OTL.Txt:
OTL logfile created on: 02/02/2010 21:51:56 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\Sara\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 18.99 Gb Free Space | 13.17% Space Free | Partition Type: NTFS
Drive D: | 144.15 Gb Total Space | 46.14 Gb Free Space | 32.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SARA-PC
Current User Name: Sara
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/02/02 21:50:05 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\Sara\Desktop\OTL.exe
PRC - [2010/01/22 19:16:42 | 000,141,608 | ---- | M] (Apple Inc.) -- D:\Program Files\iTunes\iTunesHelper.exe
PRC - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/12/18 08:58:20 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
PRC - [2009/12/10 10:54:09 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2009/10/01 16:03:14 | 001,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
PRC - [2009/09/23 22:27:50 | 000,172,032 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2009/08/25 23:39:33 | 000,117,640 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
PRC - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/04/11 06:28:08 | 000,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009/04/11 06:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/09/29 19:49:08 | 000,704,512 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2008/05/21 02:06:00 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/05/15 00:05:30 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
PRC - [2008/04/25 18:08:48 | 000,103,720 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PRC - [2008/04/25 18:08:40 | 001,049,896 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008/03/21 20:22:52 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
PRC - [2008/01/21 02:23:32 | 000,095,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mobsync.exe
PRC - [2007/01/17 18:20:10 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2006/11/29 00:44:58 | 000,386,560 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\drivers\XAudio.exe
PRC - [2006/11/02 19:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe
PRC - [2005/08/26 11:25:08 | 000,081,920 | ---- | M] (made by pr0g) -- C:\Users\Sara\Desktop\VoiceOverlay.exe
PRC - [2005/07/15 21:48:33 | 000,479,232 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Gmail Notifier\gnotify.exe
========== Modules (SafeList) ========== MOD - [2010/02/02 21:50:05 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\Sara\Desktop\OTL.exe
MOD - [2009/06/15 14:51:38 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
MOD - [2009/04/11 06:28:18 | 001,788,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
MOD - [2009/04/11 06:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 02:24:45 | 000,522,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ddraw.dll
MOD - [2008/01/21 02:24:18 | 001,039,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d8.dll
MOD - [2008/01/21 02:24:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2006/11/02 09:46:12 | 000,707,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\opengl32.dll
MOD - [2006/11/02 09:46:05 | 000,133,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\glu32.dll
MOD - [2006/11/02 09:46:03 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d8thk.dll
MOD - [2005/08/27 15:35:02 | 000,278,528 | ---- | M] (made by pr0g) -- C:\Windows\System32\VoiceInject.dll
MOD - [2005/07/15 14:41:30 | 002,337,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
========== Win32 Services (SafeList) ========== SRV - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/12/10 10:54:09 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-110309-193829)
SRV - [2009/10/01 16:03:14 | 001,858,144 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\a-squared Free\a2service.exe -- (a2free)
SRV - [2009/09/25 01:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/09/23 22:27:50 | 000,172,032 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009/08/25 23:39:33 | 000,117,640 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe -- (Norton AntiVirus)
SRV - [2009/05/29 12:41:26 | 000,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/04 00:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/09/29 19:49:08 | 000,704,512 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\Windows\System32\Ati2evxx.exe -- (Ati External Event Utility)
SRV - [2008/05/15 00:05:30 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service)
SRV - [2008/03/21 20:22:52 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService)
SRV - [2008/01/21 02:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/06 23:15:28 | 000,110,592 | ---- | M] () [Disabled | Stopped] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService)
SRV - [2007/01/17 18:20:10 | 000,061,440 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2006/11/29 00:44:58 | 000,386,560 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\System32\drivers\XAudio.exe -- (XAudioService)
SRV - [2006/11/02 19:40:12 | 000,174,656 | ---- | M] () [Auto | Running] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2006/11/02 12:35:29 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2006/11/02 09:46:05 | 000,017,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\irmon.dll -- (Irmon)
SRV - [2006/10/26 21:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_5535 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&a...p;m=aspire_5535IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000004
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/02/02 16:09:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/02/02 16:09:14 | 000,000,000 | ---D | M]
[2009/01/30 00:14:29 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Mozilla\Extensions
[2010/02/01 23:44:42 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ehjou0f7.default\extensions
[2009/02/21 03:49:47 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ehjou0f7.default\extensions\moveplayer@movenetworks.com
[2009/05/31 22:56:02 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ehjou0f7.default\extensions\searchrecs@veoh.com
[2010/01/21 20:07:37 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/02/01 21:01:34 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - No CLSID value found.
