What is the name and location of the file found by your antivirus?
The filename and location is, scvhost.exe and c:\windows\system\, respectively. And I believe there is a tracking cookie involved with it, cause when Symantec brings up the Bloodhound thing, it also brings up that to each time.
aswMBR log:aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-29 13:46:41
-----------------------------
13:46:41.182 OS Version: Windows 6.0.6002 Service Pack 2
13:46:41.182 Number of processors: 2 586 0xE0C
13:46:41.182 ComputerName: DEVONASA-PC UserName: Devonasa
13:46:50.216 Initialize success
13:47:15.915 AVAST engine defs: 11122900
13:48:01.104 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2
13:48:01.104 Disk 0 Vendor: WDC_WD1200BEVS-00UST0 01.01A01 Size: 114473MB BusType: 3
13:48:03.445 Disk 0 MBR read successfully
13:48:03.445 Disk 0 MBR scan
13:48:04.194 Disk 0 Windows VISTA default MBR code
13:48:04.475 Disk 0 scanning sectors +234436608
13:48:05.145 Disk 0 scanning C:\Windows\system32\drivers
13:49:23.884 Service scanning
13:49:48.665 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
13:49:48.781 Service SysPlant C:\Windows\SYSTEM32\Drivers\SysPlant.sys **LOCKED** 32
13:49:48.915 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
13:49:49.226 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
13:49:49.227 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
13:49:49.863 Modules scanning
13:50:33.401 Disk 0 trace - called modules:
13:50:33.432 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x83d5a1e8]<<
13:50:33.433 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84e88780]
13:50:33.434 3 CLASSPNP.SYS[86da88b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-2[0x84761b98]
13:50:33.435 \Driver\atapi[0x84700130] -> IRP_MJ_CREATE -> 0x83d5a1e8
13:50:37.297 AVAST engine scan C:\Windows
13:50:51.544 AVAST engine scan C:\Windows\system32
13:57:29.627 File: C:\Windows\system32\vmusbw32.dll **INFECTED** Win32:Delf-RFE [Trj]
13:58:08.766 AVAST engine scan C:\Windows\system32\drivers
13:58:39.029 AVAST engine scan C:\Users\Devonasa
14:29:41.243 AVAST engine scan C:\ProgramData
14:35:38.202 Scan finished successfully
15:52:31.953 Disk 0 MBR has been saved successfully to "C:\Users\Devonasa\Desktop\MBR.dat"
15:52:31.978 The log file has been saved successfully to "C:\Users\Devonasa\Desktop\aswMBR.txt"
combofix log:ComboFix 11-12-29.04 - Devonasa 12/29/2011 16:03:55.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1013.222 [GMT -5:00]
Running from: c:\users\Devonasa\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files\somototoolbar\vmNTemplatex.dll
c:\users\Devonasa\AppData\Roaming\Adobe\plugs
c:\users\Devonasa\AppData\Roaming\Adobe\shed
c:\users\Devonasa\Documents\~WRL0257.tmp
c:\users\Devonasa\Documents\~WRL0559.tmp
c:\users\Devonasa\Documents\~WRL0614.tmp
c:\users\Devonasa\Documents\~WRL0956.tmp
c:\users\Devonasa\Documents\~WRL1108.tmp
c:\users\Devonasa\Documents\~WRL1173.tmp
c:\users\Devonasa\Documents\~WRL1597.tmp
c:\users\Devonasa\Documents\~WRL1629.tmp
c:\users\Devonasa\Documents\~WRL1696.tmp
c:\users\Devonasa\Documents\~WRL1895.tmp
c:\users\Devonasa\Documents\~WRL2030.tmp
c:\users\Devonasa\Documents\~WRL2387.tmp
c:\users\Devonasa\Documents\~WRL2419.tmp
c:\users\Devonasa\Documents\~WRL2439.tmp
c:\users\Devonasa\Documents\~WRL2528.tmp
c:\users\Devonasa\Documents\~WRL2680.tmp
c:\users\Devonasa\Documents\~WRL2860.tmp
c:\users\Devonasa\Documents\~WRL2914.tmp
c:\users\Devonasa\Documents\~WRL2947.tmp
c:\users\Devonasa\Documents\~WRL2965.tmp
c:\users\Devonasa\Documents\~WRL3043.tmp
c:\users\Devonasa\Documents\~WRL3132.tmp
c:\users\Devonasa\Documents\~WRL3264.tmp
c:\users\Devonasa\Documents\~WRL3298.tmp
c:\users\Devonasa\Documents\~WRL3439.tmp
c:\users\Devonasa\Documents\~WRL3737.tmp
c:\users\Devonasa\Documents\~WRL3783.tmp
c:\users\Devonasa\Documents\~WRL3872.tmp
c:\users\Devonasa\Documents\~WRL4012.tmp
c:\users\Devonasa\videos\bitdefender_is_2012_32b.exe
c:\users\Devonasa\videos\DTLite4451-0236.exe
c:\users\Devonasa\videos\hjsplit.exe
c:\users\Devonasa\videos\OTL.exe
c:\users\Devonasa\videos\W7-SimTracker_Setup.exe
c:\windows\system\msvcr71.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\winservices
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_itlperf
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))
.
.
