So, I am pretty sure I am infected with some type of nasty malware or some variant of a Win32 Trojan. I unfortunately, stupidly, did not right the name down when I initially detected it. Anyhow, I will explain everything in details below.
The alarms went off earlier this afternoon when I was browsing the net, safe sites I assure you, when I could not create a bookmark. My primary browser is Maxthon v3.4.5.2000; I stumbled upon a website I wanted to save and when I tried creating the bookmark I could not do it; the dialog box popped up, I selected the folder, clicked "OK" and the box did not close. I forcefully closed the box by selecting "X", I then proceeded to exit Maxthon after trying to create the bookmark a couple times without success. A dialog box appeared because I had multiple tabs open, however I was unable to close the browser as clicking "OK" again did not register and clicking "X" did not work this time. I had to kill the process to close it. At this point I thought that the Maxthon files got corrupted somehow. So I attempted to load up Firefox to download Maxthon to reinstall it and received an error upon loading Firefox, which I did not right down. Then Google Chrome, which did not load at all, the process was there for a split second then it closed just as fast. Same thing that happened with Chrome occurred with Opera. So, at this point I was thinking some type of Malware was in my system. The next step I took was running a full scan of drive C with NOD32 Ver.5 with virus signature database version 7552. That was not successful as it locked up at 26% when it was scanning my desktop under C:\Users\[username]\Desktop. From this point I booted into a Ubuntu distribution of Linux off one of my USB drives. Linux is not actually installed on the USB drive, but is set up as a recovery disk of sorts; it boots into Ubuntu and creates a RAM disk, so it's in memory. From there I downloaded Avast for Linux and executed a scan. The scan found a lot of false positives and two Win32.xx Trojans in Hiberfil.sys and Pagefile.sys, so I deleted my pagefile via Avast and tried to move Hiberfil.sys to the chest because unlike the pagefile this file cannot be recreated, AFAIK...but that failed so I deleted that too. Rebooted into Windows safe mode and installed and ran Malwarebytes which found nothing. Rebooted into Win7 and recreated a 4gb pagefile. Everything seemed okay and then Windows pops a message up while I was looking at stuff saying that in xx seconds Window would restart. Windows restarted and then upon logging in, my desktop does not load, all I see is a black screen. But, I could still see the Taskbar just couldn't do anything. So, I was able to open Task Manager and restart the system. From there, everything was okay again...I am now in the Win7 environment without any difficulties so far, at least for the last two hours I have doing things like changing my desktop location, moving files and writing this post. However, I did try re-scanning drive C with NOD32 and it locked up again, maybe at the same location...not sure, but it was at 26% as it was the first time.
Anyhow, sorry for the long-winded explanation. That is where I am at right now...I am still kind of worried that I did not completely clean what was/is lingering on my system.
Any help in running additional scans would be much appreciated!
Kind regards,
Dan Porter
Please see below for my OTL scan results...I am also including the extras.txt file just in case, maybe the program errors can be of assistance; if this is not needed please disregard.
OTL.txt:
OTL logfile created on: 05/10/2012 8:42:55 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dan\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
17.99 Gb Total Physical Memory | 11.58 Gb Available Physical Memory | 64.36% Memory free
21.99 Gb Paging File | 15.45 Gb Available in Paging File | 70.27% Paging File free
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 786.92 Gb Free Space | 84.48% Space Free | Partition Type: NTFS
Drive D: | 1863.01 Gb Total Space | 1268.94 Gb Free Space | 68.11% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 139.18 Gb Free Space | 14.94% Space Free | Partition Type: NTFS
Drive H: | 279.46 Gb Total Space | 86.79 Gb Free Space | 31.06% Space Free | Partition Type: NTFS
Drive J: | 3.99 Gb Total Space | 3.98 Gb Free Space | 99.78% Space Free | Partition Type: FAT32
Drive X: | 223.57 Gb Total Space | 43.89 Gb Free Space | 19.63% Space Free | Partition Type: NTFS
Computer Name: WIN7-DP | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/10/05 20:42:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dan\Desktop\OTL.exe
PRC - [2012/09/17 01:13:54 | 000,097,152 | ---- | M] (Maxthon International ltd.) -- D:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
PRC - [2012/09/09 22:45:24 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/03/04 14:56:56 | 005,016,064 | ---- | M] (abelhadigital.com) -- D:\Utilities\HostsMan_4.0.82_beta3\hm.exe
PRC - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) -- D:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2010/08/12 20:03:02 | 000,923,072 | ---- | M] (Cyber Power Systems, Inc.) -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe
PRC - [2010/08/03 11:02:08 | 000,349,632 | ---- | M] (Cyber Power Systems, Inc.) -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe
PRC - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009/12/13 21:23:12 | 000,092,848 | ---- | M] (Binary Fortress Software) -- D:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/03/12 21:18:48 | 000,602,624 | ---- | M] () -- D:\Program Files (x86)\Everything\Everything.exe
========== Modules (No Company Name) ==========
MOD - [2012/08/30 22:27:30 | 009,465,032 | ---- | M] () -- D:\Program Files (x86)\Maxthon3\Core\Webkit\Npplugins\NPSWF32.dll
MOD - [2012/08/16 04:25:40 | 000,159,104 | ---- | M] () -- D:\Program Files (x86)\Maxthon3\Addons\Mobile\MxMobile.dll
MOD - [2012/07/11 00:33:16 | 000,258,944 | ---- | M] () -- D:\Program Files (x86)\Maxthon3\Bin\Maxzlib.dll
MOD - [2009/03/12 21:18:48 | 000,602,624 | ---- | M] () -- D:\Program Files (x86)\Everything\Everything.exe
========== Services (SafeList) ==========
SRV:64bit: - [2011/09/27 15:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2010/08/08 22:04:10 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/09/09 22:45:24 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/09/09 13:32:37 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/09/08 17:20:05 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/09/08 17:19:49 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/08/08 22:55:16 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/04/26 15:03:36 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) [Auto | Running] -- D:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV - [2010/08/12 20:03:02 | 000,923,072 | ---- | M] (Cyber Power Systems, Inc.) [Auto | Running] -- D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\ppped.exe -- (ppped)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/07/03 11:25:18 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012/03/09 10:57:36 | 000,023,816 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/20 11:00:46 | 000,106,496 | ---- | M] (SteelSeries Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SteelBus64.sys -- (busenum)
DRV:64bit: - [2012/01/20 11:00:46 | 000,034,944 | ---- | M] (SteelSeries Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SAlpham64.sys -- (SAlphamHid)
DRV:64bit: - [2011/12/24 08:45:30 | 000,071,464 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RAMDiskVE.sys -- (RAMDiskVE)
