TCF ran OK.
System restore returned an error:
See the end of this message for details on invoking
just-in-time (JIT) debugging instead of this dialog box.
************** Exception Text **************
System.Runtime.InteropServices.COMException (0x80080005): Server execution failed
at Microsoft.VisualBasic.CompilerServices.LateBinding.LateGet(Object o, Type objType, String name, Object[] args, String[] paramnames, Boolean[] CopyBack)
at Microsoft.VisualBasic.CompilerServices.NewLateBinding.LateGet(Object Instance, Type Type, String MemberName, Object[] Arguments, String[] ArgumentNames, Type[] TypeArguments, Boolean[] CopyBack)
at SysRestorePoint.Module1.CreateRestorePoint()
at SysRestorePoint.Form1.Form1_Load(Object eventSender, EventArgs eventArgs)
at System.EventHandler.Invoke(Object sender, EventArgs e)
at System.Windows.Forms.Form.OnLoad(EventArgs e)
at System.Windows.Forms.Form.OnCreateControl()
at System.Windows.Forms.Control.CreateControl(Boolean fIgnoreVisible)
at System.Windows.Forms.Control.CreateControl()
at System.Windows.Forms.Control.WmShowWindow(Message& m)
at System.Windows.Forms.Control.WndProc(Message& m)
at System.Windows.Forms.ScrollableControl.WndProc(Message& m)
at System.Windows.Forms.ContainerControl.WndProc(Message& m)
at System.Windows.Forms.Form.WmShowWindow(Message& m)
at System.Windows.Forms.Form.WndProc(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
************** Loaded Assemblies **************
mscorlib
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3082 (QFE.050727-3000)
CodeBase: file:///c:/WINDOWS/Microsoft.NET/Framework/v2.0.50727/mscorlib.dll
----------------------------------------
SysRestorePoint
Assembly Version: 1.3.0.0
Win32 Version: 1.3.0.0
CodeBase: file:///J:/SysRestorePoint.exe
----------------------------------------
Microsoft.VisualBasic
Assembly Version: 8.0.0.0
Win32 Version: 8.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/Microsoft.VisualBasic/8.0.0.0__b03f5f7f11d50a3a/Microsoft.VisualBasic.dll
----------------------------------------
System
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System/2.0.0.0__b77a5c561934e089/System.dll
----------------------------------------
System.Windows.Forms
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System.Windows.Forms/2.0.0.0__b77a5c561934e089/System.Windows.Forms.dll
----------------------------------------
System.Drawing
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System.Drawing/2.0.0.0__b03f5f7f11d50a3a/System.Drawing.dll
----------------------------------------
System.Runtime.Remoting
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System.Runtime.Remoting/2.0.0.0__b77a5c561934e089/System.Runtime.Remoting.dll
----------------------------------------
System.Configuration
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3053 (netfxsp.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System.Configuration/2.0.0.0__b03f5f7f11d50a3a/System.Configuration.dll
----------------------------------------
System.Xml
Assembly Version: 2.0.0.0
Win32 Version: 2.0.50727.3082 (QFE.050727-3000)
CodeBase: file:///C:/WINDOWS/assembly/GAC_MSIL/System.Xml/2.0.0.0__b77a5c561934e089/System.Xml.dll
----------------------------------------
************** JIT Debugging **************
To enable just-in-time (JIT) debugging, the .config file for this
application or computer (machine.config) must have the
jitDebugging value set in the system.windows.forms section.
The application must also be compiled with debugging
enabled.
For example:
<configuration>
<system.windows.forms jitDebugging="true" />
</configuration>
When JIT debugging is enabled, any unhandled exception
will be sent to the JIT debugger registered on the computer
rather than be handled by this dialog box.
ERUNT ran OK.
Malwarebytes starts scan and closes unexpectedly. No results to post.
Unable to install any antivirus.
Unable to run Windows updates. Service is stopped and says I don't have privilages to start in services.msc.
