnk
[2011/12/12 09:26:54 | 000,000,913 | ---- | M] () -- C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2011/12/10 20:42:56 | 000,359,979 | ---- | M] () -- C:\Users\Lawrence\Documents\FullReport.do.htm
[2011/12/09 15:10:29 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/12/09 01:07:44 | 000,001,473 | ---- | M] () -- C:\Users\Public\Desktop\Logitech Webcam Software .lnk
[2011/12/06 09:32:51 | 000,012,924 | ---- | M] () -- C:\Users\Lawrence\Documents\loadUCPPage.do.pdf
[2011/12/06 09:32:09 | 000,012,812 | ---- | M] () -- C:\Users\Lawrence\Documents\loadUCPPage.do.htm
[2011/12/02 12:10:11 | 000,072,960 | ---- | M] () -- C:\Users\Lawrence\Desktop\Untitled 1.pdf
[2011/12/02 10:15:14 | 000,028,816 | ---- | M] () -- C:\Users\Lawrence\Documents\Untitled 1.odt
[2011/11/23 17:41:55 | 000,001,726 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/16 06:54:16 | 000,508,928 | ---- | C] () -- C:\Windows\svcs.exe
[2011/12/15 21:56:36 | 000,000,930 | ---- | C] () -- C:\Users\Lawrence\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/12/15 21:56:36 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/15 21:20:02 | 000,011,630 | -HS- | C] () -- C:\Users\Lawrence\AppData\Local\657405y0j711t125n073v2rlu0r2
[2011/12/15 21:20:02 | 000,011,630 | -HS- | C] () -- C:\ProgramData\657405y0j711t125n073v2rlu0r2
[2011/12/13 07:16:54 | 000,001,108 | ---- | C] () -- C:\Users\Public\Desktop\Firestorm-Release.lnk
[2011/12/12 17:02:05 | 161,407,053 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/12/12 09:26:54 | 000,000,913 | ---- | C] () -- C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2011/12/10 20:42:54 | 000,359,979 | ---- | C] () -- C:\Users\Lawrence\Documents\FullReport.do.htm
[2011/12/09 01:07:44 | 000,001,473 | ---- | C] () -- C:\Users\Public\Desktop\Logitech Webcam Software .lnk
[2011/12/06 09:32:50 | 000,012,924 | ---- | C] () -- C:\Users\Lawrence\Documents\loadUCPPage.do.pdf
[2011/12/06 09:32:05 | 000,012,812 | ---- | C] () -- C:\Users\Lawrence\Documents\loadUCPPage.do.htm
[2011/12/02 12:10:08 | 000,072,960 | ---- | C] () -- C:\Users\Lawrence\Desktop\Untitled 1.pdf
[2011/11/23 17:41:55 | 000,001,726 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/11/23 17:38:02 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/09/24 18:59:26 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/09/24 18:59:26 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/08/19 01:26:20 | 010,898,456 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011/08/19 01:26:20 | 000,336,408 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011/08/19 01:26:20 | 000,104,472 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011/08/12 12:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/25 22:48:54 | 000,028,418 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2011/06/18 13:08:21 | 000,040,960 | ---- | C] () -- C:\Windows\System32\ps3sixaxis_en.exe
[2011/06/18 13:05:46 | 000,033,792 | ---- | C] () -- C:\Windows\System32\drivers\libusb0.sys
[2011/06/15 15:04:52 | 000,075,264 | ---- | C] () -- C:\Windows\System32\drivers\dfsc.sys
[2011/04/18 10:26:07 | 000,012,858 | ---- | C] () -- C:\Windows\hpwscr14.dat
[2011/04/18 10:24:27 | 000,179,734 | ---- | C] () -- C:\Windows\hpwins14.dat
[2011/04/18 10:24:27 | 000,001,108 | ---- | C] () -- C:\Windows\hpwmdl14.dat
[2011/02/27 03:12:47 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/02/26 21:49:42 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/02/26 21:49:42 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/02/25 01:42:09 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/01/31 18:04:42 | 000,058,792 | ---- | C] () -- C:\Windows\System32\wbload.dll
[2010/12/21 02:27:22 | 000,003,113 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/12/17 16:00:46 | 000,227,587 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2010/09/11 12:20:33 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/08/19 08:30:40 | 000,020,436 | ---- | C] () -- C:\Windows\MSUMLT_U.INI
[2010/08/19 08:30:39 | 000,045,056 | ---- | C] () -- C:\Windows\System32\MSHRES_U.DLL