DRV:64bit: - [2011/11/01 08:23:25 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2011/11/01 08:23:25 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011/10/30 23:08:44 | 000,272,448 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/09/02 02:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011/09/02 02:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011/08/09 14:24:52 | 000,202,576 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2011/08/04 14:13:46 | 001,650,264 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x22k.sys -- (ha20x22k)
DRV:64bit: - [2011/08/04 14:13:32 | 001,605,208 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)
DRV:64bit: - [2011/08/04 14:13:22 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:64bit: - [2011/08/04 14:13:12 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:64bit: - [2011/08/04 14:13:00 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:64bit: - [2011/08/04 14:12:50 | 000,179,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:64bit: - [2011/08/04 14:12:40 | 000,697,432 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k)
DRV:64bit: - [2011/08/04 14:12:28 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:64bit: - [2011/08/04 14:12:18 | 001,494,104 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)
DRV:64bit: - [2011/08/04 14:12:18 | 001,494,104 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:64bit: - [2011/08/04 14:12:06 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)
DRV:64bit: - [2011/08/04 14:12:06 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:64bit: - [2011/08/04 14:11:56 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)
DRV:64bit: - [2011/08/04 14:11:56 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)
DRV:64bit: - [2011/08/04 09:20:38 | 000,146,432 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2011/08/04 09:20:38 | 000,137,144 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2011/07/25 18:44:46 | 000,074,752 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:64bit: - [2011/07/20 15:58:22 | 000,044,032 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2011/05/20 22:04:32 | 000,017,496 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr03.sys -- (chdrvr03)
DRV:64bit: - [2011/05/20 22:04:30 | 000,013,016 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr02.sys -- (chdrvr02)
DRV:64bit: - [2011/05/20 22:04:28 | 000,251,224 | ---- | M] (CH Products) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\chdrvr01.sys -- (chdrvr01)
DRV:64bit: - [2011/04/23 21:30:18 | 000,033,160 | ---- | M] (WeOnlyDo Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wod0205.sys -- (wod0205)
DRV:64bit: - [2011/03/31 16:01:50 | 000,126,464 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RzSynapse.sys -- (RzSynapse)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 09:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2009/11/23 21:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 21:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/10/16 21:09:14 | 000,029,952 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Lachesis.sys -- (VaneFltr)
DRV:64bit: - [2009/08/21 02:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/07/13 20:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 18:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/05/20 05:10:00 | 000,393,728 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/05/11 18:49:10 | 000,178,728 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv61xx.sys -- (mv61xx)
DRV - [2010/11/01 06:08:46 | 000,014,544 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- D:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys -- (WinRing0_1_2_0)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 30 AF 71 BE 37 89 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{ABF532CA-D32C-4D8F-9333-5242CF180093}: "URL" = http://open-search.eu/google.php
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:0.5.5
FF - prefs.js..extensions.enabledItems: {4776510a-a1f4-41f3-a3c8-35b474ecef23}:1.0.7
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - prefs.js..keyword.enabled: true
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iam...c=tops&search="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: D:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD [2011/10/31 08:57:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components [2012/08/12 18:00:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/16 14:27:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: D:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/10/31 08:57:23 | 000,000,000 | ---D | M]
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
[2010/10/04 12:58:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/23 08:25:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\extensions
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (Stealther) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\extensions\[email protected]
[2012/07/25 22:33:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] (Stealther) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2012/04/15 21:53:49 | 000,000,000 | ---D | M] (ActiveGS) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\[email protected]
[2011/07/09 11:55:38 | 000,330,316 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\[email protected]
[2011/11/25 12:46:20 | 000,255,318 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\[email protected]
[2012/07/25 22:33:07 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\hz2nt2be.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2008/09/21 14:55:14 | 000,002,749 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\cuil.xml
[2008/06/22 23:02:53 | 000,000,908 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\imdb.xml
[2010/07/04 02:47:50 | 000,000,266 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\Search.xml
[2008/06/22 23:02:53 | 000,001,108 | ---- | M] () -- C:\Users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\d4l7a5i2.default\searchplugins\wikipedia-en.xml
File not found (No name found) -- D:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) -- D:\PROGRAM FILES (X86)\ORBITDOWNLOADER\ADDONS\ORBITFF
========== Chrome ==========
CHR - homepage: http://www.gamespot.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.gamespot.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Dan\AppData\Local\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_221.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Pando Web Installer (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Adobe Acrobat (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = D:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Dan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Digital Trends = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehpabhmfaobjofbklnedfageenjifadk\1.7.4_0\
CHR - Extension: SpaceVenture Kickstarter Prototype: Phase 1 = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomnnfeooofoenddphjjfdfbpkiiboof\0.5_0\
CHR - Extension: SpaceVenture Kickstarter Prototype: Phase 2 = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhjbdidbieimmfipadjkioniffgcgopp\0.13_0\
CHR - Extension: Gmail = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/10/03 02:44:29 | 001,009,164 | ---- | M]) - C:\Windows\SysNative\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 33263 more lines...
O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4:64bit: - HKLM..\Run: [egui] D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Everything] D:\Program Files (x86)\Everything\Everything.exe ()
O4 - HKLM..\Run: [PowerPanel Personal Edition User Interaction] D:\Program Files (x86)\CyberPower PowerPanel Personal Edition\pppeuser.exe (Cyber Power Systems, Inc.)