RootRepeal:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/17 17:21
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: 1b5981ef.sys
Image Path: C:\WINDOWS\System32\drivers\1b5981ef.sys
Address: 0xB5C9F000 Size: 80000 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB5C3B000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79CB000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB5DC4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF77DF000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xF76E7000 Size: 61440 File Visible: No Signed: -
Status: -
Hidden Services
-------------------
Service Name: 1b5981ef
Image Path: C:\WINDOWS\System32\drivers\1b5981ef.sys
Service Name: gasfkyubcdtaqd
Image Path: C:\WINDOWS\system32\drivers\gasfkyonfaqusv.sys
==EOF==
OTL.txt
OTL logfile created on: 10/17/2009 5:26:13 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = J:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 75.62% Memory free
3.35 Gb Paging File | 3.10 Gb Available in Paging File | 92.48% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 55.09 Gb Free Space | 72.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 488.00 Mb Total Space | 259.70 Mb Free Space | 53.22% Space Free | Partition Type: FAT
Computer Name: OWNER-3IIDJGMQC
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/17 16:33:44 | 00,521,216 | ---- | M] (OldTimer Tools) -- J:\OTL.exe
PRC - [2009/07/29 20:54:38 | 00,122,368 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2008/10/10 06:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/08/09 02:27:52 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
PRC - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe
PRC - [2006/03/31 18:37:33 | 00,028,672 | ---- | M] () -- C:\WINDOWS\System32\qttask.exe
PRC - [2006/02/21 22:39:15 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
========== Win32 Services (SafeList) ==========
SRV - [2009/10/03 05:47:47 | 00,022,016 | ---- | M] () -- C:\WINDOWS\System32\mssrv32.exe -- (msupdate [Auto | Stopped])
SRV - [2009/09/24 06:17:32 | 01,169,232 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (lavasoft ad-aware service [Auto | Stopped])
SRV - [2009/07/29 20:54:33 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/10/10 06:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/04/13 19:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2007/08/09 02:27:52 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [Auto | Running])
SRV - [2006/02/21 22:39:15 | 00,405,504 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2006/02/21 22:05:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2003/07/28 13:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/06 03:00:23 | 00,000,000 | ---D | M]
O1 HOSTS File: (755 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 microsoft
O2 - BHO: (C:\WINDOWS\system32\ybr37z5.dll) - {a249bc15-23f2-42ad-f4e4-00aac39c0004} - C:\WINDOWS\System32\ybr37z5.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [adobe photo downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [calc] C:\WINDOWS\System32\calc.DLL (Microsoft)
O4 - HKLM..\Run: [cmaudio] ._.Trashes ()
O4 - HKLM..\Run: [google quick search box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [hp software update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [jivolibik] c:\Documents and Settings\All Users\Application Data\biwagile\biwagile.dll ()
O4 - HKLM..\Run: [kernelfaultcheck] File not found
O4 - HKLM..\Run: [quicktime task] C:\WINDOWS\System32\qttask.exe ()
O4 - HKCU..\Run: [h/pc connection agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [spybotsd teatimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [wmpnscfg] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Yjafosi8kdf98winmdkmnkmfnwe] C:\DOCUME~1\OWNERO~1.000\LOCALS~1\Temp\lsass.exe File not found
O4 - HKCU..\Run: [zipscript] C:\Program Files\WORDsearch 8\ZipScript.exe (WORDsearch Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 93 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1142023616523 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1 4.2.2.2
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\lbxfile {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files\Libronix DLS\System\FileProt.dll (Libronix Corporation)
O18 - Protocol\Handler\lbxres {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files\Libronix DLS\System\ResProt.dll (Libronix Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\3618xxx.dll) - C:\WINDOWS\TEMP\3618xxx.dll File not found
O20 - AppInit_DLLs: (joyikeza.dll) - C:\WINDOWS\System32\joyikeza.dll ()
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\3634xxx.dll) - C:\WINDOWS\TEMP\3634xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\371xxx.dll) - C:\WINDOWS\TEMP\371xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\385xxx.dll) - C:\WINDOWS\TEMP\385xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\3921xxx.dll) - C:\WINDOWS\TEMP\3921xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\3937xxx.dll) - C:\WINDOWS\TEMP\3937xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\3947xxx.dll) - C:\WINDOWS\TEMP\3947xxx.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\TEMP\4015xxx.dll) - C:\WINDOWS\TEMP\4015xxx.dll File not found