2011-12-29 21:15 . 2011-12-29 21:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-26 06:05 . 2011-12-29 21:23 16896 ----a-w- c:\windows\system\svchost.exe
2011-12-25 20:51 . 2011-12-25 20:51 -------- d-----w- C:\Sim0
2011-12-25 20:51 . 2011-12-25 20:51 858 ----a-w- C:\HH0_HouseData.bin
2011-12-25 20:50 . 2011-12-25 20:50 -------- d-----w- C:\RLMsoft
2011-12-25 20:50 . 2011-12-25 20:50 -------- d-----w- c:\program files\RLMsoft
2011-12-21 05:25 . 2011-12-21 05:25 -------- d-----w- c:\users\Devonasa\AppData\Roaming\GamesCafe
2011-12-20 21:49 . 2011-12-21 05:17 -------- d-----w- c:\users\Devonasa\AppData\Roaming\Atari
2011-12-20 21:32 . 2011-12-20 21:32 -------- d-----w- c:\users\Devonasa\AppData\Roaming\Leadertech
2011-12-20 20:58 . 2011-12-20 20:58 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-12-20 20:58 . 2011-12-21 05:00 -------- d-----w- c:\users\Devonasa\AppData\Roaming\DAEMON Tools Lite
2011-12-18 06:54 . 2011-12-18 06:54 -------- d-----w- c:\users\Devonasa\AppData\Roaming\GOL_byHasbro
2011-12-15 01:12 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-15 01:12 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 01:12 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-15 01:12 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-15 01:12 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-15 01:12 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 01:10 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 01:00 . 2011-11-03 06:22 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-15 01:00 . 2011-11-03 06:17 743424 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2011-12-08 19:59 . 2011-12-08 20:07 -------- d-----w- c:\users\Devonasa\AppData\Roaming\SoMud
2011-12-08 19:58 . 2011-12-29 21:14 -------- d-----w- c:\program files\somototoolbar
2011-12-08 19:57 . 2011-12-08 19:59 -------- d-----w- c:\program files\SoMud FileBulldog Toolbar
2011-12-08 19:54 . 2011-12-08 19:54 -------- d-----w- c:\program files\AP Suggestor
2011-12-08 19:53 . 2011-12-08 19:58 -------- d-----w- c:\program files\SoMud
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-20 21:00 . 2010-01-31 02:11 428088 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-11-24 03:04 . 2011-10-25 04:02 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 01:49 . 2011-11-04 01:49 161792 ----a-w- c:\windows\system32\vmusbw32.dll
2011-11-24 03:08 . 2011-09-08 18:10 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D0984FD4-FA9A-46ee-9072-70B0735FF852}]
2011-11-10 21:42 167216 ----a-w- c:\program files\AP Suggestor\APSuggestor.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-15 04:46 195360 ------w- c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-21 39408]
"SoMud"="c:\program files\SoMud\somud.exe" [2011-11-16 4062720]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 284184]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-11-16 746520]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-16 244512]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-11-02 8704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10d.exe" [2009-11-03 257440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SafeConnect.lnk - c:\program files\SafeConnect\scClient.exe [2009-3-31 296088]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2010-10-29 612168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 135664]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2009-07-14 23888]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run [x]
S2 SCManager;SafeConnect Manager;c:\program files\SafeConnect\scManager.sys servicestart [x]
S2 SymAFR;SymAFR;c:\windows\system32\DRIVERS\SymAFR.sys [2011-03-22 15408]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-08 106104]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2009-06-10 347648]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
vmwareusb REG_MULTI_SZ vmusb
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 00:03]
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 00:03]
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1663229470-2338449591-2720500769-1000Core.job
- c:\users\Devonasa\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-05 02:19]
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1663229470-2338449591-2720500769-1000UA.job
- c:\users\Devonasa\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-05 02:19]
.
2011-12-29 c:\windows\Tasks\User_Feed_Synchronization-{8ED58AD3-8ABB-401C-95E3-4D53772E5585}.job
- c:\windows\system32\msfeedssync.exe [2011-12-15 04:44]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
IE: Download Web &Images with SoMud - c:\program files\SoMud\scripts\ie\images-url.html
IE: Download with SoMud - c:\program files\SoMud\scripts\ie\link-url.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{02E2473F-766B-4ce2-8FD0-C4E8071EF1C4} - {D0984FD4-FA9A-46ee-9072-70B0735FF852} - c:\program files\AP Suggestor\APSuggestor.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-AdobeBridge - (no file)
HKCU-Run-ares - c:\program files\Ares\Ares.exe
SafeBoot-Symantec Antvirus
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(12060)
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\hasplms.exe
c:\program files\SafeConnect\scManager.sys
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\system\svchost.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2011-12-29 16:38:16 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-29 21:36
.
Pre-Run: 27,785,457,664 bytes free
Post-Run: 28,756,049,920 bytes free
.