O4 - HKCU..\Run: [DisplayFusion] D:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [HostsMan] D:\Utilities\HostsMan_4.0.82_beta3\hm.exe (abelhadigital.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_04)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_04)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.25 192.168.0.1 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = porter.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{271FC4E1-0192-4AA4-BC2E-86FE092558D2}: DhcpNameServer = 127.0.0.1 192.168.0.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F25B8A8-1564-47B0-82C6-E45C88A57F2B}: DhcpNameServer = 192.168.0.25 192.168.0.1 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F25B8A8-1564-47B0-82C6-E45C88A57F2B}: NameServer = 64.71.255.198,192.168.0.25
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{22b78c25-0337-11e1-bc7e-00248c444208}\Shell - "" = AutoRun
O33 - MountPoints2\{22b78c25-0337-11e1-bc7e-00248c444208}\Shell\AutoRun\command - "" = I:\setup.exe
O33 - MountPoints2\{97a5fd06-030f-11e1-a437-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{97a5fd06-030f-11e1-a437-806e6f6e6963}\Shell\AutoRun\command - "" = G:\FalloutLauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/05 20:42:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Dan\Desktop\OTL.exe
[2012/10/05 19:48:57 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Stardock
[2012/10/05 13:01:11 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2012/10/05 12:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012/10/05 12:55:58 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012/10/05 02:09:47 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Solid State Networks
[2012/09/29 11:32:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BOSS
[2012/09/28 23:54:37 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Meteor Entertainment
[2012/09/24 21:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nicolas Games
[2012/09/22 19:20:15 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\Runic Games
[2012/09/22 19:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Torchlight 2
[2012/09/20 08:55:01 | 000,000,000 | ---D | C] -- D:\Users\Dan\Documents\Inquisitor_SaveGames
[2012/09/20 00:17:33 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\GOG.com
[2012/09/16 14:32:40 | 000,000,000 | ---D | C] -- D:\Users\Dan\Documents\Mudbox
[2012/09/16 14:27:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/09/10 15:01:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\ProcessLasso
[2012/09/09 23:42:10 | 000,000,000 | ---D | C] -- D:\Users\Dan\Documents\Hard Reset Extended
[2012/09/09 22:59:37 | 000,000,000 | ---D | C] -- C:\Users\Dan\Saved Games
[2012/09/09 22:46:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2012/09/09 22:45:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2012/09/09 16:48:15 | 000,060,776 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012/09/09 16:48:15 | 000,052,584 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012/09/08 17:21:28 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Creative Installation Information
[2012/09/08 17:21:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative
[2012/09/08 17:20:18 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Data
[2012/09/08 17:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auzentech
[2012/09/08 17:19:56 | 000,000,000 | ---D | C] -- C:\Program Files\Creative
[2012/09/08 17:19:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative Labs Shared
[2012/09/08 17:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
[2012/09/08 17:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Creative
[2012/09/08 17:09:47 | 000,782,336 | ---- | C] (Creative Labs Inc.) -- C:\Windows\SysWow64\oalinst.exe
[2012/09/08 17:09:47 | 000,077,824 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\eaxac3.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/05 20:42:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dan\Desktop\OTL.exe
[2012/10/05 20:42:04 | 000,025,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/05 20:42:04 | 000,025,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/05 20:35:22 | 000,791,498 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/05 20:35:22 | 000,672,432 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/10/05 20:35:22 | 000,128,426 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/10/05 20:29:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/05 20:29:06 | 1603,620,861 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/05 20:16:08 | 000,062,836 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/05 20:16:08 | 000,062,836 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/05 20:16:08 | 000,000,904 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/10/05 20:14:37 | 000,777,054 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/04 22:26:02 | 1395,766,598 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 8.mp4
[2012/10/04 22:25:52 | 1380,838,861 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 9.mp4
[2012/10/04 02:49:17 | 1607,115,555 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 7.mp4
[2012/10/04 02:47:00 | 1386,365,463 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 6.mp4
[2012/10/03 02:44:29 | 001,009,164 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\HOSTS
[2012/10/03 01:47:52 | 001,009,165 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\HOSTS.bak
[2012/10/02 22:53:05 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2012/10/02 22:53:05 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2012/10/02 19:25:48 | 2253,952,302 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 5.mp4
[2012/10/02 13:18:43 | 935,639,840 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 4.mp4
[2012/10/01 17:32:09 | 1913,044,538 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 3.mp4
[2012/09/30 16:23:54 | 000,075,510 | ---- | M] () -- D:\Users\Dan\Documents\Chieftain_Insurance_$163_30-Sep-2012.pdf
[2012/09/30 16:22:08 | 000,076,294 | ---- | M] () -- D:\Users\Dan\Documents\ScotiaLine_$50_30-Sep-2012.pdf
[2012/09/30 16:21:22 | 000,071,647 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$200_30-Sep-2012.pdf
[2012/09/30 16:20:27 | 000,090,295 | ---- | M] () -- D:\Users\Dan\Documents\Rent_Dad_$270_30-Sep-2012.pdf
[2012/09/28 23:55:45 | 000,001,285 | ---- | M] () -- C:\Users\Dan\Desktop\Hawken.lnk
[2012/09/28 08:35:40 | 774,414,598 | ---- | M] () -- C:\Users\Dan\Desktop\Borderlands 2_Gamespot_hardware_comparison.mp4
[2012/09/25 02:21:54 | 1150,511,496 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 2.mp4
[2012/09/24 22:46:55 | 1184,335,437 | ---- | M] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 1.mp4
[2012/09/18 01:36:10 | 1606,619,565 | ---- | M] () -- C:\Users\Dan\Desktop\videoplayback.mp4