O20 - AppInit_DLLs: (c:\DOCUME~1\ALLUSE~1\APPLIC~1\biwagile\biwagile.dll) - c:\Documents and Settings\All Users\Application Data\biwagile\biwagile.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\System32\sdra64.exe ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O21 - SSODL: divulamat - {7abce5ca-8e96-4f27-9345-a7424183332c} - c:\Documents and Settings\All Users\Application Data\biwagile\biwagile.dll ()
O22 - SharedTaskScheduler: {7abce5ca-8e96-4f27-9345-a7424183332c} - gahurihor - c:\Documents and Settings\All Users\Application Data\biwagile\biwagile.dll ()
O22 - SharedTaskScheduler: {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - iukjsf8w3jirojs9f8u3jruhsf78s3jijdif - C:\WINDOWS\System32\ybr37z5.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/09 17:16:56 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{b287eb01-b0fc-11dc-b607-000d875637b0}\Shell - "" = AutoRun
O33 - MountPoints2\{b287eb01-b0fc-11dc-b607-000d875637b0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b287eb01-b0fc-11dc-b607-000d875637b0}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
NetSvcs: Wmipsc - Service key not found. File not found
========== Files/Folders - Created Within 14 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/10/17 15:47:51 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\biwagile
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\darakibe
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\lusiyuge
[2009/10/05 15:37:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\rorusofa
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\semoyesi
[2009/10/04 01:41:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\tifeliri
[2009/10/05 13:31:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\BILEVSE
[2009/10/05 15:37:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Malwarebytes
[2009/10/05 13:35:43 | 00,000,000 | ---D | C] -- C:\Program Files\Angle Interactive
[2009/10/17 16:43:25 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/06 13:33:26 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/05 15:40:38 | 00,000,000 | ---D | C] -- C:\Program Files\New Folder
[2009/10/05 13:31:37 | 00,000,000 | ---D | C] -- C:\Program Files\Registry Convoy 2009
[2009/10/04 18:47:10 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Police Pro
[2009/10/17 16:44:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/17 15:48:09 | 00,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/10/17 15:48:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/10/06 13:33:27 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/06 13:33:26 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/06 13:28:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/10/05 16:45:03 | 00,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2009/10/05 13:35:43 | 00,000,000 | ---D | C] -- C:\ProgramData
[2009/10/04 22:01:20 | 04,165,792 | ---- | C] (Sammsoft ) -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\AROTrial_mt.exe
========== Files - Modified Within 14 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/10/17 17:26:35 | 00,080,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\1b5981ef.sys
[2009/10/17 17:21:38 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\miwekuro
[2009/10/17 17:19:16 | 00,052,736 | -HS- | M] () -- C:\WINDOWS\System32\mosowisi.dll
[2009/10/17 17:18:59 | 00,001,531 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\Windows Police Pro.lnk
[2009/10/17 17:18:46 | 01,089,058 | -HS- | M] () -- C:\WINDOWS\System32\rinapiza.exe
[2009/10/17 17:18:46 | 01,079,842 | -HS- | M] () -- C:\WINDOWS\System32\fupipivo.exe
[2009/10/17 17:10:38 | 00,039,424 | -HS- | M] () -- C:\WINDOWS\System32\pupamawe.dll
[2009/10/17 16:47:11 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/17 16:47:03 | 00,000,000 | ---- | M] () -- C:\WINDOWS\win32k.sys
[2009/10/17 16:47:02 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/17 16:45:23 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/17 16:43:25 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\NTREGOPT.lnk
[2009/10/17 16:43:25 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\ERUNT.lnk
[2009/10/17 16:35:53 | 00,005,008 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\sysrestorepoint error.rtf
[2009/10/17 15:52:57 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/17 15:52:31 | 00,013,002 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/17 15:47:50 | 00,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/06 19:17:17 | 00,000,890 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/10/06 19:17:17 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/10/06 19:17:17 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/10/06 18:33:08 | 00,085,612 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\cc_20091006_1833.reg
[2009/10/05 14:16:57 | 00,052,224 | -HS- | M] () -- C:\WINDOWS\System32\kavunize.dll
[2009/10/05 14:16:39 | 01,048,099 | -HS- | M] () -- C:\WINDOWS\System32\nadejafi.exe
[2009/10/05 14:16:27 | 00,090,624 | -HS- | M] () -- C:\WINDOWS\System32\zomuhiwu.dll
[2009/10/05 14:16:27 | 00,038,912 | -HS- | M] () -- C:\WINDOWS\System32\radisezo.dll
[2009/10/05 14:04:54 | 16,409,960 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\setup-spybotsd162.exe
[2009/10/05 13:31:46 | 00,000,366 | ---- | M] () -- C:\WINDOWS\tasks\RegistryConvoy.job
[2009/10/05 13:31:37 | 00,000,619 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\Registry Convoy 2009.lnk