[2010/08/12 02:44:21 | 000,207,872 | ---- | C] () -- C:\Users\Lawrence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/04 14:06:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/08/04 13:15:04 | 000,148,480 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2010/08/04 13:15:04 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2010/08/04 12:38:57 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2010/08/04 11:59:26 | 000,000,680 | ---- | C] () -- C:\Users\Lawrence\AppData\Local\d3d9caps.dat
[2010/07/06 17:14:26 | 000,023,040 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2009/06/04 00:37:08 | 000,021,093 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2009/06/04 00:37:06 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2009/06/03 23:55:20 | 000,002,560 | ---- | C] () -- C:\Windows\System32\CtxfiRes.dll
[2009/06/03 23:55:20 | 000,002,560 | ---- | C] () -- C:\Windows\CTXFIRES.DLL
[2009/06/03 23:40:44 | 000,321,512 | ---- | C] () -- C:\Windows\System32\ctdlang.dat
[2009/06/03 23:40:44 | 000,056,509 | ---- | C] () -- C:\Windows\System32\ctdnlstr.dat
[2009/06/03 23:36:30 | 000,016,384 | ---- | C] () -- C:\Windows\System32\regplib.exe
[2009/06/03 23:33:04 | 000,007,680 | ---- | C] () -- C:\Windows\System32\enlocstr.exe
[2009/05/27 08:49:00 | 000,000,285 | ---- | C] () -- C:\Windows\System32\kill.ini
[2006/11/02 04:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 04:47:37 | 000,262,104 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 04:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:33:01 | 000,642,462 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 02:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 02:33:01 | 000,119,614 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 02:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 02:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 00:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 00:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/01 23:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/01 23:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2011/03/23 16:49:08 | 000,000,000 | -HSD | M] -- C:\Users\Lawrence\AppData\Roaming\.#
[2010/08/04 18:01:29 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\acccore
[2011/05/26 23:22:39 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Avnex
[2010/09/03 16:34:25 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Barnes & Noble
[2011/12/01 17:29:58 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\BitTorrent
[2010/09/06 14:13:54 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Canneverbe Limited
[2011/05/15 17:58:35 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/08/03 09:32:59 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\DAEMON Tools Lite
[2011/08/03 09:32:59 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\DAEMON Tools Pro
[2011/05/30 18:14:39 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Firestorm
[2011/10/18 03:13:39 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\fltk.org
[2010/09/26 11:16:55 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\GetRightToGo
[2011/10/04 00:54:32 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\gtk-2.0
[2011/06/29 17:02:45 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Imprudence
[2010/08/14 16:20:03 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Individual Software
[2011/10/12 22:57:42 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\InWorldz
[2011/12/09 01:11:17 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Leadertech
[2010/08/19 07:06:52 | 000,000,000 | -HSD | M] -- C:\Users\Lawrence\AppData\Roaming\lowsec
[2011/08/14 11:37:14 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\MH GED
[2011/12/17 14:30:11 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Mieq
[2011/06/03 14:29:34 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\musicjacker
[2010/08/14 16:29:28 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\OpenOffice.org
[2010/08/13 10:23:33 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Propellerhead Software
[2011/08/31 21:43:29 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\SecondLife
[2011/01/31 18:02:48 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Stardock
[2011/07/11 17:57:05 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\uPlayer