[2012/09/14 20:17:00 | 000,016,054 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2012/09/14 17:25:31 | 003,499,215 | ---- | M] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/09/10 19:42:01 | 000,071,239 | ---- | M] () -- D:\Users\Dan\Documents\Visa_Payment_$200_10-Sep-2012.pdf
[2012/09/10 19:39:07 | 000,091,105 | ---- | M] () -- D:\Users\Dan\Documents\Rent_Dad_$219_10-Sep-2012.pdf
[2012/09/10 19:36:41 | 000,083,165 | ---- | M] () -- D:\Users\Dan\Documents\Rogers-HomePhone_Internet__$169.73_10-Sep-2012.pdf
[2012/09/09 22:45:24 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/09/08 17:21:18 | 000,000,159 | RH-- | M] () -- C:\Windows\ctfile.rfc
[2012/09/07 22:05:43 | 1177,751,522 | ---- | M] () -- C:\Users\Dan\Desktop\169_qft_ep13_090712_hd.mp4
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/05 18:39:20 | 1603,620,861 | -HS- | C] () -- C:\hiberfil.sys
[2012/10/05 12:57:58 | 003,499,215 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/10/05 12:57:00 | 000,016,054 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2012/10/04 22:03:51 | 1380,838,861 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 9.mp4
[2012/10/04 22:03:14 | 1395,766,598 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 8.mp4
[2012/10/04 02:37:22 | 1607,115,555 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 7.mp4
[2012/10/04 02:36:15 | 1386,365,463 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 6.mp4
[2012/10/02 19:13:07 | 2253,952,302 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 5.mp4
[2012/10/02 13:11:28 | 935,639,840 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 4.mp4
[2012/10/01 17:19:53 | 1913,044,538 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 3.mp4
[2012/09/30 16:23:54 | 000,075,510 | ---- | C] () -- D:\Users\Dan\Documents\Chieftain_Insurance_$163_30-Sep-2012.pdf
[2012/09/30 16:22:08 | 000,076,294 | ---- | C] () -- D:\Users\Dan\Documents\ScotiaLine_$50_30-Sep-2012.pdf
[2012/09/30 16:21:22 | 000,071,647 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$200_30-Sep-2012.pdf
[2012/09/30 16:20:27 | 000,090,295 | ---- | C] () -- D:\Users\Dan\Documents\Rent_Dad_$270_30-Sep-2012.pdf
[2012/09/28 23:55:45 | 000,001,285 | ---- | C] () -- C:\Users\Dan\Desktop\Hawken.lnk
[2012/09/28 08:31:43 | 774,414,598 | ---- | C] () -- C:\Users\Dan\Desktop\Borderlands 2_Gamespot_hardware_comparison.mp4
[2012/09/25 02:11:12 | 1150,511,496 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 2.mp4
[2012/09/24 22:05:35 | 1184,335,437 | ---- | C] () -- C:\Users\Dan\Desktop\Gopher Vids - Let's Play Fallout 3_part 1.mp4
[2012/09/18 01:29:24 | 1606,619,565 | ---- | C] () -- C:\Users\Dan\Desktop\videoplayback.mp4
[2012/09/16 14:27:12 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/09/10 19:42:00 | 000,071,239 | ---- | C] () -- D:\Users\Dan\Documents\Visa_Payment_$200_10-Sep-2012.pdf
[2012/09/10 19:39:06 | 000,091,105 | ---- | C] () -- D:\Users\Dan\Documents\Rent_Dad_$219_10-Sep-2012.pdf
[2012/09/10 19:36:41 | 000,083,165 | ---- | C] () -- D:\Users\Dan\Documents\Rogers-HomePhone_Internet__$169.73_10-Sep-2012.pdf
[2012/09/08 17:41:21 | 000,001,080 | ---- | C] () -- C:\Windows\SysNative\settingsbkup.sfm
[2012/09/08 17:41:21 | 000,001,080 | ---- | C] () -- C:\Windows\SysNative\settings.sfm
[2012/09/08 17:23:39 | 000,062,836 | ---- | C] () -- C:\Windows\SysNative\BMXStateBkp-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/09/08 17:23:39 | 000,062,836 | ---- | C] () -- C:\Windows\SysNative\BMXState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/09/08 17:23:39 | 000,000,904 | ---- | C] () -- C:\Windows\SysNative\DVCState-{00000003-00000000-00000000-00001102-0000000B-00495431}.rfx
[2012/09/08 17:20:17 | 000,207,872 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012/09/08 17:20:17 | 000,089,600 | ---- | C] () -- C:\Windows\SysNative\CmdRtr64.DLL
[2012/09/08 17:20:17 | 000,074,240 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012/09/08 17:20:16 | 000,272,384 | ---- | C] () -- C:\Windows\SysNative\APOMgr64.DLL
[2012/09/08 17:20:16 | 000,000,159 | RH-- | C] () -- C:\Windows\ctfile.rfc
[2012/09/08 17:09:47 | 002,167,684 | ---- | C] () -- C:\Windows\SysWow64\CT2MGM.SF2
[2012/09/08 17:09:47 | 002,167,684 | ---- | C] () -- C:\Windows\SysNative\CT2MGM.SF2
[2012/09/08 17:09:47 | 001,048,576 | ---- | C] () -- C:\Windows\SysWow64\CT1MGM.ROM
[2012/09/08 17:09:47 | 001,048,576 | ---- | C] () -- C:\Windows\SysNative\CT1MGM.ROM
[2012/09/08 17:09:47 | 000,390,609 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2012/09/08 17:09:47 | 000,390,609 | ---- | C] () -- C:\Windows\SysNative\ctdnlstr.dat
[2012/09/08 17:09:47 | 000,051,979 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2012/09/08 17:09:47 | 000,051,979 | ---- | C] () -- C:\Windows\SysNative\ctdlang.dat
[2012/09/08 17:09:47 | 000,028,411 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2012/09/08 17:09:47 | 000,028,411 | ---- | C] () -- C:\Windows\SysNative\instwdm.ini
[2012/09/08 17:09:47 | 000,018,432 | ---- | C] () -- C:\Windows\SysNative\regplib.exe
[2012/09/08 17:09:47 | 000,014,336 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2012/09/08 17:09:47 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
[2012/09/08 17:09:47 | 000,010,062 | ---- | C] () -- C:\Windows\SysWow64\UDAAPO64.UDA
[2012/09/08 17:09:47 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2012/09/08 17:09:47 | 000,005,530 | ---- | C] () -- C:\Windows\SysWow64\CTMLFX64.UDA
[2012/09/08 17:09:47 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL
[2012/09/08 17:09:47 | 000,002,560 | ---- | C] () -- C:\Windows\SysNative\CtxfiRes.dll
[2012/09/08 17:09:47 | 000,001,688 | ---- | C] () -- C:\Windows\SysNative\XFi.bmp
[2012/09/08 17:09:47 | 000,000,287 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysWow64\default8.sfm
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysNative\default8.sfm
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysWow64\default4.sfm
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysNative\default4.sfm
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysWow64\default.sfm
[2012/09/08 17:09:47 | 000,000,059 | ---- | C] () -- C:\Windows\SysNative\default.sfm
[2012/09/08 17:09:47 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2012/09/08 17:09:47 | 000,000,054 | ---- | C] () -- C:\Windows\SysNative\ctzapxx.ini
[2012/09/07 21:57:19 | 1177,751,522 | ---- | C] () -- C:\Users\Dan\Desktop\169_qft_ep13_090712_hd.mp4
[2012/08/26 23:06:58 | 000,000,213 | ---- | C] () -- C:\Windows\PCWGXDRV.INI
[2012/08/26 23:06:58 | 000,000,057 | ---- | C] () -- C:\Windows\LOGINPUT.INI
[2012/08/12 21:26:44 | 000,000,040 | ---- | C] () -- C:\Windows\RUNAWAY2.INI
[2012/07/25 16:01:16 | 000,002,081 | ---- | C] () -- C:\ProgramData\ENG.2012-07.pl.nicolasgames_B05A5A11-F525-40DF-AE67-58228603B921.swidtag
[2012/07/21 00:03:09 | 000,000,036 | ---- | C] () -- C:\Windows\wininit.ini
[2012/03/05 00:28:53 | 000,000,079 | ---- | C] () -- C:\Users\Dan\AppData\Local\CrystalDiskMark30.ini