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - Startup: C:\Users\Sara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78}
https://portal.knightfrank.com/nps/portal/g...t/LocalExec.CAB (LocalExec Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Acer01.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer01.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 02:34:27 | 000,000,000 | ---D | M]
NetSvcs: Irmon - C:\Windows\System32\irmon.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!
========== Files/Folders - Created Within 14 Days ========== [2010/02/02 21:50:04 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\Users\Sara\Desktop\OTL.exe
[2010/02/02 16:12:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/02/02 16:08:29 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/02/01 21:11:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/02/01 20:48:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/02/01 18:40:11 | 000,000,000 | ---D | C] -- C:\Users\Sara\Documents\Selfish
[2010/02/01 18:36:43 | 000,000,000 | ---D | C] -- C:\Users\Sara\Documents\AquilineTwo
[2010/01/31 23:15:11 | 000,000,000 | ---D | C] -- C:\Users\Sara\AppData\Local\temp
[2010/01/31 22:49:27 | 000,000,000 | ---D | C] -- C:\schrauber
[2010/01/31 22:43:43 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/01/31 22:43:43 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/01/31 22:43:43 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/01/31 22:42:07 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/01/31 22:41:41 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/01/30 13:58:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/01/28 17:27:43 | 000,000,000 | ---D | C] -- C:\Users\Sara\AppData\Roaming\vlc
[2010/01/26 18:50:47 | 000,000,000 | ---D | C] -- C:\Users\Sara\AppData\Roaming\Uniblue
[2010/01/26 18:50:38 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2010/01/24 14:59:04 | 000,000,000 | ---D | C] -- C:\MGtools
[2010/01/22 18:31:22 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/01/22 18:31:08 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/22 18:30:43 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/21 23:01:37 | 000,000,000 | R--D | C] -- C:\Program Files\Norton Support
[2010/01/21 23:00:12 | 000,000,000 | ---D | C] -- C:\Users\Sara\AppData\Local\Symantec
[2010/01/20 12:31:26 | 000,000,000 | ---D | C] -- C:\Users\Sara\Documents\a-squared Free
[2010/01/20 12:31:26 | 000,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/03/11 11:57:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Sara\AppData\Roaming\pcouffin.sys
[2008/10/05 02:17:44 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[5 C:\Users\Sara\Documents\*.tmp files -> C:\Users\Sara\Documents\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2010/02/02 21:54:42 | 007,077,888 | ---- | M] () -- C:\Users\Sara\ntuser.dat
[2010/02/02 21:50:05 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\Sara\Desktop\OTL.exe
[2010/02/02 21:46:03 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 21:46:03 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 16:13:20 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/02/02 13:52:34 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/02/02 13:52:34 | 000,600,378 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/02/02 13:52:34 | 000,105,852 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/02/02 13:46:07 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/02/02 13:45:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/02/02 02:20:13 | 000,524,288 | -HS- | M] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TMContainer00000000000000000001.regtrans-ms
[2010/02/02 02:20:13 | 000,065,536 | -HS- | M] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TM.blf
[2010/02/02 02:20:10 | 001,350,541 | -H-- | M] () -- C:\Users\Sara\AppData\Local\IconCache.db
[2010/02/02 01:22:50 | 000,242,176 | ---- | M] () -- C:\Users\Sara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/02 01:21:33 | 000,002,828 | -HS- | M] () -- C:\Windows\System32\KGyGaAvL.sys
[2010/02/02 01:10:42 | 000,000,008 | RHS- | M] () -- C:\Windows\System32\D97797DCFB.sys
[2010/02/01 23:00:37 | 000,300,032 | ---- | M] () -- C:\Users\Sara\Documents\10015-NR Information Assistant x3 - Final.doc