[2010/08/15 02:06:12 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\VirtuaWin
[2011/11/15 20:07:27 | 000,000,000 | ---D | M] -- C:\Users\Lawrence\AppData\Roaming\Yzadog
[2011/12/15 22:04:42 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 2158 bytes -> C:\Windows\System32\drivers\afzdbcea.sys:changelist
< End of report >
Extras:
OTL Extras logfile created on: 12/17/2011 2:26:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Lawrence\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.64% Memory free
4.23 Gb Paging File | 2.31 Gb Available in Paging File | 54.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 16.09 Gb Free Space | 16.48% Space Free | Partition Type: NTFS
Drive D: | 51.39 Gb Total Space | 14.60 Gb Free Space | 28.41% Space Free | Partition Type: NTFS
Computer Name: LAWRENCE-PC | User Name: Lawrence | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{8C6366BD-BCF8-4C78-BFB0-8A55FD02E546}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C0E159CC-0D57-4866-9FD9-56BB520706A9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FBAB7E9D-C1A8-4E7E-99A7-63EAC59A9C15}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0000ADA4-82F4-4AA8-AE49-921448989FFF}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{0A6DD4F8-A653-42BA-907C-7E79B426EF15}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{1C8A1EF5-C3FA-4D23-8DB8-C94151929EF9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\counterstrike source beta\hl2.exe |
"{21CFA925-8753-4F7C-90B9-0E5802871739}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\counterstrike source beta\hl2.exe |
"{22CC0896-E5E5-4446-B18E-7460DD2C32E0}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2FCE2A2A-BDD0-4884-A20D-AC407A03B40B}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{3967AF4F-9275-4333-80AE-A2020F2113A2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{408034A6-0CDB-450F-836C-BB93D8A818B6}" = protocol=6 | dir=in | app=c:\program files\barnes & noble\nookstudy\nookstudy.exe |
"{4C271AF1-A18C-4680-8E0C-AA493C7A122E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{51210A08-D2B6-4461-ABD2-2BA859F1F24E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress classic\hl.exe |
"{55391DB2-4650-407A-A6D6-805F1C59C138}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{5E28F352-B56C-4E02-BB84-7E4C434BA3A1}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\day of defeat source\hl2.exe |
"{6E8AA84B-4884-41CF-9D2B-4E5B935B8DDE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\grand theft auto san andreas\gta-sa.exe |
"{7EE56860-8595-4E2C-826E-CD18D2AD3136}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9E4CE849-03B0-4B72-B052-744B214610B1}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{A0B185BF-33C0-4539-AEE5-D13873351A95}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\day of defeat source\hl2.exe |
"{A2B9BDC3-8E15-487B-8797-EB5D4037477E}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{AF491A84-203E-44A7-AD1D-BB14AC24E8A9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\half-life\hl.exe |
"{B660E0F8-05AB-4C69-BE55-ACED870D97EF}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CD0E6ACE-D8AB-40E3-A04E-31303CB43D0C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\grand theft auto san andreas\gta-sa.exe |
"{D26033F9-B851-4187-A467-AEC9D133D7ED}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\half-life\hl.exe |
"{E5EC88E2-F387-4A68-84F0-F48E603F8A31}" = protocol=17 | dir=in | app=c:\program files\barnes & noble\nookstudy\nookstudy.exe |
"{F51696B5-3986-4295-AEE7-1F411510E704}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{F59F6BF5-CF70-4680-8BA7-961730F2D91F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress classic\hl.exe |
"{FBD35036-377D-49DB-AD0C-DBC35B546631}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FC1571BB-F3BE-45AE-9C5D-E2CB102D7B71}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{02DB324F-C308-4331-974F-F6BE692E80D4}C:\program files\secondlifeviewer2\slplugin.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slplugin.exe |
"TCP Query User{04F28D6D-D631-45EC-AD64-5569440557ED}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{05CE8715-0F97-4CE6-8035-FF156D8FC5E7}C:\program files\firestorm-beta-mesh\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\firestorm-beta-mesh\slvoice.exe |