[2009/10/04 22:02:20 | 04,165,792 | ---- | M] (Sammsoft ) -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\AROTrial_mt.exe
[2009/10/04 21:54:47 | 00,000,837 | ---- | M] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\Spybot - Search & Destroy.lnk
[2009/10/04 20:35:50 | 01,955,840 | ---- | M] () -- C:\WINDOWS\System32\AVR09.exe
[2009/10/04 20:35:39 | 00,022,528 | ---- | M] () -- C:\WINDOWS\System32\winhelper.dll
[2009/10/04 20:35:23 | 00,000,831 | ---- | M] () -- C:\WINDOWS\System32\critical_warning.html
[2009/10/04 18:47:14 | 00,000,046 | ---- | M] () -- C:\p2hhr.bat
[2009/10/04 18:47:07 | 00,034,243 | ---- | M] () -- C:\pmkvle.exe
[2009/10/04 18:47:05 | 00,189,960 | ---- | M] () -- C:\ngvh.exe
[2009/10/04 18:47:02 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\px7jlhlaa.dll
[2009/10/04 18:47:01 | 00,213,067 | ---- | M] () -- C:\gpsjumwh.exe
[2009/10/04 18:47:00 | 00,052,224 | ---- | M] () -- C:\nysin.exe
[2009/10/04 18:46:58 | 00,019,456 | ---- | M] () -- C:\tlvkon.exe
[2009/10/04 18:46:57 | 00,161,280 | ---- | M] () -- C:\apkjixyw.exe
[2009/10/04 18:46:57 | 00,045,568 | ---- | M] () -- C:\rurqq.exe
[2009/10/04 18:46:55 | 00,009,728 | ---- | M] () -- C:\lqxebik.exe
[2009/10/04 18:06:09 | 00,000,442 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009/10/04 13:41:42 | 00,052,736 | -HS- | M] () -- C:\WINDOWS\System32\melamiro.dll
[2009/10/04 13:41:16 | 01,048,611 | -HS- | M] () -- C:\WINDOWS\System32\hememefo.exe
[2009/10/04 13:41:12 | 00,090,624 | -HS- | M] () -- C:\WINDOWS\System32\pularewi.dll
[2009/10/04 13:41:11 | 00,038,912 | -HS- | M] () -- C:\WINDOWS\System32\silulawo.dll
[2009/10/04 01:40:23 | 00,051,200 | ---- | M] () -- C:\dkvyax.exe
[2009/10/04 01:40:21 | 00,079,360 | ---- | M] () -- C:\hsjcyle.exe
[2009/10/04 01:40:20 | 00,043,520 | ---- | M] () -- C:\rmnkbgw.exe
[2009/10/04 01:40:19 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\ybr37z5.dll
[2009/10/04 01:40:18 | 00,009,728 | ---- | M] () -- C:\luqnovd.exe
[2009/10/04 01:39:54 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\pj2yox5.dll
[2009/10/04 01:39:29 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\kqkeo7.dll
[2009/10/04 01:38:52 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\xyvj1dk.dll
[2009/10/04 01:38:10 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\mru1ycog.dll
[2009/10/04 01:37:59 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\ln9m9vv.dll
[2009/10/04 01:37:16 | 00,189,841 | ---- | M] () -- C:\ituycggj.exe
[2009/10/04 01:36:56 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\bgrej.dll
[2009/10/04 01:36:32 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\c3fx01t.dll
[2009/10/04 01:36:15 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\lybmp.dll
[2009/10/04 01:35:39 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\zsn4yys4.dll
[2009/10/04 00:33:00 | 00,000,416 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version2.job
========== Files - No Company Name ==========
[2009/10/17 17:18:59 | 00,001,531 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\Windows Police Pro.lnk
[2009/10/17 16:45:23 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/17 16:43:25 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\NTREGOPT.lnk
[2009/10/17 16:43:25 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\ERUNT.lnk
[2009/10/17 16:35:53 | 00,005,008 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\sysrestorepoint error.rtf
[2009/10/17 15:49:09 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/17 15:47:50 | 00,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/06 19:35:50 | 00,472,064 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\RootRepeal.exe
[2009/10/06 19:29:14 | 00,361,369 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\dds.scr
[2009/10/06 19:17:17 | 00,001,879 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2009/10/06 19:17:17 | 00,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/10/06 19:17:17 | 00,000,869 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
[2009/10/06 19:17:17 | 00,000,773 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
[2009/10/06 18:33:06 | 00,085,612 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\My Documents\cc_20091006_1833.reg
[2009/10/05 14:02:31 | 16,409,960 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\setup-spybotsd162.exe
[2009/10/05 13:31:45 | 00,000,366 | ---- | C] () -- C:\WINDOWS\tasks\RegistryConvoy.job
[2009/10/05 13:31:37 | 00,000,619 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Desktop\Registry Convoy 2009.lnk
[2009/10/04 18:47:14 | 00,000,046 | ---- | C] () -- C:\p2hhr.bat
[2009/10/04 18:47:06 | 00,034,243 | ---- | C] () -- C:\pmkvle.exe
[2009/10/04 18:47:02 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\px7jlhlaa.dll
[2009/10/04 18:47:00 | 00,189,960 | ---- | C] () -- C:\ngvh.exe
[2009/10/04 18:46:57 | 00,019,456 | ---- | C] () -- C:\tlvkon.exe
[2009/10/04 18:46:56 | 00,045,568 | ---- | C] () -- C:\rurqq.exe
[2009/10/04 18:46:55 | 00,009,728 | ---- | C] () -- C:\lqxebik.exe
[2009/10/04 01:45:30 | 00,000,000 | ---- | C] () -- C:\WINDOWS\win32k.sys
[2009/10/04 01:40:19 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\ybr37z5.dll
[2009/10/04 01:40:08 | 00,009,728 | ---- | C] () -- C:\luqnovd.exe
[2009/10/04 01:39:54 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\pj2yox5.dll