[2010/02/01 23:00:13 | 000,175,104 | ---- | M] () -- C:\Users\Sara\Documents\pink.doc
[2010/02/01 22:28:48 | 000,028,160 | ---- | M] () -- C:\Users\Sara\Documents\rehab.doc
[2010/02/01 21:02:29 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/02/01 21:01:34 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/02/01 21:00:50 | 000,299,456 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/02/01 20:48:18 | 003,842,878 | R--- | M] () -- C:\Users\Sara\Desktop\schrauber.exe
[2010/02/01 19:59:05 | 000,007,002 | ---- | M] () -- C:\Users\Sara\Documents\BestBlogAward.jpg
[2010/02/01 19:48:20 | 000,071,680 | ---- | M] () -- C:\Users\Sara\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/01 18:40:03 | 000,131,737 | ---- | M] () -- C:\Users\Sara\Documents\Selfish.zip
[2010/02/01 18:34:32 | 000,176,937 | ---- | M] () -- C:\Users\Sara\Documents\AquilineTwo.zip
[2010/02/01 18:33:38 | 000,025,373 | ---- | M] () -- C:\Users\Sara\Documents\ChopinScript.zip
[2010/01/28 17:24:49 | 018,030,130 | ---- | M] () -- C:\Users\Sara\Documents\vlc-1.0.3-win32.exe
[2010/01/27 16:09:47 | 000,524,288 | -HS- | M] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TMContainer00000000000000000002.regtrans-ms
[2010/01/27 02:41:59 | 000,524,288 | -HS- | M] () -- C:\Users\Sara\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/01/27 02:41:59 | 000,065,536 | -HS- | M] () -- C:\Users\Sara\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/01/26 18:50:42 | 000,001,033 | ---- | M] () -- C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/01/24 15:09:47 | 000,193,955 | ---- | M] () -- C:\MGlogs.zip
[2010/01/24 14:59:11 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/01/24 14:59:11 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/01/24 14:57:53 | 001,092,543 | ---- | M] () -- C:\FixAVP.exe
[2010/01/24 14:57:12 | 002,387,269 | ---- | M] () -- C:\MGtools.exe
[2010/01/23 01:36:55 | 000,173,576 | ---- | M] (AMD Technologies Inc.) -- C:\Windows\System32\drivers\ahcix86s.sys
[2010/01/22 18:31:26 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/22 12:50:42 | 000,000,774 | ---- | M] () -- C:\Users\Public\Desktop\a-squared Free.lnk
[2010/01/21 23:01:51 | 000,000,312 | ---- | M] () -- C:\Users\Sara\Desktop\Curse Client.appref-ms
[2010/01/21 22:59:42 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2010/01/21 22:45:14 | 000,007,512 | ---- | M] () -- C:\Users\Sara\AppData\Local\d3d9caps.dat
[5 C:\Users\Sara\Documents\*.tmp files -> C:\Users\Sara\Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/02/02 16:13:20 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/02/02 01:10:42 | 000,000,008 | RHS- | C] () -- C:\Windows\System32\D97797DCFB.sys
[2010/02/01 23:00:35 | 000,300,032 | ---- | C] () -- C:\Users\Sara\Documents\10015-NR Information Assistant x3 - Final.doc
[2010/02/01 23:00:12 | 000,175,104 | ---- | C] () -- C:\Users\Sara\Documents\pink.doc
[2010/02/01 22:28:47 | 000,028,160 | ---- | C] () -- C:\Users\Sara\Documents\rehab.doc
[2010/02/01 19:59:04 | 000,007,002 | ---- | C] () -- C:\Users\Sara\Documents\BestBlogAward.jpg
[2010/02/01 18:40:02 | 000,131,737 | ---- | C] () -- C:\Users\Sara\Documents\Selfish.zip
[2010/02/01 18:36:12 | 000,037,552 | ---- | C] () -- C:\Users\Sara\Documents\CHOPS___.TTF
[2010/02/01 18:36:12 | 000,000,943 | ---- | C] () -- C:\Users\Sara\Documents\ffonts.net.htm
[2010/02/01 18:34:31 | 000,176,937 | ---- | C] () -- C:\Users\Sara\Documents\AquilineTwo.zip
[2010/02/01 18:33:37 | 000,025,373 | ---- | C] () -- C:\Users\Sara\Documents\ChopinScript.zip
[2010/01/31 22:43:43 | 000,261,632 | ---- | C] () -- C:\Windows\PEV.exe
[2010/01/31 22:43:43 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/01/31 22:43:43 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/01/31 22:43:43 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/01/31 22:43:43 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/01/31 20:34:27 | 003,842,878 | R--- | C] () -- C:\Users\Sara\Desktop\schrauber.exe
[2010/01/27 13:14:14 | 000,524,288 | -HS- | C] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TMContainer00000000000000000002.regtrans-ms
[2010/01/27 13:14:14 | 000,524,288 | -HS- | C] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TMContainer00000000000000000001.regtrans-ms