"TCP Query User{090CA08A-0B53-4884-9A2C-010897A9B4A3}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{12D7075C-EB51-43DF-8B2E-108AFCDA42B2}C:\program files\firestorm-release\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\firestorm-release\slvoice.exe |
"TCP Query User{19BDD935-B2BE-4191-AA88-FB0D02A84A7D}C:\program files\firestorm-preview\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\firestorm-preview\slvoice.exe |
"TCP Query User{23C00775-7382-4759-A8D0-FA8AB094A1D6}E:\win32\launcher\dist\launch.exe" = protocol=6 | dir=in | app=e:\win32\launcher\dist\launch.exe |
"TCP Query User{2E085DEF-979C-46EF-8882-A180A25223C2}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{3322B553-C620-4533-9813-7C112FDAA9D6}C:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe |
"TCP Query User{3920A0E0-6A0E-4B8E-92BD-83FAABAC23F9}C:\users\lawrence\desktop\darklife 2\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\users\lawrence\desktop\darklife 2\secondlife\slvoice.exe |
"TCP Query User{3B318306-F89D-42CC-8E62-F93E7660450E}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{4C96BB9E-C13D-4299-BB98-62C37ACBF36A}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{5C20FDEB-2C5C-4463-921F-FDC349894870}C:\program files\steam\steamapps\respawnsodomy\half-life 2 deathmatch\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\half-life 2 deathmatch\hl2.exe |
"TCP Query User{76CBCB85-B252-488A-886C-D56C1011B55A}C:\users\lawrence\saved games\dark life\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\users\lawrence\saved games\dark life\secondlife\slvoice.exe |
"TCP Query User{801A9ACD-32E9-4B6F-B4C6-B3F8CCE09363}C:\program files\phoenix viewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\phoenix viewer\slvoice.exe |
"TCP Query User{8C4A110C-B7F8-4043-AAE0-0DE909DD6F84}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"TCP Query User{8EDCD710-90DE-434D-B412-C0C402F46E39}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{90C799BB-208D-4325-AFDF-8A6B9738A9FA}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"TCP Query User{958EAF10-BE67-490E-A877-A27210346C23}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"TCP Query User{9824A96A-5B78-4848-B241-892575400D96}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{A4A35F82-DF32-4B5D-803F-8BC04AD33400}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{B481D310-D5D0-4714-B4B0-73616EB019DE}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{B846EC43-7419-4C72-8C32-1F4901DD94CA}C:\program files\emerald viewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\emerald viewer\slvoice.exe |
"TCP Query User{B9D682FB-4FE2-44AD-84AC-F1B6885406F7}C:\program files\singularityviewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\singularityviewer\slvoice.exe |
"TCP Query User{BACDC3A8-3E61-469B-AC31-5D2C25E1CC8D}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"TCP Query User{C4772A0F-740A-4B38-A7C0-5818E74CE853}C:\program files\phoenix viewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\phoenix viewer\slvoice.exe |
"TCP Query User{C944CF21-55DC-4338-82BE-59F44CF6F2C7}C:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe |
"TCP Query User{D9865131-7C40-443D-842E-6D95F528F08E}C:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe |
"TCP Query User{DACE4FFF-0962-423A-9910-7F35C2491597}C:\program files\incognito\slvoice.exe" = protocol=6 | dir=in | app=c:\program files\incognito\slvoice.exe |
"TCP Query User{E26FC98F-96A4-4504-932E-BB6ADC1B5922}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"TCP Query User{E98FE8DF-09D5-49EC-AE18-4F1A1BD593B5}C:\program files\3dchat\client.exe" = protocol=6 | dir=in | app=c:\program files\3dchat\client.exe |
"TCP Query User{FDE83EE2-B8C9-4AA3-9BAF-6C1B49E08B34}C:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe |
"UDP Query User{1A6A67AE-2CD7-4590-94BD-B02C648CD4F8}C:\program files\singularityviewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\singularityviewer\slvoice.exe |
"UDP Query User{212B932A-1BBD-4322-8601-44D168B93599}C:\program files\phoenix viewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\phoenix viewer\slvoice.exe |