[2009/10/04 01:39:35 | 00,079,360 | ---- | C] () -- C:\hsjcyle.exe
[2009/10/04 01:39:29 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\kqkeo7.dll
[2009/10/04 01:38:52 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\xyvj1dk.dll
[2009/10/04 01:38:25 | 01,955,840 | ---- | C] () -- C:\WINDOWS\System32\AVR09.exe
[2009/10/04 01:38:24 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\winhelper.dll
[2009/10/04 01:38:10 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\mru1ycog.dll
[2009/10/04 01:37:59 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\ln9m9vv.dll
[2009/10/04 01:36:56 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\bgrej.dll
[2009/10/04 01:36:32 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\c3fx01t.dll
[2009/10/04 01:36:15 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\lybmp.dll
[2009/10/04 01:36:12 | 00,189,841 | ---- | C] () -- C:\ituycggj.exe
[2009/10/04 01:36:09 | 00,051,200 | ---- | C] () -- C:\dkvyax.exe
[2009/10/04 01:36:03 | 00,043,520 | ---- | C] () -- C:\rmnkbgw.exe
[2009/10/04 01:35:58 | 00,080,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\1b5981ef.sys
[2009/10/04 01:35:39 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\zsn4yys4.dll
[2009/10/04 01:35:35 | 00,000,831 | ---- | C] () -- C:\WINDOWS\System32\critical_warning.html
[2009/10/04 01:35:32 | 00,213,067 | ---- | C] () -- C:\gpsjumwh.exe
[2009/10/04 01:35:29 | 00,052,224 | ---- | C] () -- C:\nysin.exe
[2009/10/04 01:35:28 | 00,161,280 | ---- | C] () -- C:\apkjixyw.exe
[2009/08/03 14:37:17 | 00,000,023 | ---- | C] () -- C:\WINDOWS\Mahjongg Variations.INI
[2009/07/17 17:10:38 | 00,091,648 | -HS- | C] () -- C:\WINDOWS\System32\nujaduha.dll
[2009/07/17 17:10:38 | 00,052,736 | -HS- | C] () -- C:\WINDOWS\System32\mosowisi.dll
[2009/07/17 17:10:38 | 00,039,424 | -HS- | C] () -- C:\WINDOWS\System32\pupamawe.dll
[2009/07/05 14:16:26 | 00,090,624 | -HS- | C] () -- C:\WINDOWS\System32\zomuhiwu.dll
[2009/07/05 14:16:26 | 00,052,224 | -HS- | C] () -- C:\WINDOWS\System32\kavunize.dll
[2009/07/05 14:16:26 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\radisezo.dll
[2009/07/04 13:41:11 | 00,090,624 | -HS- | C] () -- C:\WINDOWS\System32\pularewi.dll
[2009/07/04 13:41:11 | 00,052,736 | -HS- | C] () -- C:\WINDOWS\System32\melamiro.dll
[2009/07/04 13:41:11 | 00,038,912 | -HS- | C] () -- C:\WINDOWS\System32\silulawo.dll
[2009/07/04 01:35:35 | 00,051,200 | -HS- | C] () -- C:\WINDOWS\System32\zihanine.dll
[2009/07/04 01:35:35 | 00,051,200 | -HS- | C] () -- C:\WINDOWS\System32\yokifafa.dll
[2009/07/04 01:35:35 | 00,051,200 | -HS- | C] () -- C:\WINDOWS\System32\joyikeza.dll
[2008/08/16 11:11:46 | 00,000,058 | ---- | C] () -- C:\WINDOWS\TTN.INI
[2007/09/22 19:28:31 | 00,000,071 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini
[2007/09/16 14:59:19 | 00,000,429 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/07/20 10:18:49 | 00,000,335 | ---- | C] () -- C:\WINDOWS\Trpmaker.INI
[2007/07/20 10:18:19 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\PlugFile.dll
[2007/07/20 10:08:25 | 00,000,039 | ---- | C] () -- C:\WINDOWS\Winhelp.INI
[2007/07/20 10:08:24 | 00,000,186 | ---- | C] () -- C:\WINDOWS\RPlanner.INI
[2007/07/20 10:07:48 | 00,038,688 | ---- | C] () -- C:\WINDOWS\System32\Leaddib.drv
[2007/07/20 10:07:46 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
[2007/07/20 10:07:41 | 00,011,136 | ---- | C] () -- C:\WINDOWS\System32\Fprun300.dll
[2006/12/23 15:57:01 | 00,000,894 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Hewlett-PackardHP Photosmart 3300 series1160495728_PROTOCOL.log
[2006/12/23 15:57:00 | 00,004,619 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Hewlett-PackardHP Photosmart 3300 series1160495728_UI.log
[2006/12/23 15:57:00 | 00,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini
[2006/12/23 15:57:00 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Hewlett-PackardHP Photosmart 3300 series1160495728_API.log
[2006/09/11 20:38:49 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/11 20:20:45 | 00,000,063 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/07/18 08:01:46 | 00,344,479 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/07/18 08:01:46 | 00,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/07/18 08:01:36 | 00,004,176 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\HPSU_48BitScanUpdate.log
[2006/07/18 08:01:36 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/07/18 08:00:30 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\HelpFilesUpdatePatch_HELPFILEREPLACE.log
[2006/07/18 08:00:29 | 00,000,716 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\HelpFilesUpdatePatch_PRINTHELPWRAPPER.log
[2006/07/18 08:00:29 | 00,000,234 | ---- | C] () -- C:\WINDOWS\PrnHlpLogConfig.ini
[2006/07/18 08:00:17 | 00,004,828 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\PatchUpdate_HP_ISRegionListUpdatelog_HPSU.log
[2006/07/18 08:00:17 | 00,000,228 | ---- | C] () -- C:\WINDOWS\HP_ISRegionListUpdatelog_HPSU.ini
[2006/07/18 08:00:05 | 00,005,646 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\PatchUpdate_InstantShareJPG.log
[2006/07/18 08:00:05 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/07/18 07:59:39 | 00,007,321 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\PatchUpdate_IZClosingDiscError.log