[2010/01/27 13:14:14 | 000,065,536 | -HS- | C] () -- C:\Users\Sara\ntuser.dat{32e0effe-0a83-11df-b61a-001d72d84a21}.TM.blf
[2010/01/26 18:50:42 | 000,001,033 | ---- | C] () -- C:\Users\Public\Desktop\RegistryBooster.lnk
[2010/01/24 14:59:11 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010/01/24 14:59:11 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010/01/24 14:59:08 | 000,193,955 | ---- | C] () -- C:\MGlogs.zip
[2010/01/24 14:58:07 | 001,092,543 | ---- | C] () -- C:\FixAVP.exe
[2010/01/24 14:57:33 | 002,387,269 | ---- | C] () -- C:\MGtools.exe
[2010/01/22 18:31:25 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/22 12:50:42 | 000,000,774 | ---- | C] () -- C:\Users\Public\Desktop\a-squared Free.lnk
[2009/10/20 19:37:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/06/01 22:19:55 | 000,000,467 | ---- | C] () -- C:\Users\Sara\AppData\Roaming\Poladroid prefs.plist
[2009/06/01 10:29:01 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/05/22 19:27:15 | 000,002,828 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/04/21 05:23:49 | 000,000,091 | ---- | C] () -- C:\ProgramData\PS.log
[2009/04/21 05:19:27 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll
[2009/03/21 17:30:18 | 000,007,512 | ---- | C] () -- C:\Users\Sara\AppData\Local\d3d9caps.dat
[2009/03/11 11:58:51 | 000,000,033 | ---- | C] () -- C:\Users\Sara\AppData\Roaming\pcouffin.log
[2009/03/11 11:57:59 | 000,007,887 | ---- | C] () -- C:\Users\Sara\AppData\Roaming\pcouffin.cat
[2009/03/11 11:57:59 | 000,001,144 | ---- | C] () -- C:\Users\Sara\AppData\Roaming\pcouffin.inf
[2009/03/07 10:58:00 | 000,795,648 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/03/07 10:58:00 | 000,130,048 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/03/07 10:57:59 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2009/03/07 10:57:57 | 000,067,584 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/03/07 10:57:57 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2009/03/07 10:56:41 | 000,168,448 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/01/31 21:21:41 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/01/30 00:17:25 | 000,242,176 | ---- | C] () -- C:\Users\Sara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/05 02:16:27 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/10/05 01:31:54 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2008/08/19 09:38:00 | 000,005,475 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe2.log
[2008/08/19 09:36:19 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll
[2008/08/19 09:32:33 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll
[2008/08/19 09:32:33 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll
[2008/08/19 02:48:56 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/08/19 02:48:50 | 000,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2008/08/19 02:48:50 | 000,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2008/08/19 02:48:18 | 000,000,042 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2006/11/02 12:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 07:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2001/12/26 23:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 06:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 23:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 05:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
========== LOP Check ========== [2008/08/19 09:29:23 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Acer GameZone Console
[2009/01/30 18:52:22 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Acreon
[2010/02/02 18:32:07 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Azureus
[2009/01/29 21:21:24 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\CopyTrans
[2009/01/29 21:18:22 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\CopyTransControlCenter
[2009/01/30 17:47:23 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\CopyTransDoctor
[2009/06/21 22:02:48 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2009/06/22 11:37:47 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\GetRightToGo
[2009/02/02 09:42:52 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\ICAClient
[2009/09/02 15:04:19 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\IObit
[2009/04/18 23:07:25 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\SystemRequirementsLab