- - End Of File - - EF47C7646D27CB8FA652912E6EA34DB4
OTLlog.txtOTL logfile created on: 12/29/2011 5:13:50 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Devonasa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.38 Mb Total Physical Memory | 79.21 Mb Available Physical Memory | 7.82% Memory free
2.24 Gb Paging File | 1.20 Gb Available in Paging File | 53.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 101.64 Gb Total Space | 26.97 Gb Free Space | 26.53% Space Free | Partition Type: NTFS
Drive D: | 10.15 Gb Total Space | 0.09 Gb Free Space | 0.89% Space Free | Partition Type: NTFS
Computer Name: DEVONASA-PC | User Name: Devonasa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/12/29 17:12:54 | 000,016,896 | ---- | M] () -- C:\Windows\system\svchost.exe
PRC - [2011/12/29 17:02:34 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Devonasa\Desktop\OTL.exe
PRC - [2011/11/23 22:08:18 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/11/15 20:49:32 | 004,062,720 | ---- | M] () -- C:\Program Files\SoMud\somud.exe
PRC - [2011/11/10 04:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2011/09/26 12:34:16 | 000,296,088 | ---- | M] (Impulse Point, LLC) -- C:\Program Files\SafeConnect\SCClient.exe
PRC - [2011/09/26 12:34:08 | 000,175,968 | ---- | M] (Impulse Point, LLC) -- C:\Program Files\SafeConnect\scManager.sys
PRC - [2011/07/28 18:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/10/29 14:00:00 | 000,612,168 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2009/12/16 15:44:36 | 003,750,400 | ---- | M] (SafeNet Inc.) -- C:\Windows\System32\hasplms.exe
PRC - [2009/09/17 17:56:58 | 002,477,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2009/09/17 17:38:02 | 001,864,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2009/09/17 17:27:26 | 001,455,432 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/07/08 19:14:40 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2009/07/08 19:14:20 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2006/11/15 21:03:36 | 000,109,344 | ---- | M] (Logitech Inc.) -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
PRC - [2006/11/15 21:01:52 | 000,244,512 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
PRC - [2006/11/15 20:58:40 | 000,746,520 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
PRC - [2006/11/15 20:57:20 | 000,171,544 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2006/10/31 00:03:48 | 000,284,184 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
========== Modules (No Company Name) ========== MOD - [2011/11/23 22:08:13 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/11/15 20:49:32 | 004,062,720 | ---- | M] () -- C:\Program Files\SoMud\somud.exe
MOD - [2011/10/07 21:40:40 | 000,028,672 | ---- | M] () -- C:\Program Files\SoMud\imageformats\qico4.dll
MOD - [2011/10/07 21:40:38 | 000,284,672 | ---- | M] () -- C:\Program Files\SoMud\imageformats\qtiff4.dll
MOD - [2011/10/07 21:40:30 | 000,220,672 | ---- | M] () -- C:\Program Files\SoMud\imageformats\qmng4.dll
MOD - [2011/10/07 21:40:24 | 000,026,624 | ---- | M] () -- C:\Program Files\SoMud\imageformats\qgif4.dll
MOD - [2011/10/07 21:40:20 | 000,196,608 | ---- | M] () -- C:\Program Files\SoMud\imageformats\qjpeg4.dll
MOD - [2011/10/07 21:40:14 | 000,077,824 | ---- | M] () -- C:\Program Files\SoMud\codecs\qkrcodecs4.dll
MOD - [2011/10/07 21:40:12 | 000,155,136 | ---- | M] () -- C:\Program Files\SoMud\codecs\qtwcodecs4.dll
MOD - [2011/10/07 21:40:10 | 000,167,936 | ---- | M] () -- C:\Program Files\SoMud\codecs\qjpcodecs4.dll
MOD - [2011/10/07 21:40:08 | 000,141,824 | ---- | M] () -- C:\Program Files\SoMud\codecs\qcncodecs4.dll
MOD - [2011/10/07 21:38:12 | 010,862,592 | ---- | M] () -- C:\Program Files\SoMud\QtWebKit4.dll
MOD - [2011/10/07 20:33:36 | 001,294,848 | ---- | M] () -- C:\Program Files\SoMud\QtScript4.dll
MOD - [2011/10/07 20:26:54 | 000,266,752 | ---- | M] () -- C:\Program Files\SoMud\phonon4.dll
MOD - [2011/10/07 20:20:28 | 008,222,720 | ---- | M] () -- C:\Program Files\SoMud\QtGui4.dll
MOD - [2011/10/07 20:11:46 | 000,975,360 | ---- | M] () -- C:\Program Files\SoMud\QtNetwork4.dll
MOD - [2011/10/07 20:10:38 | 002,292,224 | ---- | M] () -- C:\Program Files\SoMud\QtCore4.dll
MOD - [2011/07/28 18:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 18:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2009/11/03 18:51:42 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2006/11/15 21:01:08 | 001,058,328 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\LAppRes.DLL
MOD - [2006/11/15 20:58:40 | 000,746,520 | ---- | M] () -- C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
MOD - [2006/11/02 04:46:05 | 000,061,440 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll
MOD - [2006/10/31 00:04:12 | 000,022,040 | ---- | M] () -- C:\Program Files\Common Files\Logitech\LComMgr\LCMServerPS.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (RoxLiveShare9)
SRV - [2011/11/03 20:49:14 | 000,161,792 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Windows\System32\vmusbw32.dll -- (vmusb)
SRV - [2011/09/26 12:34:08 | 000,175,968 | ---- | M] (Impulse Point, LLC) [Auto | Running] -- C:\Program Files\SafeConnect\scManager.sys -- (SCManager)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/05 00:31:56 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/12/16 15:44:36 | 003,750,400 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\Windows\System32\hasplms.exe -- (hasplms)
SRV - [2009/09/17 17:56:58 | 002,477,304 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2009/09/17 17:38:02 | 001,864,888 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/09/17 16:21:10 | 000,341,320 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/07/13 11:06:15 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2009/07/08 19:14:20 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/07/08 19:14:20 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2006/11/15 21:05:40 | 000,101,152 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2006/11/15 21:03:36 | 000,109,344 | ---- | M] (Logitech Inc.) [Auto | Running] -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