[2006/07/18 07:59:39 | 00,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2006/07/18 07:56:44 | 00,005,848 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/07/18 07:56:44 | 00,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/07/18 07:53:44 | 00,269,908 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/07/18 07:53:44 | 00,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/07/16 21:38:10 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2006/03/31 19:01:21 | 00,001,607 | ---- | C] () -- C:\Program Files\uninstal.log
[2006/03/14 21:07:09 | 00,009,711 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/03/14 14:13:32 | 00,002,508 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\$_hpcst$.hpc
[2006/03/13 16:28:40 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/03/10 21:14:55 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\UnAudioNT.dll
[2006/03/10 20:46:08 | 00,000,148 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Local Settings\Application Data\fusioncache.dat
[2006/03/10 20:42:44 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2006/03/10 20:36:20 | 00,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2006/03/10 20:36:19 | 00,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2006/03/10 16:21:37 | 00,082,848 | ---- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/03/10 15:02:01 | 06,395,536 | -H-- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Local Settings\Application Data\IconCache.db
[2006/03/10 15:01:22 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\desktop.ini
[2006/03/09 11:01:34 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2005/08/27 19:41:50 | 00,032,768 | R--- | C] () -- C:\WINDOWS\System32\dwsvclnt.dll
[2004/09/17 18:37:42 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2003/02/18 19:26:28 | 00,028,672 | R--- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/04 03:24:26 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2001/08/18 07:00:00 | 00,061,952 | ---- | C] () -- C:\WINDOWS\System32\eventlog.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Wmipsiv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Wmipscv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\WmdmPv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Nwsapv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\NWCWov32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Irmonv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Ipripv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\Iasv32.dll
[2001/08/18 07:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\6to4v32.dll
[2001/08/18 07:00:00 | 00,002,304 | ---- | C] () -- C:\WINDOWS\System32\isasdk.sys
[2001/08/18 07:00:00 | 00,000,890 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/18 07:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/07/06 15:30:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2009/10/17 15:47:51 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/10/29 19:17:05 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{4A8C70B4-22EC-4060-8BF4-A88F7B8448DE}
[2008/01/19 16:57:27 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{B306A3A9-A7C4-4B0D-9D6A-DD50F415168A}
[2009/10/17 15:47:51 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2008/10/29 19:13:38 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{F86C4463-4448-48BD-9E9E-83A333A8E98B}
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\biwagile
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\darakibe
[2009/01/23 19:37:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2009/05/02 09:42:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/02/11 21:22:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2009/08/09 14:43:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2008/10/29 19:13:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LESSONmaker
[2006/10/29 22:27:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Libronix DLS
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\lusiyuge
[2009/01/23 19:38:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\rorusofa
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\semoyesi
[2009/08/09 15:54:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/04 01:41:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tifeliri
[2008/10/29 19:39:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WORDsearch
[2008/01/19 16:56:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wsc
[2009/10/05 15:37:43 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data
[2006/03/10 20:46:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\ATI
[2009/10/05 13:31:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\BILEVSE
[2009/01/23 19:39:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\DriverCure
[2009/08/03 15:51:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Gaijin Ent
[2008/04/09 15:18:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Intuit
[2006/08/07 17:41:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Leadertech
[2006/10/29 22:27:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\Libronix DLS
[2009/08/09 14:36:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\SpinTop
[2009/08/30 14:25:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\U3
[2008/11/16 16:38:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner.OWNER-3IIDJGMQC.000\Application Data\W Photo Studio Viewer