[2010/01/26 18:50:47 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Uniblue
[2009/10/12 17:20:53 | 000,000,000 | ---D | M] -- C:\Users\Sara\AppData\Roaming\Vso
[2010/02/02 02:20:15 | 000,032,578 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2010/01/24 14:57:53 | 001,092,543 | ---- | M] () -- C:\FixAVP.exe
[2010/01/24 14:57:12 | 002,387,269 | ---- | M] () -- C:\MGtools.exe
< MD5 for: AGP440.SYS >[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\ERDNT\cache\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 02:23:01 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 09:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >[2009/04/11 06:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 06:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 06:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 06:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 02:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 02:23:00 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 09:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2006/11/02 09:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 09:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 09:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >[2008/01/21 02:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 02:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 02:23:23 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 09:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >[2009/04/11 06:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/11 06:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 06:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 02:24:05 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >[2006/11/02 09:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 02:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >[2008/01/21 02:24:50 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 06:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\ERDNT\cache\scecli.dll
[2009/04/11 06:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009/04/11 06:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< %systemroot%\*. /mp /s > ========== Alternate Data Streams ========== @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Extras.Txt:
OTL Extras logfile created on: 02/02/2010 21:51:56 - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\Sara\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 18.99 Gb Free Space | 13.17% Space Free | Partition Type: NTFS
Drive D: | 144.15 Gb Total Space | 46.14 Gb Free Space | 32.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SARA-PC
Current User Name: Sara
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11A70977-6997-475B-AF25-A18320946C43}" = rport=138 | protocol=17 | dir=out | app=system |
"{188C8CAF-613D-474C-898B-ADFB80EE9797}" = lport=445 | protocol=6 | dir=in | app=system |
"{1AD0526B-0B0F-40A1-BF0A-8422E5E7A4E4}" = rport=445 | protocol=6 | dir=out | app=system |
"{2C336332-5CDA-4B67-B001-325450D17E34}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{4B2EF756-7F48-4134-AEE7-BD499CF14F0B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6117C466-6E18-4CF8-BC9B-E5EF48ECBB88}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{69EE42BA-1807-4962-B8C3-349F9B05C71F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{749D1546-B9FD-4B26-9FFC-B81BC3D8687D}" = rport=137 | protocol=17 | dir=out | app=system |
"{78E0EBA2-9EBE-4FC1-9356-DBC79119C36A}" = lport=139 | protocol=6 | dir=in | app=system |
"{8E1DCA23-CFBF-4FE6-80FD-5DC3CD448C22}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{AAE6BED2-B6D9-4A09-852B-B1B96B63BB35}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B2287B9C-548B-47E1-8BB4-46C3ACDB5605}" = lport=138 | protocol=17 | dir=in | app=system |
"{E23C3FE2-A875-4A33-9855-E69DDBAB513B}" = rport=139 | protocol=6 | dir=out | app=system |
"{E3C5FAF9-6882-41CD-8EDD-7F69973CCE15}" = lport=137 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06C637F2-BA55-45FA-954D-3949047D8D4A}" = protocol=6 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_10385b9745e33e88\curseclient.exe |