========== Driver Services (SafeList) ========== DRV - [2011/12/20 16:00:52 | 000,428,088 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2011/11/08 04:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/11/08 04:00:00 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/08/03 03:00:00 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111228.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/08/03 03:00:00 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111228.002\NAVENG.SYS -- (NAVENG)
DRV - [2011/07/06 18:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/06/22 19:05:28 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wpshelper.sys -- (WpsHelper)
DRV - [2011/03/21 19:33:42 | 000,015,408 | ---- | M] (Windows ® Codename Longhorn DDK provider) [File_System | Auto | Running] -- C:\Windows\System32\drivers\SymAFR.sys -- (SymAFR)
DRV - [2010/06/24 11:01:36 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/12/09 20:27:18 | 000,588,800 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hardlock.sys -- (hardlock)
DRV - [2009/11/04 19:53:40 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/09/17 17:38:10 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2009/09/17 17:31:50 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2009/09/03 15:03:48 | 000,188,080 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/09/03 15:03:48 | 000,026,416 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2009/08/26 10:54:38 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/08/25 19:05:44 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/08/25 19:05:42 | 000,320,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/08/25 19:05:42 | 000,281,648 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/08/20 06:01:50 | 000,356,864 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge)
DRV - [2009/07/14 11:51:12 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2009/06/10 08:52:58 | 000,347,648 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2009/05/27 13:31:18 | 000,050,064 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2006/11/15 21:03:12 | 000,024,736 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2006/11/15 21:02:50 | 001,962,912 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2006/11/15 21:00:56 | 001,678,368 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2006/11/10 22:48:11 | 001,083,680 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech QuickCam Ultra Vision(UVC)
DRV - [2006/11/10 22:48:00 | 000,040,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2006/11/10 22:46:29 | 001,512,224 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2006/11/02 02:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..extensions.enabledItems: {99210d54-6321-41e8-bd1b-2b4c55874efb}:1.16
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Devonasa\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Devonasa\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Devonasa\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Devonasa\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/09/14 00:10:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/23 22:08:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/29 15:33:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{6B05BDE5-EBAC-4D82-ABE7-1A6F070E09C0}: C:\Users\Devonasa\AppData\Local\{6B05BDE5-EBAC-4D82-ABE7-1A6F070E09C0}
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\SoMud\scripts\mozilla [2011/12/08 14:53:45 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\SoMud\scripts\mozilla [2011/12/08 14:53:45 | 000,000,000 | ---D | M]
[2010/03/24 10:50:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Extensions
[2011/12/27 11:41:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\extensions
[2011/08/17 00:23:36 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/07/08 20:13:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/08 14:58:55 | 000,000,000 | ---D | M] (Somoto Toolbar) -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\extensions\{652853ad-5592-4231-88c6-706613a52e61}
[2011/12/27 11:41:27 | 000,000,000 | ---D | M] ("Tumblr Post") -- C:\Users\Devonasa\AppData\Roaming\Mozilla\Firefox\Profiles\m0xqq5lg.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2011/12/29 13:32:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2008/11/06 23:35:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\App\Photoshop\Plug-ins\Extensions
() (No name found) -- C:\USERS\DEVONASA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\M0XQQ5LG.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/23 22:08:18 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/19 04:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/02 18:25:59 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/23 22:08:19 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/29 16:27:51 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (AP Suggestor) - {D0984FD4-FA9A-46ee-9072-70B0735FF852} - C:\Program Files\AP Suggestor\APSuggestor.dll (Think Tank Labs, LLC)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [LVCOMSX] C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [SoMud] C:\Program Files\SoMud\somud.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Web &Images with SoMud - C:\Program Files\SoMud\scripts\ie\images-url.html ()
O8 - Extra context menu item: Download with SoMud - C:\Program Files\SoMud\scripts\ie\link-url.html ()
O9 - Extra Button: AP Suggestor - {02E2473F-766B-4ce2-8FD0-C4E8071EF1C4} - C:\Program Files\AP Suggestor\APSuggestor.dll (Think Tank Labs, LLC)