"UDP Query User{246B1DB1-0EBA-433C-A91C-576204726993}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{3D7CF850-BADC-48D5-AC83-66F78E73BB4F}C:\program files\phoenix viewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\phoenix viewer\slvoice.exe |
"UDP Query User{4FE8B33D-DCCC-4C95-A930-3831C9471376}C:\users\lawrence\saved games\dark life\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\users\lawrence\saved games\dark life\secondlife\slvoice.exe |
"UDP Query User{512D93D2-C6F1-4AA8-9861-300F84EB1188}C:\program files\3dchat\client.exe" = protocol=17 | dir=in | app=c:\program files\3dchat\client.exe |
"UDP Query User{521F585A-1EE7-4384-8630-B8C890235C51}C:\program files\incognito\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\incognito\slvoice.exe |
"UDP Query User{5341D996-DCE8-4E5E-81B6-3E49F27A490A}C:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe |
"UDP Query User{632D6624-5C73-4A8D-B70F-3A02D687973B}C:\program files\emerald viewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\emerald viewer\slvoice.exe |
"UDP Query User{646FD486-6A8D-4AAC-86FC-0D5CDA8EC8C4}C:\program files\firestorm-release\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\firestorm-release\slvoice.exe |
"UDP Query User{684F71AC-34D4-4C70-B140-85F1C887894B}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{717329D5-E5C3-4EF8-B8A0-074CF540983C}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{7422736D-E2D8-451E-90A4-37469314AEE2}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{750DB535-5B02-45DE-A07B-ED7D6A6E6FA0}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"UDP Query User{7982D860-0A0F-466B-936F-AC2E78F160F1}C:\program files\firestorm-beta-mesh\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\firestorm-beta-mesh\slvoice.exe |
"UDP Query User{7C7D79C8-A510-4FAE-982D-5F208CABD4AF}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{7E4DCC07-E6EE-40E6-B400-EBAF53E5AACA}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"UDP Query User{82D05BFA-0FFD-43C1-BC8C-AF241182332B}E:\win32\launcher\dist\launch.exe" = protocol=17 | dir=in | app=e:\win32\launcher\dist\launch.exe |
"UDP Query User{834EFCEE-B656-4AF4-9135-C9007E0990ED}C:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\source sdk base\hl2.exe |
"UDP Query User{85045E0B-AC65-4F31-A7F1-7230587A107B}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{870FC149-BC9A-4AE5-B803-D8E06730F6A9}C:\program files\secondlifeviewer2\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slvoice.exe |
"UDP Query User{A55E5BFC-DA1D-4E87-97BE-A9A679519DB9}C:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe |
"UDP Query User{A9F94606-745A-4B1E-B224-59E32413FED5}C:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\team fortress 2\hl2.exe |
"UDP Query User{AD85442D-7E38-40B3-8D92-428E6F9B7E4E}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"UDP Query User{BB2C3925-FE8B-4AF1-99CE-DBC6083BDF38}C:\users\lawrence\desktop\darklife 2\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\users\lawrence\desktop\darklife 2\secondlife\slvoice.exe |
"UDP Query User{C6004BB5-F788-455C-AEC6-489CCDBAE200}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{CA193461-FCE6-4DB9-B067-E7F0F1EB6E4F}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{D1B605BB-683B-4F09-9DCE-849009DAEA66}C:\program files\steam\steamapps\respawnsodomy\half-life 2 deathmatch\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\respawnsodomy\half-life 2 deathmatch\hl2.exe |
"UDP Query User{D57830F1-AD42-40B8-B3A3-D5D97468E62B}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{DC00B877-D8D3-46D7-A2FC-01900602A574}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{DEB00285-B9EF-4C03-830F-F1D4EDB9FBE5}C:\program files\firestorm-preview\slvoice.exe" = protocol=17 | dir=in | app=c:\program files\firestorm-preview\slvoice.exe |
"UDP Query User{FAD87EB3-3846-4C56-AB6F-4DCF57AACF38}C:\program files\secondlifeviewer2\slplugin.exe" = protocol=17 | dir=in | app=c:\program files\secondlifeviewer2\slplugin.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{0FEA9A38-B993-0969-3A78-4D5CDDACEFEE}" = ATI Catalyst Install Manager
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15262012-213A-4f65-9019-C8A409EC0156}" = HP Officejet J6400 Series