"{0D3627F2-CFB9-4949-A05C-7A0C7EBE8325}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0FD3DF9A-33A4-42A6-8785-1713AF84680A}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{10DF10BA-082F-4FAE-9650-7CB6FA8D9E9F}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-engb-downloader.exe |
"{1BB8C8A9-110A-46EE-B7AB-4462B1D50938}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1FC72AD9-D127-47A1-ADFF-D7BD14948CB5}" = protocol=6 | dir=in | app=d:\program files\world of warcraft\backgrounddownloader.exe |
"{210CFA76-5DBA-434B-8002-78DE043C9979}" = protocol=6 | dir=in | app=d:\program files\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-engb-downloader.exe |
"{218EA5EB-1E47-4C7D-850F-30242C498C26}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2AE7FE0F-3C8B-4769-A428-519759C2ACCF}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{344E6AD3-1893-4B63-B6A5-40B288D5164E}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{36B3D21D-DC05-4C2A-849D-39291FA85490}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{3D84DE3B-5C43-4DD6-B244-D140D431FB16}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{44BD4117-0025-4859-BF7C-534ABFC8EFDD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{496CCA95-113B-4BC0-B144-FEBC4EE86509}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4B37B0CF-0CDF-4A46-949D-45179D2C4363}" = protocol=17 | dir=in | app=d:\program files\itunes\itunes.exe |
"{50B6FB9C-2619-48B6-848B-9178CB5594E2}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-engb-downloader.exe |
"{51669F9D-A5EB-4FC5-9815-BA41C05F6E56}" = protocol=17 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_1430d97334050788\curseclient.exe |
"{5E50BF5C-63CF-4D37-8CE8-32EAA3602BD8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{637896DE-0574-4A07-9C95-4CB6B5206951}" = protocol=17 | dir=in | app=d:\program files\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-engb-downloader.exe |
"{7A391A61-836C-4E35-9F82-3C541536E7DD}" = protocol=17 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_1332b9f434841748\curseclient.exe |
"{80D83D4A-8CE3-4E6F-962C-ECB54D400C14}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{82632DF7-C902-464B-BCDA-18ED213EB1CB}" = protocol=17 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_10385b9745e33e88\curseclient.exe |
"{870304C0-A8F9-40F8-8ABF-E77079F2C357}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8A8F3612-6C0A-4850-9E27-1149919C73EC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{8D957F87-A337-453E-B9BF-9256F43A0981}" = protocol=6 | dir=in | app=d:\program files\itunes\itunes.exe |
"{915B514B-3544-4A7C-BB05-DB3BF15A74B2}" = protocol=6 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_1430d97334050788\curseclient.exe |
"{937AA921-C43F-49F3-862E-878E7C6F37E0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{9F72D275-5422-4F8B-8B47-FF254A4ABD87}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{A1C1DBB6-478E-42B8-9BDA-1EEBC3705FB7}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{A760A4A2-6E8A-44D6-9EF6-7B1074AA648A}" = protocol=17 | dir=in | app=d:\program files\world of warcraft\backgrounddownloader.exe |
"{B10034A0-BACA-40A6-A816-DCE6B240966D}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{B60BE233-3400-4776-931A-B0283958A76B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BC360DDB-245C-4253-A197-2338BAF49FD2}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
"{BDEB9B19-2A3D-4F19-8D8B-C77C0F842D9A}" = protocol=17 | dir=in | app=d:\program files\itunes\itunes.exe |
"{D0CBCE8F-0B5B-4793-ACAD-385DD79EC6B3}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{D40D4D91-3264-43B5-856A-CDF59D64F12A}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{D498D30F-3312-4B9E-8117-5F1FB5AB6FFD}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{D7192D44-F6BA-4FEE-88BE-47E7C26975B5}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{D8FBDFAA-9B2B-4403-8AA6-4E624895321A}" = protocol=6 | dir=in | app=c:\users\sara\appdata\local\apps\2.0\dj441dy0.t0j\z3b0rbkq.lvz\curs..tion_eee711038731a406_0004.0000_1332b9f434841748\curseclient.exe |
"{F6162034-E2A1-41BC-906D-DD78A8C201DA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{F78FBBF9-9092-4BF3-9AC4-503820B06FF3}" = protocol=6 | dir=in | app=d:\program files\itunes\itunes.exe |