[2012/02/25 21:55:54 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2012/02/25 18:29:56 | 000,000,119 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Network Monitor II_Traffic.ini
[2012/02/22 22:53:47 | 000,001,765 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\System Monitor II_CPU0_Settings.ini
[2012/02/22 22:53:39 | 000,000,513 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\GPU Monitor_GPU0_Settings.ini
[2012/02/03 22:53:39 | 000,777,054 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/12/18 17:56:43 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/11/13 00:25:28 | 000,111,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/13 00:25:09 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/12 18:42:04 | 000,000,535 | ---- | C] () -- C:\Windows\eReg.dat
[2011/10/30 23:57:41 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/10/30 11:07:56 | 000,258,864 | ---- | C] () -- C:\Windows\SUPDRun.exe
[2011/10/30 07:53:21 | 000,003,084 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/10/26 22:35:05 | 000,081,456 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\icarus-dxdiag.xml
[2011/10/26 22:35:05 | 000,001,702 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\System Monitor II_Settings.ini
[2011/10/26 22:35:05 | 000,000,601 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Network Monitor II_Settings.ini
[2011/10/26 22:35:05 | 000,000,485 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\GPU Monitor_Settings.ini
[2011/10/26 22:35:05 | 000,000,424 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\Drives Monitor_Settings.ini
[2011/10/26 22:33:37 | 000,007,618 | ---- | C] () -- C:\Users\Dan\AppData\Local\Resmon.ResmonCfg
[2011/10/26 22:33:37 | 000,000,091 | ---- | C] () -- C:\Users\Dan\AppData\Local\fusioncache.dat
[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
========== ZeroAccess Check ==========
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/10/26 22:35:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.dbox
[2012/08/22 22:23:18 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.minecraft
[2012/03/17 21:49:59 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\abelhadigital.com
[2011/10/26 22:35:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Acronis
[2010/07/01 08:36:51 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Amazon
[2012/08/26 23:33:33 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Audacity
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Autodesk
[2012/03/23 12:00:42 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BHOK IT Consulting
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Bioshock2
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Bizarre Creations
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Blackberry Desktop
[2012/04/16 01:07:00 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BoneTown
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Braid
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Brawsome
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Cloanto
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\com.adobe.ExMan
[2011/10/26 22:35:41 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2011/10/26 22:35:46 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\CrystalApp
[2010/05/24 07:52:19 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\CrystalSpace
[2012/09/24 21:48:02 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\DAEMON Tools Pro
[2012/09/06 22:42:10 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\DisplayFusion
[2011/10/26 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Downloaded Installations
[2012/05/01 08:37:36 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Dropbox
[2011/07/21 00:00:08 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\EurekaLog
[2012/08/13 00:56:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\fltk.org
[2011/10/26 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Foxit
[2011/10/26 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Foxit Software
[2012/02/15 00:34:40 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\GameRanger
[2011/10/26 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\GARMIN
[2011/10/26 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\GetRightToGo
[2012/09/20 00:17:32 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\GOG.com
[2011/10/26 22:35:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\GrabPro
[2012/03/22 18:55:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\gsmartcontrol
[2012/04/02 19:07:56 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Hensense.com
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Hothead Games
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ImgBurn
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\JKHub
[2012/02/25 18:25:56 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Language
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Leadertech
[2012/04/24 22:49:43 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\LoneSurvivor
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\LucasArts
[2011/10/26 22:35:50 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MagicIndie
[2011/10/26 22:35:51 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Maxthon3
[2011/10/26 22:35:55 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MinMaxGames
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Mumble
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\New Technology Studio
[2012/01/02 02:23:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Nifflas
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Nokia
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Notepad++
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\OpenCandy
[2011/10/26 22:35:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\OpenOffice.org
[2011/10/26 22:35:58 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Opera
[2012/04/29 18:18:42 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Orbit
[2011/10/26 22:36:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PlaneShift
[2011/10/26 22:36:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PlayFirst
[2012/09/10 15:03:32 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ProcessLasso
[2011/10/26 22:36:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ProgSense
[2011/10/26 22:36:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ProtectDISC
[2012/01/31 23:31:40 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Razer
[2011/10/26 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Research In Motion
[2011/10/26 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\runic games
[2011/10/26 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ScummVM
[2012/07/05 23:07:34 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SteelSeries
[2012/01/18 09:48:06 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SumatraPDF
[2011/10/26 22:36:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\The Creative Assembly