O9 - Extra 'Tools' menuitem : AP Suggestor options - {02E2473F-766B-4ce2-8FD0-C4E8071EF1C4} - C:\Program Files\AP Suggestor\APSuggestor.dll (Think Tank Labs, LLC)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\NPJPI150_02.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB3AA8F6-0159-4F70-994A-780FCEE470F9}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\Users\Devonasa\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/12/29 17:04:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/12/29 17:02:33 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Devonasa\Desktop\OTL.exe
[2011/12/29 16:38:22 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Local\temp
[2011/12/29 16:27:59 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011/12/29 15:56:54 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/12/29 15:56:53 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/12/29 15:56:53 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/12/29 15:56:32 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/12/29 15:56:30 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/12/29 15:55:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/29 15:51:18 | 004,356,248 | R--- | C] (Swearware) -- C:\Users\Devonasa\Desktop\ComboFix.exe
[2011/12/29 13:32:38 | 000,127,078 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/12/29 13:32:37 | 000,049,250 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/12/29 13:32:37 | 000,049,248 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/12/29 13:21:07 | 004,702,720 | ---- | C] (AVAST Software) -- C:\Users\Devonasa\Desktop\aswMBR(1).exe
[2011/12/25 15:51:03 | 000,000,000 | ---D | C] -- C:\Sim0
[2011/12/25 15:51:03 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\Documents\RLMsoft
[2011/12/25 15:50:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RLMsoft
[2011/12/25 15:50:27 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RLMsoft
[2011/12/25 15:50:14 | 000,000,000 | ---D | C] -- C:\RLMsoft
[2011/12/25 15:50:09 | 000,000,000 | ---D | C] -- C:\Program Files\RLMsoft
[2011/12/21 00:25:07 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\GamesCafe
[2011/12/21 00:06:32 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\Documents\My Games
[2011/12/20 16:49:15 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\Atari
[2011/12/20 16:32:04 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\Leadertech
[2011/12/20 16:00:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011/12/20 15:58:47 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2011/12/20 15:58:17 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\DAEMON Tools Lite
[2011/12/20 15:58:09 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2011/12/18 01:54:15 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\GOL_byHasbro
[2011/12/15 18:43:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DJS Sims
[2011/12/14 20:12:43 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/12/14 20:12:40 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011/12/14 20:12:34 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/12/14 20:12:33 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/12/14 20:12:28 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/12/14 20:10:47 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011/12/14 20:00:05 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/12/14 19:59:52 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/12/14 19:59:41 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011/12/14 19:59:38 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011/12/14 19:59:38 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/12/14 19:59:37 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011/12/14 19:59:37 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011/12/14 19:59:36 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/12/14 19:59:35 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011/12/14 19:59:34 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011/12/14 19:59:31 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011/12/14 19:59:31 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011/12/14 19:59:31 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011/12/14 19:59:30 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011/12/14 19:59:29 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011/12/14 19:59:29 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011/12/14 19:59:28 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/12/14 19:59:28 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011/12/08 15:05:14 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\Documents\SoMud
[2011/12/08 14:59:35 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\AppData\Roaming\SoMud
[2011/12/08 14:57:35 | 000,000,000 | ---D | C] -- C:\Program Files\SoMud FileBulldog Toolbar
[2011/12/08 14:54:07 | 000,000,000 | ---D | C] -- C:\Program Files\AP Suggestor
[2011/12/08 14:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\APSuggestor
[2011/12/08 14:53:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoMud
[2011/12/08 14:53:39 | 000,000,000 | ---D | C] -- C:\Program Files\SoMud
[2011/12/08 14:33:04 | 000,000,000 | ---D | C] -- C:\Users\Devonasa\Desktop\My Shared Folder
========== Files - Modified Within 30 Days ========== [2011/12/29 17:12:54 | 000,016,896 | ---- | M] () -- C:\Windows\System\svchost.exe
[2011/12/29 17:08:08 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/29 17:07:58 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/29 17:07:58 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/29 17:07:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/29 17:02:34 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Devonasa\Desktop\OTL.exe
[2011/12/29 16:54:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 16:27:51 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/12/29 16:00:44 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1663229470-2338449591-2720500769-1000UA.job
[2011/12/29 15:52:31 | 000,000,512 | ---- | M] () -- C:\Users\Devonasa\Desktop\MBR.dat