"TCP Query User{0BC64FF7-379C-4C9B-8197-325C45C0D67F}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{1F374235-FE24-4E94-B9AF-D6BBA75F7FDC}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{21AE50EA-54D9-4BA1-AFF1-F81CB964D31B}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{517353E8-B2D9-4E61-939E-309E81BCB88B}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{94DCBBFB-E3EF-436C-AE68-13AD4DE4CCC0}D:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\program files\world of warcraft\launcher.exe |
"TCP Query User{9AE8B5A9-BD7B-47C9-BFCC-9F3738FCF0CA}D:\program files\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\program files\world of warcraft\launcher.exe |
"UDP Query User{0CA63B09-DEE4-46E7-B568-2971783D38CF}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{3E463EBB-7704-40F0-BD0F-87D797406773}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{468ADABD-F4EA-432C-8320-C6AA4C40416C}D:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\program files\world of warcraft\launcher.exe |
"UDP Query User{7183CE53-2EF0-41D6-8828-A6BE856AB535}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{AF8A1BC3-C6A4-4CD5-8EE9-A622CD025D11}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{BBFB4C66-D92E-4588-84E5-D2AFF8246536}D:\program files\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\program files\world of warcraft\launcher.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial
"{06396923-449E-4881-DB30-9677EBFBE5ED}" = Catalyst Control Center Localization Dutch
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0AD7E761-CDD9-79AD-6C0F-2CE53F7277DB}" = Catalyst Control Center Localization Japanese
"{0CAA0BF0-293D-32E7-BF40-99C26947B3B6}" = CCC Help Greek
"{0D0256AB-54EF-414E-A6D9-896610EBAB70}" = Catalyst Control Center Localization Thai
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{16A31107-6828-ED37-8551-37888EA51D85}" = Catalyst Control Center Localization Chinese Standard
"{18855F72-E9B6-74C7-67DC-86CA6D775554}" = CCC Help Swedish
"{1D801B9D-9473-2001-2FB4-875F75C5CFFA}" = Catalyst Control Center Localization French
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{265B1C1D-9BD0-A416-D5FE-0710AC0A9592}" = CCC Help Italian
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 15
"{27C9470C-2077-F4AD-8921-9504D1B9BC83}" = Catalyst Control Center Graphics Light
"{33D8205B-9118-D20E-F94A-4B467BB46289}" = Catalyst Control Center Localization Chinese Traditional
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4684B4D7-A90A-028E-F300-7C96761B1287}" = CCC Help Chinese Traditional
"{468789CE-4A7C-F9C8-9DB9-6F32827F1721}" = CCC Help Danish
"{5122D45F-16C5-6E6C-4509-4EE321E8A45F}" = Catalyst Control Center Localization Finnish
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5735B860-F404-20E5-2C4A-2108AFDF7DAB}" = CCC Help Polish
"{573CE82D-3BA8-1D84-9F59-87DD11EAFB79}" = CCC Help Norwegian
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{591137F5-39FD-BFEF-FA09-181F0FA9B9EF}" = CCC Help Hungarian
"{5AB587B5-8FAE-55F2-DB26-5A83234E3FDC}" = CCC Help Japanese
"{5B63A470-9334-44D1-AF61-6CE2DB565AE9}" = Orion
"{60C85C96-8D91-58AF-E5D0-4C53A0ACEE78}" = Catalyst Control Center Localization Polish
"{613D098B-93C6-A2DE-5319-FF7D2229DB2B}" = CCC Help German
"{67DEBF39-8470-344D-6332-969307D41805}" = CCC Help Chinese Standard
"{687BD5FD-DC50-A653-9022-A7113D50B331}" = CCC Help Korean
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73B5C7D2-30E4-5522-52BC-89677DFD8E32}" = Catalyst Control Center InstallProxy
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{781B8114-9EFF-BFF5-B7F7-7DCFE5571218}" = Catalyst Control Center Localization German
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{79866648-18CB-4C93-F124-31AFE54F9A9D}" = Catalyst Control Center Core Implementation
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7CAE5047-9916-477F-283A-8E994DFAAD21}" = Catalyst Control Center Localization Spanish
"{7EAB15F0-5857-A3B6-565F-F5A27EC4FD91}" = ATI Catalyst Install Manager
"{802F0F4E-A0A5-4E4D-9D7B-1933913EF7B6}" = Catalyst Control Center - Branding
"{849C1158-7421-893E-8E33-4312F49C1ADF}" = Catalyst Control Center Localization Greek
"{8EA318FC-D486-57D6-2A25-6BD247FA99DB}" = Catalyst Control Center Localization Norwegian
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90C26DA5-6780-0E5F-BC97-CAA7B5727E86}" = Catalyst Control Center Graphics Full Existing