[2011/10/26 22:36:04 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Thunderbird
[2011/10/26 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Tilted Mill
[2011/10/26 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TrueCrypt
[2011/10/26 22:37:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TS3Client
[2011/10/26 22:37:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Turbine
[2011/10/26 22:37:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Ubisoft
[2011/10/26 22:37:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\UHS Reader
[2011/10/26 22:37:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\uqm
[2012/10/03 20:46:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\uTorrent
[2012/07/16 20:44:54 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Vessel
[2011/10/26 22:37:17 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Wippien
[2011/10/26 22:37:19 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\World of Warcraft
[2012/01/12 23:31:57 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\XnView
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 5120 bytes -> C:\Users\Public\Documents\desktop.ini:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\ProgramData:gs5sys
@Alternate Data Stream - 3584 bytes -> D:\Users\Dan\Documents\desktop.ini:gs5sys
< End of report >
Extras.txt:
OTL Extras logfile created on: 05/10/2012 8:42:55 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dan\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
17.99 Gb Total Physical Memory | 11.58 Gb Available Physical Memory | 64.36% Memory free
21.99 Gb Paging File | 15.45 Gb Available in Paging File | 70.27% Paging File free
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 786.92 Gb Free Space | 84.48% Space Free | Partition Type: NTFS
Drive D: | 1863.01 Gb Total Space | 1268.94 Gb Free Space | 68.11% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 139.18 Gb Free Space | 14.94% Space Free | Partition Type: NTFS
Drive H: | 279.46 Gb Total Space | 86.79 Gb Free Space | 31.06% Space Free | Partition Type: NTFS
Drive J: | 3.99 Gb Total Space | 3.98 Gb Free Space | 99.78% Space Free | Partition Type: FAT32
Drive X: | 223.57 Gb Total Space | 43.89 Gb Free Space | 19.63% Space Free | Partition Type: NTFS
Computer Name: WIN7-DP | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = Max3.Association.HTML] -- D:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe (Maxthon International ltd.)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with XnView] -- "D:\Program Files (x86)\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with XnView] -- "D:\Program Files (x86)\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "D:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1BADFD17-5C84-4920-A4E7-14F3AF36D8CC}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2B99955D-E79A-4861-A4DA-A1754DECF45E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2F216B51-4768-4483-96E8-854D37B899A5}" = lport=57012 | protocol=17 | dir=in | name=pando media booster |
"{3761BA1C-1760-4C98-8141-E7A715716389}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{431F06F0-B86B-4FA9-948D-28BED627C3D6}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4687EE1D-8C44-4595-868D-9929DB4EAD1C}" = lport=57012 | protocol=6 | dir=in | name=pando media booster |
"{5B2DB423-1832-487B-9492-AA625356BB26}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5D170943-0C4C-47DB-8E5F-44AEBDD66605}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{73F71296-D02E-400B-A79A-27866AFACCFC}" = lport=57012 | protocol=6 | dir=in | name=pando media booster |
"{7A38BE08-08A5-4417-9A4D-AE5091FED629}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{8291ED36-F31E-4510-929A-37AC8B9DDB75}" = lport=57012 | protocol=17 | dir=in | name=pando media booster |
"{85A22411-639A-48E1-A6DE-C8E62C1CF013}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{A2AF314F-ABCB-4923-A723-68EC9221B4A5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B48F0B85-6FAD-44C3-9C2E-3C6E710F5778}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{D82778BF-61E8-4DD8-B43C-473AE90AFD82}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E0935523-80B3-4989-97EA-288E6A1C7D53}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EF734D76-85B0-4205-B6B3-177A6BEA331C}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{F93EE87A-BCEB-4372-92B8-8AABCA1E0B72}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0337668E-1D8B-4877-8C45-C51E8F377453}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc.exe |
"{0E644385-7A6E-45CB-BD26-1B43256E47A8}" = protocol=6 | dir=in | app=d:\program files (x86)\maxthon3\bin\mxup.exe |
"{1E1FD935-AA87-4B35-9F45-EBDCB7C16231}" = protocol=17 | dir=in | app=d:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{1EBAC985-18C5-4568-848E-E4C8C287F0B8}" = protocol=17 | dir=in | app=d:\program files (x86)\maxthon3\bin\maxthon.exe |
"{6EC79879-8834-4681-B1F2-E37638B5CA60}" = protocol=6 | dir=in | app=d:\program files (x86)\utorrent\utorrent.exe |
"{77F138DE-869B-4CD2-9FEE-83A398B7337B}" = protocol=17 | dir=in | app=d:\games\star wars-the old republic\launcher.exe |
"{95F4AD16-A05D-49D2-9E69-74C1DBCED766}" = protocol=17 | dir=in | app=d:\program files (x86)\utorrent\utorrent.exe |
"{9C1122DB-39C3-443D-BCBB-61865659B0C6}" = protocol=6 | dir=in | app=d:\games\star wars-the old republic\launcher.exe |
"{CF9B8CFE-FE3B-4E26-BF72-FEAEC93B0803}" = protocol=17 | dir=in | app=d:\program files (x86)\maxthon3\bin\mxup.exe |
"{D5377B04-AECF-4FE0-B9B6-A51D6B66A1CC}" = protocol=6 | dir=in | app=d:\program files (x86)\maxthon3\bin\maxthon.exe |
"{E2F76DBE-6FD2-487B-86FB-543B2C5A699D}" = protocol=6 | dir=in | app=d:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{E70DD125-4025-48DA-A78A-C75886471696}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EEF2EE23-8E80-4796-8E97-72C3862E5716}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc.exe |
"TCP Query User{09E55F61-2A53-467E-87ED-09E7AF28A3A5}D:\program files (x86)\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe" = protocol=6 | dir=in | app=d:\program files (x86)\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe |
"TCP Query User{13979C66-995C-4188-9778-F6E2C61C6DEC}C:\users\dan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\dan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{35116CB9-74A3-443E-8FC4-172759D2444C}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{3E4C8057-0B9E-445A-96C4-37CD628E74A6}D:\games\star wars-the old republic\betatest\retailclient\swtor.exe" = protocol=6 | dir=in | app=d:\games\star wars-the old republic\betatest\retailclient\swtor.exe |
"TCP Query User{706AF2EB-7C28-496E-AB78-1CF673FA3B3F}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{71062E2E-17E0-487C-BE17-7BB3D3801699}D:\udk\udk-2010-09\binaries\unrealfrontend.exe" = protocol=6 | dir=in | app=d:\udk\udk-2010-09\binaries\unrealfrontend.exe |