[2011/12/29 15:51:47 | 004,356,248 | R--- | M] (Swearware) -- C:\Users\Devonasa\Desktop\ComboFix.exe
[2011/12/29 13:40:02 | 175,803,661 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/12/29 13:21:16 | 004,702,720 | ---- | M] (AVAST Software) -- C:\Users\Devonasa\Desktop\aswMBR(1).exe
[2011/12/29 12:20:40 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1663229470-2338449591-2720500769-1000Core.job
[2011/12/29 12:14:12 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8ED58AD3-8ABB-401C-95E3-4D53772E5585}.job
[2011/12/28 15:37:44 | 000,152,064 | ---- | M] () -- C:\Users\Devonasa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/25 15:51:02 | 000,000,858 | ---- | M] () -- C:\HH0_HouseData.bin
[2011/12/25 15:50:30 | 000,001,927 | ---- | M] () -- C:\Users\Devonasa\Desktop\W7 - Sim Tracker.lnk
[2011/12/23 20:40:11 | 000,004,096 | ---- | M] () -- C:\Windows\d3dx.dat
[2011/12/21 10:19:49 | 000,000,196 | ---- | M] () -- C:\Windows\System32\itlsvc.dat
[2011/12/21 10:19:48 | 000,103,733 | ---- | M] () -- C:\Windows\System32\itusbcore.dat
[2011/12/21 00:17:09 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/12/21 00:17:09 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/12/21 00:06:03 | 000,000,933 | ---- | M] () -- C:\Users\Devonasa\Desktop\HG2 - Shortcut.lnk
[2011/12/20 16:48:59 | 000,001,074 | ---- | M] () -- C:\Users\Devonasa\Desktop\RCT3plus - Shortcut.lnk
[2011/12/20 16:19:21 | 000,604,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/20 16:19:21 | 000,104,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/20 16:02:31 | 000,001,742 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/12/15 03:35:25 | 003,730,792 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/13 01:27:21 | 000,000,000 | ---- | M] () -- C:\t1bg.5
[2011/12/08 14:53:50 | 000,000,791 | ---- | M] () -- C:\Users\Devonasa\Application Data\Microsoft\Internet Explorer\Quick Launch\SoMud.lnk
[2011/12/08 14:53:50 | 000,000,767 | ---- | M] () -- C:\Users\Public\Desktop\SoMud.lnk
========== Files Created - No Company Name ========== [2011/12/29 15:56:55 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/12/29 15:56:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/12/29 15:56:53 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/12/29 15:56:53 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/12/29 15:56:53 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/29 15:52:31 | 000,000,512 | ---- | C] () -- C:\Users\Devonasa\Desktop\MBR.dat
[2011/12/29 13:40:02 | 175,803,661 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/12/26 01:05:14 | 000,016,896 | ---- | C] () -- C:\Windows\System\svchost.exe
[2011/12/25 15:51:01 | 000,000,858 | ---- | C] () -- C:\HH0_HouseData.bin
[2011/12/25 15:50:30 | 000,001,927 | ---- | C] () -- C:\Users\Devonasa\Desktop\W7 - Sim Tracker.lnk
[2011/12/23 20:40:11 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/12/21 00:17:09 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/12/21 00:17:09 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/12/21 00:06:03 | 000,000,933 | ---- | C] () -- C:\Users\Devonasa\Desktop\HG2 - Shortcut.lnk
[2011/12/20 16:48:59 | 000,001,074 | ---- | C] () -- C:\Users\Devonasa\Desktop\RCT3plus - Shortcut.lnk
[2011/12/20 16:02:31 | 000,001,742 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011/12/15 18:41:25 | 003,844,711 | ---- | C] () -- C:\Users\Devonasa\Documents\WardrobeWranglerManual.pdf
[2011/12/15 18:41:25 | 001,464,604 | ---- | C] () -- C:\Users\Devonasa\Documents\InstallWardrobeWranger1.1.exe
[2011/12/13 01:27:21 | 000,000,000 | ---- | C] () -- C:\t1bg.5
[2011/12/08 14:53:50 | 000,000,791 | ---- | C] () -- C:\Users\Devonasa\Application Data\Microsoft\Internet Explorer\Quick Launch\SoMud.lnk
[2011/12/08 14:53:49 | 000,000,767 | ---- | C] () -- C:\Users\Public\Desktop\SoMud.lnk
[2011/11/03 20:54:21 | 000,000,196 | ---- | C] () -- C:\Windows\System32\itlsvc.dat
[2011/11/03 20:54:20 | 000,103,733 | ---- | C] () -- C:\Windows\System32\itusbcore.dat
[2011/09/15 02:39:32 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/09/14 00:34:52 | 000,074,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/08/13 18:51:08 | 000,000,000 | ---- | C] () -- C:\Users\Devonasa\AppData\Local\{09D65B15-4284-4663-AB55-38DC4CF5780E}
[2011/08/10 17:10:51 | 000,000,274 | ---- | C] () -- C:\Windows\ulead32.ini
[2011/08/03 18:53:38 | 000,000,000 | ---- | C] () -- C:\Users\Devonasa\AppData\Local\{1CF3071A-A136-4BBC-A174-D3B2CFC1128A}
[2010/09/05 16:41:21 | 000,001,356 | ---- | C] () -- C:\Users\Devonasa\AppData\Local\d3d9caps.dat
[2010/09/05 16:36:58 | 000,042,594 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010/02/07 23:10:21 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/02/07 23:10:20 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/02/06 06:04:48 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/01/30 20:01:11 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/01/30 16:56:39 | 000,152,064 | ---- | C] () -- C:\Users\Devonasa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/15 21:03:12 | 000,024,736 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2006/11/15 21:00:56 | 001,678,368 | ---- | C] () -- C:\Windows\System32\drivers\Lvckap.sys
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 003,730,792 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,502 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,170 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
< End of report >
Extras.txtOTL Extras logfile created on: 12/29/2011 5:13:50 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Devonasa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.38 Mb Total Physical Memory | 79.21 Mb Available Physical Memory | 7.82% Memory free
2.24 Gb Paging File | 1.20 Gb Available in Paging File | 53.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 101.64 Gb Total Space | 26.97 Gb Free Space | 26.53% Space Free | Partition Type: NTFS
Drive D: | 10.15 Gb Total Space | 0.09 Gb Free Space | 0.89% Space Free | Partition Type: NTFS