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{188C0E25-3D65-4DAC-9C00-7483FBA4C7EB}" = Status
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 26
"{26DB09BC-6EB5-4CE0-A05D-D4DECE60E189}_is1" = Phoenix Viewer 1.5.2.1102
"{279D3818-7287-4ab4-A927-542EBEA9E365}" = ProductContext
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31ECA0DA-4EE0-8C1E-484A-C304BAA9179A}" = Catalyst Control Center Graphics Previews Common
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{380CC749-8C28-4C74-BE01-45921D062302}" = BPDSoftware_Ini
"{3878A9A3-2448-7607-01EA-0DB9E31B7242}" = Catalyst Control Center Graphics Previews Vista
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{41853D20-40CC-4266-978D-F128BB97CA96}" = 6400_Help
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5BB4D7C1-52F2-4BFD-9E40-0D419E2E3021}" = bpd_scan
"{5D934326-165A-413b-B056-26BE1EC082AF}" = J6400
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{676981B7-A2D9-49D0-9F4C-03018F131DA9}" = DocProc
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{75670A63-A18E-5066-0A78-93F6865BA3AA}" = ccc-core-static
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77EC0035-AFBA-4A8C-814A-6A887224C1A1}" = DeskScapes
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{845FDC75-F31E-A75A-4300-593CAB195847}" = ccc-utility
"{85C8D391-0EAE-4492-8A0A-2EE8B0B6DA03}" = BPDSoftware
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{94FB5B63-A65F-7E5D-560D-A79FB29EA52F}" = Catalyst Control Center InstallProxy
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9699C9AA-8990-904D-FD1B-D931E437434D}" = CCC Help English
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA00898-9467-4689-9F40-DE7F58C8429C}" = Fax
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{E52BFE61-E0FF-11D6-9D69-00065BABCB42}" = Reason
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED8A2334-84CB-4AE0-80C5-7E26F9610AA0}_is1" = Incognito version Summer 2011
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F63A3F0E-BE83-43E4-A9A2-153E877A857C}" = McGraw-Hill's GED
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"Audacity_is1" = Audacity 1.2.6
"AudioCS" = Creative Audio Control Panel
"AV Voice Changer Software DIAMOND 7.0" = AV Voice Changer Software DIAMOND 7.0
"BitTorrent" = BitTorrent
"Blender" = Blender
"CCleaner" = CCleaner
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"DAEMON Tools Lite" = DAEMON Tools Lite
"DeskScapes" = DeskScapes
"DirectVobSub" = DirectVobSub (remove only)
"DivX Setup" = DivX Setup
"EAX Unified (SHELL)" = EAX Unified (SHELL)
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"Firestorm-Beta-Mesh" = Firestorm-Beta-Mesh (remove only)
"Firestorm-Preview" = Firestorm-Preview (remove only)
"Firestorm-Release" = Firestorm-Release (remove only)
"GoldWave v5.24" = GoldWave v5.24
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"HTC_WModemDriver" = WModem Driver Installer
"IconPackager" = IconPackager
"InstallShield_{F63A3F0E-BE83-43E4-A9A2-153E877A857C}" = McGraw-Hill's GED
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.3.9 (Basic)
"KONICA MINOLTA magicolor 2430DL" = KONICA MINOLTA magicolor 2430DL
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"MKV Player_is1" = MKV Player 2.0
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"NOOK Study" = NOOK Study
"OpenAL" = OpenAL
"RealPlayer 12.0" = RealPlayer
"Reason4_is1" = Reason 4.0
"ResumeMaker" = ResumeMaker
"Search Toolbar" = Search Toolbar
"Shop for HP Supplies" = Shop for HP Supplies
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 12120" = Grand Theft Auto: San Andreas
"Steam App 215" = Source SDK Base 2006
"Steam App 260" = Counter-Strike: Source Beta
"VirtuaWin_is1" = VirtuaWin v4.2
"VTFEdit_is1" = VTFEdit 1.2.5
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 beta 5 (32-bit)
"Xvid Video Codec 1.3.1" = Xvid Video Codec
"Yahoo! Messenger" = Yahoo! Messenger
"YTdetect" = Yahoo! Detect
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"WinDirStat" = WinDirStat 1.1.2
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/17/2011 4:05:39 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x2940, application
start time 0x01ccbcf6809ae6bd.