"TCP Query User{E27DD617-DB46-436F-8402-9DD02DC76BFE}D:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=d:\program files (x86)\opera\opera.exe |
"TCP Query User{F9D71C9C-A255-4FBF-B80F-C96BE48999CA}D:\program files (x86)\maxthon3\modules\mxminithunder\thundermini.exe" = protocol=6 | dir=in | app=d:\program files (x86)\maxthon3\modules\mxminithunder\thundermini.exe |
"UDP Query User{03DC33CC-C5F6-4D15-A376-D3B8586202D5}D:\program files (x86)\maxthon3\modules\mxminithunder\thundermini.exe" = protocol=17 | dir=in | app=d:\program files (x86)\maxthon3\modules\mxminithunder\thundermini.exe |
"UDP Query User{1122B828-6D37-4805-BDD8-F37A574EAA10}D:\program files (x86)\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe" = protocol=17 | dir=in | app=d:\program files (x86)\codemasters\rise of the argonauts\binaries\riseoftheargonauts.exe |
"UDP Query User{141EC4D6-4E4F-45C6-9D04-321489059840}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{173EB1A2-C08D-44CD-8115-23CD50C53728}D:\games\star wars-the old republic\betatest\retailclient\swtor.exe" = protocol=17 | dir=in | app=d:\games\star wars-the old republic\betatest\retailclient\swtor.exe |
"UDP Query User{2BC6D970-2C94-4571-9E1D-6B89905B57A4}D:\udk\udk-2010-09\binaries\unrealfrontend.exe" = protocol=17 | dir=in | app=d:\udk\udk-2010-09\binaries\unrealfrontend.exe |
"UDP Query User{BEDFC086-F6E1-4202-A93B-74FD6201E736}D:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=d:\program files (x86)\opera\opera.exe |
"UDP Query User{CB0644E0-A604-482E-8E9D-44D9C7AF0688}C:\users\dan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\dan\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{E162B6F4-319D-4C18-8738-1D588FD175EE}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{10E5F3FF-AD93-40C5-A0F5-13B9185DBB12}" = ESET NOD32 Antivirus
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416031FF}" = Java 6 Update 31 (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86417004FF}" = Java 7 Update 4 (64-bit)
"{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}" = Foxit Phantom
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.63
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.63
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{D9C50188-12D5-4D3E-8F00-682346C2AA5F}" = Microsoft Xbox 360 Accessories 1.2
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E1993D28-CC66-47D2-AB36-64EEDC317FFA}" = StudioTax 2011
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6FD24B4-34A3-4635-8ECD-7B5C791EAE5F}" = Wing Commander Saga 1.0.2.7795
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.60.1
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.19
"Explorer Suite_is1" = Explorer Suite III
"HardlinkShellExt" = Link Shell Extension
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"sp6" = Logitech SetPoint 6.32
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01D5FF1F-BB19-4387-8EF1-C6319037EC12}" = RAMDisk
"{049FF5E4-EB02-4c42-8DB0-226E2F7A9E53}" = Torchlight 2
"{08CFF9D1-BD86-4CA3-BC4A-AC51EF7640A4}" = X-Fi Forte 7.1
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1AA94747-3BF6-4237-9E1A-7B3067738FE1}" = Max Payne 3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3D693CF9-13F1-432A-8FF4-4ADA4CB523B5}" = Afterfall InSanity
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{456A5815-604D-4D72-94DF-346D2B978A59}_is1" = GOG.com Downloader version 3.0.52
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{93F750BB-805D-4325-A8E6-C80BE01B870D}" = BOSS Userlist Manager
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E4406ED3-B04C-44F1-ABB4-08775B74934F}" = Call Of Cthulhu DCoTE
"{EDEC45BE-39B9-4C23-81AF-FD1B5CECEA2A}" = CyberPower PowerPanel Personal Edition 1.3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}" = BlackBerry Desktop Software 6.1
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"12bbe590-c890-11d9-9669-0800200c9a66_is1" = The Lord of the Rings Online™ v03.04.04.8012
"3.0.100.39_is1" = Disktrix UltimateDefrag 3.0
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Age of Conan_is1" = Age of Conan: Unchained
"Audacity_is1" = Audacity 2.0.2
"AutoHotkey" = AutoHotkey 1.0.48.05
"AviSynth" = AviSynth 2.5
"AW7" = Postal 2: AW7
"Baldur's Gate II_is1" = Baldur's Gate II
"Baldur's Gate_is1" = Baldur's Gate
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"BOSS" = BOSS
"CHControlManager_is1" = CH Control Manager Software
"CwGet_is1" = CwGet V2.26
"DarkLoader_is1" = DarkLoader 4.3
"Diablo III" = Diablo III
"dips64" = Desktop Icon Position Saver (64-bit)
"ENTERPRISER" = Microsoft Office Enterprise 2007
"Eternal Damnation: A Postal 2 Modification" = Eternal Damnation: A Postal 2 Modification
"Everything" = Everything 1.2.1.371
"ffdshow_is1" = ffdshow [rev 497] [2006-11-04]
"Fraps" = Fraps (remove only)
"Game Booster_is1" = Game Booster 3
"GOM Player" = GOM Player
"GSmartControl" = GSmartControl
"Guild Wars 2" = Guild Wars 2
"Inquisitor_is1" = Inquisitor
"Intel® Solid-State Drive Toolbox" = Intel® Solid-State Drive Toolbox
"Legend of Grimrock_is1" = Legend of Grimrock
"Marvell Miniport Driver" = Marvell Miniport Driver
"Maxthon3" = Maxthon 3
"MDK_is1" = MDK
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"mv61xxDriver" = marvell 61xx
"OpenAL" = OpenAL
"PFPortChecker" = PFPortChecker 1.0.39
"Postal 2 - Apocalypse Weekend" = Postal 2 - Apocalypse Weekend
"Postal 2 - Share The Pain" = Postal 2 - Share The Pain
"PunkBusterSvc" = PunkBuster Services
"Resonance_is1" = Resonance
"Rockstar Games Social Club" = Rockstar Games Social Club
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Steam App 202170" = Sleeping Dogs™
"Steam App 202480" = Creation Kit
"Steam App 218350" = Unmechanical Demo
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8980" = Borderlands
"TechPowerUp GPU-Z" = TechPowerUp GPU-Z
"The Secret World_is1" = The Secret World
"The Walking Dead © 3_is1" = The Walking Dead © 3 version 1
"Thief 2: The Metal Age_is1" = Thief 2: The Metal Age
"Thief Gold_is1" = Thief Gold
"uTorrent" = µTorrent
"Winamp" = Winamp
"Wrye Bash" = Wrye Bash
"x264vfw" = x264vfw - H.264/MPEG-4 AVC codec (remove only)
"XnView Shell Extension_is1" = XnView Shell Extension 3.1.0 (64bits)
"XnView_is1" = XnView 1.98.5
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Hawken" = Hawken
"Space Quest II Remake" = Space Quest II Remake
"Winamp Detect" = Winamp Detector Plug-in
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 02/10/2012 1:51:54 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Fallout3.exe, version: 1.7.0.3, time stamp:
0x4a40f18b Faulting module name: Fallout3.exe, version: 1.7.0.3, time stamp: 0x4a40f18b
Exception
code: 0xc0000005 Fault offset: 0x001878f8 Faulting process id: 0x15a4 Faulting application
start time: 0x01cda0c65f35caf4 Faulting application path: X:\Games\Fallout 3\Fallout3.exe
Faulting
module path: X:\Games\Fallout 3\Fallout3.exe Report Id: d981a724-0cb9-11e2-a466-00248c444208