Computer Name: DEVONASA-PC | User Name: Devonasa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0085576B-D3EE-46B7-AA04-66A5125B7F35}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{21CFAEE3-2052-4AAD-90EE-5FA580801D4F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{34A1F824-33C6-4189-BE1D-E978357B46E9}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss |
[email protected],-28539 |
"{35553D9A-B804-4858-B2E2-DA375AE074FA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4B177052-1968-45FB-A6B6-0FFAE304E7A5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{50F942EA-9D9C-4743-A9CB-F686D349EF35}" = rport=445 | protocol=6 | dir=out | app=system |
"{611CCD2D-091D-4F49-977E-565352EBEFA6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{6705CF10-30BC-46ED-9EA3-C7F8DCB18509}" = lport=138 | protocol=17 | dir=in | app=system |
"{6BD5B8C4-8EC7-4C93-B8F3-3295EB350EF5}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6E9CC70F-B543-4A36-BAE2-B1CD9D34022A}" = rport=137 | protocol=17 | dir=out | app=system |
"{7508CBF0-69A7-4598-BF35-6FB21C082582}" = lport=139 | protocol=6 | dir=in | app=system |
"{76F8A62C-8433-49E9-AA04-0DB48CBCF13C}" = lport=445 | protocol=6 | dir=in | app=system |
"{7E59EBD7-3C6E-463A-AE54-E8C3229F04F2}" = lport=137 | protocol=17 | dir=in | app=system |
"{95DA2CEA-29E3-4E36-93FB-D141DD0951F0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{99A9D656-7713-405D-803F-8B13C616985E}" = rport=139 | protocol=6 | dir=out | app=system |
"{9A5568A8-41EE-418E-B950-832FDAEAC61A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B324AFE6-2F60-42F1-943A-94106358F847}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{CC00111E-7E56-4B6E-9701-C42C70BA5FEC}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{CCB77BF9-E025-4D74-99F6-B731F6814801}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F5A7872B-2098-4636-BA8E-32B370935809}" = rport=138 | protocol=17 | dir=out | app=system |
========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FC0B411-9991-41E6-9BD4-53DA22E4FD7F}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{1161531B-1A83-433D-A1BD-8020B7E2AC88}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
"{11EDFDB4-CAC0-4AF1-BB79-A87C169FA640}" = protocol=1 | dir=out |
[email protected],-28544 |
"{159C461B-C3C4-47BA-AC60-896CF4687489}" = protocol=58 | dir=out |
[email protected],-28546 |
"{297323D9-E021-4481-ADAE-9FEF7D7DD925}" = protocol=6 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{2CF12751-81D9-4BD1-B498-355DA794BA9C}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{340414A8-802A-4E2F-A4FB-FC69B8CAB7DB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3706B691-7C1B-4E8B-BF7E-DE4AEF1DD566}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{47B19CF9-AF40-4F31-B10B-D774F4057D25}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
"{5081AF52-E57A-474A-BEAC-8E5BF60036E0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5E308BDC-5BAF-4A53-B8D3-92CA5D001FB0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{663853B3-1759-42F1-90A8-035144D55AFD}" = protocol=1 | dir=in |
[email protected],-28543 |
"{698A6159-4D4C-4E8C-A195-380CA5D3BDC9}" = protocol=17 | dir=in | app=c:\windows\system32\hasplms.exe |
"{719436CB-DFC0-4A33-B623-3C81BE81F397}" = protocol=58 | dir=in |
[email protected],-28545 |
"{7C4BE71D-C474-43CB-AFA6-85A67C5D3DB2}" = protocol=6 | dir=in | app=c:\windows\system32\hasplms.exe |
"{82C9CC69-0661-432C-BF21-217861061B8B}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
"{84570C9E-57B3-4100-A2FD-77FBAA866A8E}" = protocol=17 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
"{88BD47C5-3B21-4788-A3A3-B2172AC05761}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{93BB38FA-2556-4C75-AAF6-0A4AE11BE436}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{98925A0F-C000-4DB4-9CCC-1574C672B586}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9CB9EE5B-55FA-4FA1-92EA-D8B04E108A5A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C4645DD4-8198-4424-AF0C-D1F2C7CDEFA2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CF28F06E-5DDD-46FD-94AC-13C57A5B8E9A}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{D820A76E-3191-469C-A800-8C28C8DFEC3D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{DBE61390-BC9E-4051-B308-D329366D2D2C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{F88D0857-9510-450B-B451-C92A4D7BC5AE}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
"TCP Query User{1905A504-D7AF-46E7-96A9-5199067E85EE}C:\users\devonasa\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\devonasa\appdata\roaming\spotify\spotify.exe |
"TCP Query User{1B681419-5DFC-4AE7-A6C4-126CC12A0657}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{52528F5C-F7AB-4C74-AFAF-AFD45601F065}C:\program files\ares\ares.exe" = protocol=6 | dir=in | app=c:\program files\ares\ares.exe |
"TCP Query User{569637BC-C95E-4500-956A-73A76B7CEF65}C:\program files\java\jre1.5.0_02\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.5.0_02\bin\javaw.exe |
"TCP Query User{ACAD2765-4639-4C1A-9F7B-AD7A4329B1B7}C:\program files\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\program files\spotify\spotify.exe |
"TCP Query User{D7D1863C-C2B9-4C60-9F46-251A680FA6CD}C:\program files\somud\somud.exe" = protocol=6 | dir=in | app=c:\program files\somud\somud.exe |
"UDP Query User{0AC36375-CFC5-44E2-ADFC-215F6D411802}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"UDP Query User{1D8EE7F6-B413-4BCB-9983-443CAA86F9A7}C:\program files\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\program files\spotify\spotify.exe |
"UDP Query User{3D77B565-7803-4F96-ABA8-212C7B368C63}C:\program files\ares\ares.exe" = protocol=17 | dir=in | app=c:\program files\ares\ares.exe |
"UDP Query User{689D8561-B94D-49D3-9A87-BB51A0A7AE15}C:\program files\somud\somud.exe" = protocol=17 | dir=in | app=c:\program files\somud\somud.exe |