[2009/10/17 15:52:57 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2001/08/18 07:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/04 18:06:09 | 00,000,442 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009/10/04 00:33:00 | 00,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version2.job
[2009/10/05 13:31:46 | 00,000,366 | ---- | M] () -- C:\WINDOWS\Tasks\RegistryConvoy.job
[2009/10/17 16:47:11 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2009/10/04 18:46:57 | 00,161,280 | ---- | M] () -- C:\apkjixyw.exe
[2009/10/04 01:40:23 | 00,051,200 | ---- | M] () -- C:\dkvyax.exe
[2009/10/04 18:47:05 | 00,167,424 | ---- | M] (Microsoft Corporation) -- C:\fmmvqn.exe
[2009/10/04 18:47:01 | 00,213,067 | ---- | M] () -- C:\gpsjumwh.exe
[2009/10/04 01:40:21 | 00,079,360 | ---- | M] () -- C:\hsjcyle.exe
[2009/10/04 01:37:16 | 00,189,841 | ---- | M] () -- C:\ituycggj.exe
[2009/10/04 18:46:55 | 00,009,728 | ---- | M] () -- C:\lqxebik.exe
[2009/10/04 01:40:18 | 00,009,728 | ---- | M] () -- C:\luqnovd.exe
[2009/10/04 18:47:05 | 00,189,960 | ---- | M] () -- C:\ngvh.exe
[2009/10/04 18:47:00 | 00,052,224 | ---- | M] () -- C:\nysin.exe
[2009/10/04 18:47:07 | 00,034,243 | ---- | M] () -- C:\pmkvle.exe
[2009/10/04 01:40:20 | 00,043,520 | ---- | M] () -- C:\rmnkbgw.exe
[2009/10/04 18:46:57 | 00,045,568 | ---- | M] () -- C:\rurqq.exe
[2009/10/04 18:46:58 | 00,019,456 | ---- | M] () -- C:\tlvkon.exe
[2009/10/04 01:36:07 | 00,161,280 | ---- | M] (Microsoft Corporation) -- C:\uheu.exe
< %systemroot%\system32\eventlog.dll >
[2008/04/13 19:11:53 | 00,061,952 | ---- | M] () -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\logevent.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:47BC930A
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F8104EE7
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:08FAADE1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:84E7BFEB
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DA18FD1D
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:211ED887
< End of report >
Extras.txt:
OTL Extras logfile created on: 10/17/2009 5:26:13 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = J:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 75.62% Memory free
3.35 Gb Paging File | 3.10 Gb Available in Paging File | 92.48% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 55.09 Gb Free Space | 72.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 488.00 Mb Total Space | 259.70 Mb Free Space | 53.22% Space Free | Partition Type: FAT
Computer Name: OWNER-3IIDJGMQC
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager -- (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application -- (Microsoft Corporation)
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client -- (Hewlett-Packard)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- ()
"C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
"C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
"C:\Program Files\Rand McNally\TripMaker\Trpmaker.exe" = C:\Program Files\Rand McNally\TripMaker\Trpmaker.exe:*:Enabled:Trpmaker -- ()
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"H:\TTN.exe" = H:\TTN.exe:*:Enabled:TTN -- File not found
"C:\TTN\TTN.exe" = C:\TTN\TTN.exe:*:Enabled:TTN -- (Nikasoft)
"C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)
"C:\WINDOWS\TEMP\p.exe" = C:\WINDOWS\TEMP\p.exe:*:Enabled:Enabled -- ()
"C:\WINDOWS\system32\qttask.exe" = C:\WINDOWS\system32\qttask.exe:*:Enabled:qttask -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0378C1D0-3F01-4074-AB93-E68A1CA32B7E}" = Bible Explorer 4 for LESSONmaker
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{1330F885-F8E4-4c36-9B88-E19F82042C06}" = 3100_3200_3300trb
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19991EAD-C273-47EB-87E8-0D274925230B}" = Oeb Resource Driver
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{25771101-7948-4591-ABF3-B1ECE7A7F45F}" = HP Update
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{4B9E068C-12BC-4B4F-9799-EE2ACE576BDD}" = WORDsearch 8 Basic Edition
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4ED47439-5232-4BBC-93F2-7BC895B56246}" = 3300
"{50E7BB78-02B4-469a-9D8B-B2F42835F90E}" = ProductContextNPI
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57707A73-5901-4306-B927-AA5B9A006EFF}" = LESSONmaker 8 Complete Edition
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{5F81DD84-6A2F-11D4-903E-00E0293397B7}" = Bible Data Type System Files
"{5F81DD89-6A2F-11D4-903E-00E0293397B7}" = Common System Files
"{5F81DD92-6A2F-11D4-903E-00E0293397B7}" = Libronix Digital Library System
"{5F81DD97-6A2F-11D4-903E-00E0293397B7}" = Libronix DLS Application
"{5F81DD9B-6A2F-11D4-903E-00E0293397B7}" = LibronixUpdate
"{5F81DD9F-6A2F-11D4-903E-00E0293397B7}" = LLS Resource Driver
"{5F81DDA3-6A2F-11D4-903E-00E0293397B7}" = PDF Resource Driver
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{76effc7c-17a6-479d-9e47-8e658c1695ae}" = Windows Backup Utility
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{90437E5F-0A9E-4B63-AD8B-D232897D18BF}" = ATI Parental Control & Encoder
"{91E30409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{b4092c6d-e886-4cb2-ba68-fe5a88d31de6}_is1" = Spybot - Search & Destroy
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2D95C7-189C-4596-B071-CE99C309573D}" = ATI Catalyst Control Center