Error - 02/10/2012 9:11:57 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Fallout3.exe, version: 1.7.0.3, time stamp:
0x4a40f18b Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0x1d24 Faulting application
start time: 0x01cda0d2e1451dab Faulting application path: X:\Games\Fallout 3\Fallout3.exe
Faulting
module path: unknown Report Id: 5321fb71-0cf7-11e2-a466-00248c444208
Error - 04/10/2012 1:50:30 AM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Fallout3.exe, version: 1.7.0.3, time stamp:
0x4a40f18b Faulting module name: Fallout3.exe, version: 1.7.0.3, time stamp: 0x4a40f18b
Exception
code: 0xc0000005 Fault offset: 0x007ecef3 Faulting process id: 0x5194 Faulting application
start time: 0x01cda1ef723da334 Faulting application path: X:\Games\Fallout 3\Fallout3.exe
Faulting
module path: X:\Games\Fallout 3\Fallout3.exe Report Id: 67128114-0de7-11e2-a23c-00248c444208
Error - 04/10/2012 7:52:07 PM | Computer Name = Win7-DP.porter.local | Source = Application Hang | ID = 1002
Description = The program Fallout3.exe version 1.7.0.3 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2da4 Start
Time: 01cda2757a847311 Termination Time: 229 Application Path: X:\Games\Fallout 3\Fallout3.exe
Report
Id: 7a204bc3-0e7e-11e2-a23c-00248c444208
Error - 04/10/2012 11:00:05 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Borderlands.exe, version: 1.4.2.1, time
stamp: 0x4eddb1bf Faulting module name: Borderlands.exe, version: 1.4.2.1, time
stamp: 0x4eddb1bf Exception code: 0xc0000005 Fault offset: 0x006ad78a Faulting process
id: 0x23c4 Faulting application start time: 0x01cda2a581199851 Faulting application
path: x:\steam\steamapps\common\borderlands\Binaries\Borderlands.exe Faulting module
path: x:\steam\steamapps\common\borderlands\Binaries\Borderlands.exe Report Id:
c2f06427-0e98-11e2-a23c-00248c444208
Error - 04/10/2012 11:00:09 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Borderlands.exe, version: 1.4.2.1, time
stamp: 0x4eddb1bf Faulting module name: Borderlands.exe, version: 1.4.2.1, time
stamp: 0x4eddb1bf Exception code: 0xc0000005 Fault offset: 0x0145dab7 Faulting process
id: 0x23c4 Faulting application start time: 0x01cda2a581199851 Faulting application
path: x:\steam\steamapps\common\borderlands\Binaries\Borderlands.exe Faulting module
path: x:\steam\steamapps\common\borderlands\Binaries\Borderlands.exe Report Id:
c558e1ae-0e98-11e2-a23c-00248c444208
Error - 05/10/2012 12:57:20 PM | Computer Name = Win7-DP.porter.local | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddCoreCsiFiles : GetNextFileMapContent() failed.
System
Error: The parameter is incorrect. .
Error - 05/10/2012 12:57:20 PM | Computer Name = Win7-DP.porter.local | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddCoreCsiFiles : GetNextFileMapContent() failed.
System
Error: The parameter is incorrect. .
Error - 05/10/2012 1:45:34 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 21.0.1180.83, time
stamp: 0x502eaec7 Faulting module name: USP10.dll, version: 1.626.7601.17514, time
stamp: 0x4ce7ba29 Exception code: 0xc0000005 Fault offset: 0x00047075 Faulting process
id: 0x1eb4 Faulting application start time: 0x01cda32136d5b52e Faulting application
path: C:\Users\Dan\AppData\Local\Google\Chrome\Application\chrome.exe Faulting module
path: C:\Windows\syswow64\USP10.dll Report Id: 7633134d-0f14-11e2-8c3e-00248c444208
Error - 05/10/2012 1:59:22 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 21.0.1180.83, time
stamp: 0x502eaec7 Faulting module name: USP10.dll, version: 1.626.7601.17514, time
stamp: 0x4ce7ba29 Exception code: 0xc0000005 Fault offset: 0x00047075 Faulting process
id: 0x1090 Faulting application start time: 0x01cda323254da37b Faulting application
path: C:\Users\Dan\AppData\Local\Google\Chrome\Application\chrome.exe Faulting module
path: C:\Windows\syswow64\USP10.dll Report Id: 63af38ca-0f16-11e2-8c3e-00248c444208
Error - 05/10/2012 2:00:04 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: opera.exe, version: 11.52.1100.0, time
stamp: 0x4e9c6c1d Faulting module name: USP10.dll, version: 1.626.7601.17514, time
stamp: 0x4ce7ba29 Exception code: 0xc0000005 Fault offset: 0x00047075 Faulting process
id: 0x1ff4 Faulting application start time: 0x01cda3233f2501d8 Faulting application
path: D:\Program Files (x86)\Opera\opera.exe Faulting module path: C:\Windows\syswow64\USP10.dll
Report
Id: 7cf7264e-0f16-11e2-8c3e-00248c444208
Error - 05/10/2012 7:39:59 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Steam.exe, version: 1.0.1446.623, time
stamp: 0x5004ae1a Faulting module name: libcef.dll, version: 1.989.464.0, time stamp:
0x502d6408 Exception code: 0x80000003 Fault offset: 0x0002f1a0 Faulting process id:
0x21c Faulting application start time: 0x01cda352b20aca40 Faulting application path:
X:\Steam\Steam.exe Faulting module path: X:\Steam\bin\libcef.dll Report Id: f93ad5f3-0f45-11e2-86fd-00248c444208
Error - 05/10/2012 7:40:21 PM | Computer Name = Win7-DP.porter.local | Source = Application Error | ID = 1000
Description = Faulting application name: Steam.exe, version: 1.0.1446.623, time
stamp: 0x5004ae1a Faulting module name: libcef.dll, version: 1.989.464.0, time stamp:
0x502d6408 Exception code: 0x80000003 Fault offset: 0x0002f1a0 Faulting process id:
0x7c4 Faulting application start time: 0x01cda352bf60605c Faulting application path:
X:\Steam\Steam.exe Faulting module path: X:\Steam\bin\libcef.dll Report Id: 064aaf79-0f46-11e2-86fd-00248c444208
[ System Events ]
Error - 05/10/2012 8:23:06 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:23:06 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:23:06 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:23:06 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:23:12 PM | Computer Name = Win7-DP.porter.local | Source = DCOM | ID = 10005
Description =
Error - 05/10/2012 8:23:13 PM | Computer Name = Win7-DP.porter.local | Source = DCOM | ID = 10005
Description =
Error - 05/10/2012 8:23:12 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:24:35 PM | Computer Name = Win7-DP.porter.local | Source = Service Control Manager | ID = 7001
Description = The PnP-X IP Bus Enumerator service depends on the Function Discovery
Provider Host service which failed to start because of the following error: %%1068
Error - 05/10/2012 8:29:26 PM | Computer Name = Win7-DP.porter.local | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain PORTER due to the following: %%1311 This may lead to authentication problems.
Make sure that this computer is connected to the network. If the problem persists,
please
contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller
for the specified domain, it sets up the secure session to the primary domain controller
emulator in the specified domain. Otherwise, this computer sets up the secure session
to any domain controller in the specified domain.
Error - 05/10/2012 8:29:28 PM | Computer Name = Win7-DP.porter.local | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.
< End of report >