"UDP Query User{995EE229-A66C-42D3-94BA-1B39F7BF550A}C:\program files\java\jre1.5.0_02\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.5.0_02\bin\javaw.exe |
"UDP Query User{C2E92073-EE04-4C6B-B53C-A95F73757B3C}C:\users\devonasa\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\devonasa\appdata\roaming\spotify\spotify.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{10110FE9-1EE8-4A3D-ADFD-1294F86BE5FC}" = Logitech QuickCam
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A2A15C2-6780-49c1-B296-503230E9DE00}" = The Sims™ 2 Mansion and Garden Stuff
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{40C03514-89C3-41BA-0090-3B440256DB87}" = The Sims 2
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5035723E-C26D-4979-ACA9-12765F5AD7EB}" = WinZip Pro
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Teen Style Stuff
"{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Sims™ 2 Kitchen & Bath Interior Design Stuff
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Sims™ 2 IKEA® Home Stuff
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Sims™ 2 H&M® Fashion Stuff
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8AF3E926-ED59-11D4-A44B-0000E86D2305}" = Ulead GIF Animator 5 TBYB
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CEA4C7D0-ABBE-4074-A488-173BB382CDFF}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9158FF30-78D7-40EF-B83E-451AC5334640}" = Adobe Photoshop CS5.1
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB26A501-6BA6-459B-89AA-9736730752FB}" = VoiceOver Kit
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter_is1" = AC3Filter 1.62b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"AP Suggestor" = AP Suggestor
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"BPM Counter_is1" = BPM Counter 1.2.0.0
"CameraUserGuide-PSA470" = Canon PowerShot A470 Camera User Guide
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CEP - Colour Enable Packages_is1" = CEP (Color Enable Package) v.9.2 (beta)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DAEMON Tools Lite" = DAEMON Tools Lite
"DirectPrintUserGuide" = Canon Direct Print User Guide
"DivX Setup" = DivX Setup
"E.M. Youtube Video Download Tool_is1" = E.M. Youtube Video Download Tool 3.13
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ffdshow_is1" = ffdshow v1.1.3981 [2011-09-12]
"FLV Player" = FLV Player 2.0 (build 25)
"HaaliMkx" = Haali Media Splitter
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"Norton UAC Tool" = Norton UAC Tool
"PhotoStitch" = Canon Utilities PhotoStitch
"QcDrv" = Logitech® Camera Driver
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"SafeConnect" = SafeConnect
"Scriptorium_for_TS2_is1" = Scriptorium for TS2
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"SoftwareStarterGuide-DCSD34" = Canon Digital Camera Solution Disk 34 Software Starter Guide
"SoMud" = SoMud 1.3.5
"SoMud FileBulldog Toolbar" = SoMud FileBulldog Toolbar
"Spotify" = Spotify
"ST6UNST #1" = Sims 2 Categorizer
"TweakUAC_is1" = TweakUAC
"VLC media player" = VLC media player 1.1.11
"W7 - Sim Tracker" = W7 - Sim Tracker
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WinZip Pro" = WinZip Pro
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 12/1/2011 3:20:16 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 12/1/2011 3:20:16 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32105
Error - 12/1/2011 3:20:16 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32105
Error - 12/1/2011 3:20:17 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 12/1/2011 3:20:17 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 33119
Error - 12/1/2011 3:20:17 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 33119
Error - 12/1/2011 3:20:18 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 12/1/2011 3:20:18 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 34133
Error - 12/1/2011 3:20:18 AM | Computer Name = Devonasa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 34133
Error - 12/1/2011 11:36:47 PM | Computer Name = Devonasa-PC | Source = Application Error | ID = 1000
Description = Faulting application Rtvscan.exe, version 11.0.5002.290, time stamp
0x4ab2da72, faulting module Rtvscan.exe, version 11.0.5002.290, time stamp 0x4ab2da72,
exception code 0xc0000005, fault offset 0x00151d71, process id 0xa70, application
start time 0x01ccaf7e6738a381.
[ OSession Events ]
Error - 4/30/2010 10:29:42 AM | Computer Name = Devonasa-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.6425.1000. This session lasted 158992
seconds with 22800 seconds of active time. This session ended with a crash.
Error - 7/29/2010 3:06:23 PM | Computer Name = Devonasa-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 52466
seconds with 1800 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2/4/2010 7:27:33 AM | Computer Name = Devonasa-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 2/4/2010 12:58:43 PM | Computer Name = Devonasa-PC | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.
Error - 2/4/2010 5:29:59 PM | Computer Name = Devonasa-PC | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.
Error - 2/5/2010 12:08:26 AM | Computer Name = Devonasa-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.
Error - 2/5/2010 12:08:26 AM | Computer Name = Devonasa-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.
Error - 2/5/2010 12:08:26 AM | Computer Name = Devonasa-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.
Error - 2/5/2010 12:08:26 AM | Computer Name = Devonasa-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.
Error - 2/5/2010 12:08:26 AM | Computer Name = Devonasa-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.
Error - 2/5/2010 12:09:06 AM | Computer Name = Devonasa-PC | Source = volsnap | ID = 393230
Description = The shadow copies of volume C: were aborted because of an IO failure
on volume C:.
Error - 2/5/2010 12:41:07 AM | Computer Name = Devonasa-PC | Source = DCOM | ID = 10010
Description =
< End of report >