Error - 12/17/2011 4:10:56 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x2a64, application
start time 0x01ccbcf76530a2a4.
Error - 12/17/2011 4:15:59 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x1ec4, application
start time 0x01ccbcf82299304a.
Error - 12/17/2011 4:58:05 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x2ae8, application
start time 0x01ccbcfdde9af1d4.
Error - 12/17/2011 5:36:22 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x23b0, application
start time 0x01ccbd03c3700114.
Error - 12/17/2011 5:55:45 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0xe6c, application
start time 0x01ccbd06623e88ef.
Error - 12/17/2011 6:01:01 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0xadc, application
start time 0x01ccbd06c6ff1795.
Error - 12/17/2011 6:07:00 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x15b4, application
start time 0x01ccbd07f7ecd512.
Error - 12/17/2011 6:16:51 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x2540, application
start time 0x01ccbd08b165fb8b.
Error - 12/17/2011 6:23:52 PM | Computer Name = Lawrence-PC | Source = Application Error | ID = 1000
Description = Faulting application ping.exe, version 6.0.6001.18000, time stamp
0x47919130, faulting module SHLWAPI.dll, version 6.0.6002.18393, time stamp 0x4d39b5cc,
exception code 0xc0000005, fault offset 0x0001e7bf, process id 0x10fc, application
start time 0x01ccbd09bf12f710.
[ System Events ]
Error - 12/16/2011 2:21:11 AM | Computer Name = Lawrence-PC | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%835 Error Code: 0x80004005 Error description: Unspecified error Reason: %%858
Error - 12/16/2011 2:21:11 AM | Computer Name = Lawrence-PC | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%886 Error Code: 0x8007042c Error description: The dependency service or group failed
to start. Reason: %%892
Error - 12/16/2011 10:54:18 AM | Computer Name = Lawrence-PC | Source = Service Control Manager | ID = 7030
Description =
Error - 12/16/2011 7:50:22 PM | Computer Name = Lawrence-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:43:58 PM on 12/16/2011 was unexpected.
Error - 12/16/2011 7:51:38 PM | Computer Name = Lawrence-PC | Source = Service Control Manager | ID = 7023
Description =
Error - 12/16/2011 7:51:38 PM | Computer Name = Lawrence-PC | Source = Service Control Manager | ID = 7003
Description =
Error - 12/16/2011 7:51:38 PM | Computer Name = Lawrence-PC | Source = Service Control Manager | ID = 7003
Description =
Error - 12/16/2011 7:52:02 PM | Computer Name = Lawrence-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 12/16/2011 7:52:21 PM | Computer Name = Lawrence-PC | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%835 Error Code: 0x80004005 Error description: Unspecified error Reason: %%842
Error - 12/16/2011 7:52:21 PM | Computer Name = Lawrence-PC | Source = Microsoft Antimalware | ID = 3002
Description = %%860 Real-Time Protection feature has encountered an error and failed.
Feature:
%%886 Error Code: 0x8007042c Error description: The dependency service or group failed
to start. Reason: %%892
< End of report >