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCDD8C24-EB4A-4BCC-BAFD-4812F9B70FDE}" = TurboTax 2008 wokiper
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4576E0D-2295-4B8E-B663-B68086B00EE5}" = Sonic CinePlayer DVD Pack
"{ded53b0b-b67c-4244-ae6a-d6fd3c28d1ef}" = Ad-Aware
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{F1931CAB-C7DD-4825-8A58-BC5278805200}" = 3100_3200_3300_Help
"{f333a33d-125c-32a2-8dce-5c5d14231e27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{f333a33d-125c-32a2-8dce-5c5d14231e27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"ad-aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Bible Explorer 4 for LESSONmaker" = Bible Explorer 4 for LESSONmaker
"CCleaner" = CCleaner (remove only)
"C-Media Audio Driver" = C-Media WDM Audio Driver
"Encyclopædia Britannica Ultimate Reference Suite" = Encyclopædia Britannica Ultimate Reference Suite
"erunt_is1" = ERUNT 1.1j
"Hoyle Classic Games" = Hoyle Classic Games
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"ie8" = Windows Internet Explorer 8
"LEARN Microsoft® Word xp" = LEARN Microsoft® Word xp
"LESSONmaker 8 Complete Edition" = LESSONmaker 8 Complete Edition
"Libronix DLS" = Libronix Digital Library System
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Mahjong Match" = Mahjong Match
"malwarebytes' anti-malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"QuickTime" = QuickTime
"Rahjongg The Curse of Ra" = Rahjongg The Curse of Ra
"registry convoy" = Registry Convoy 2009
"Sierra Utilities" = Sierra Utilities
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"TripMaker" = Rand McNally TripMaker 2000
"TurboTax 2008" = TurboTax 2008
"TurboTax Deluxe 2005" = TurboTax Deluxe 2005
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"TurboTax Premier 2007" = TurboTax Premier 2007
"VIA Audio Driver Setup Program" = VIA Audio Driver Setup Program
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WORDsearch 8 Basic Edition" = WORDsearch 8 Basic Edition
"WORDsearch Basic Edition" = WORDsearch Basic Edition
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar for Internet Explorer
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Route Planner" = Rand McNally Route Planner
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/13/2009 8:30:34 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:31:51 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:32:21 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:33:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 9:42:26 PM | Computer Name = OWNER-3IIDJGMQC | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 10/17/2009 4:10:43 PM | Computer Name = OWNER-3IIDJGMQC | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 10/17/2009 4:47:59 PM | Computer Name = OWNER-3IIDJGMQC | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 10/17/2009 5:05:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00e39554.
Error - 10/17/2009 5:06:09 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application wmpnetwk.exe, version 11.0.5721.5145, faulting
module unknown, version 0.0.0.0, fault address 0x0000000b.
Error - 10/17/2009 5:07:41 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application imapi.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000fe60.
[ Application Events ]
Error - 10/13/2009 8:30:34 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:31:51 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:32:21 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 8:33:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.
Error - 10/13/2009 9:42:26 PM | Computer Name = OWNER-3IIDJGMQC | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 10/17/2009 4:10:43 PM | Computer Name = OWNER-3IIDJGMQC | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 10/17/2009 4:47:59 PM | Computer Name = OWNER-3IIDJGMQC | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 10/17/2009 5:05:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00e39554.
Error - 10/17/2009 5:06:09 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application wmpnetwk.exe, version 11.0.5721.5145, faulting
module unknown, version 0.0.0.0, fault address 0x0000000b.
Error - 10/17/2009 5:07:41 PM | Computer Name = OWNER-3IIDJGMQC | Source = Application Error | ID = 1000
Description = Faulting application imapi.exe, version 5.1.2600.5512, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000fe60.
[ System Events ]
Error - 10/17/2009 6:12:23 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:13:39 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The BITS Registry key denied access to SYSTEM account programs so
the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:14:43 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:18:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:19:56 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:19:58 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:20:52 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:23:13 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:23:39 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The BITS Registry key denied access to SYSTEM account programs so
the Service Control Manager took ownership of the Registry key.
Error - 10/17/2009 6:25:18 PM | Computer Name = OWNER-3IIDJGMQC | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
< End of report >
Thanks for any help in advance.