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{925150D7-0CC2-D6DF-6066-3784CE22CEE7}" = Catalyst Control Center Localization Korean
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{966DE944-348D-01B7-F9B7-0F0D696F4076}" = Catalyst Control Center Localization Swedish
"{99F8744D-211D-42D9-CA25-1029F8E0912B}" = Catalyst Control Center Localization Portuguese
"{9C3FA7FD-9B70-C526-FA63-162783E1060D}" = CCC Help Portuguese
"{9D6271F2-6F0A-A259-085B-5BBD4F05A33E}" = Catalyst Control Center Localization Hungarian
"{A2694396-5508-3DB0-5308-7E6768DD7896}" = Catalyst Control Center Localization Turkish
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A5FDB0FC-8DD0-E5D4-E031-922AE876403A}" = CCC Help Turkish
"{A79E4110-0087-E8AE-BD4F-A1883B2FD357}" = CCC Help French
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B316A8CE-F7F6-C99A-C41D-369A7CD33FC6}" = Catalyst Control Center Localization Danish
"{B44695F8-959E-95EC-F3AC-F734C9DC6DAE}" = Catalyst Control Center Localization Italian
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B73BEEBE-3D94-2634-B5D1-28B8269489FF}" = twhirl
"{C08A4D67-6837-5097-CC0C-B5DFD60630B9}" = ccc-core-static
"{C0A1C9D6-9AC7-5B5A-6C25-B8FBC478BA8A}" = CCC Help Russian
"{C34686CD-A03B-1B48-8085-341CD632C0BC}" = Catalyst Control Center Graphics Full New
"{C83127E6-697A-7EEC-D53D-C089610D7F4A}" = CCC Help Dutch
"{C91E74DA-8852-D2BB-B3A2-60A9202E1732}" = CCC Help Thai
"{CAC9E80B-7515-0DB9-40BB-09B3703D90BB}" = Catalyst Control Center Localization Russian
"{CD4D90B4-CC18-C176-B261-8BA8D5F644AB}" = CCC Help Czech
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DCD2B7EA-5452-DD3E-D008-2320C06862DB}" = CCC Help Finnish
"{DD1DED37-2486-4F56-8F89-56AA814003F5}" = Acer Crystal Eye Webcam
"{E1C7EF5E-3A7B-4ED4-A48B-F70F1B36EAB4}" = Corel Paint Shop Pro Photo XI
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster 2010
"{E7E36B90-24D7-E382-CEFB-6F293A2302F6}" = CCC Help English
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3E29994-EE0A-C417-7FDE-902B1D722460}" = Catalyst Control Center Localization Czech
"{F420F5B3-677A-779E-AEEC-81A00ED373FE}" = ccc-utility
"{F42D4CA6-E811-C8DA-D607-4F8A510D7953}" = CCC Help Spanish
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"8461-7759-5462-8226" = Vuze
"AC3Filter" = AC3Filter (remove only)
"Acer GameZone Console_is1" = Acer GameZone Console 2.0.1.1
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Vuze Toolbar
"a-squared Free_is1" = a-squared Free 4.5
"CDisplay_is1" = CDisplay 1.8
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"CopyTrans Suite" = CopyTrans Suite Remove Only
"de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1" = twhirl
"Game Booster_is1" = Game Booster
"Google Desktop" = Google Desktop
"GridVista" = Acer GridVista
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Full)
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"NAV" = Norton AntiVirus
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VLC media player 1.0.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client
"Wow Web Stats Client v3.0" = Wow Web Stats Client v3.0
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 28/01/2010 07:22:31 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start
Error - 28/01/2010 07:22:31 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16388
Description = ATI EEU Client event error
Error - 28/01/2010 07:22:31 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:32 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:32 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:33 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:35 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:35 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:36 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
Error - 28/01/2010 07:22:38 | Computer Name = Sara-PC | Source = ATIeRecord | ID = 16387
Description = ATI EEU Service event error
[ System Events ]
Error - 01/02/2010 21:15:25 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 01/02/2010 21:15:25 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 02/02/2010 09:45:24 | Computer Name = Sara-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 02/02/2010 09:45:38 | Computer Name = Sara-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 02/02/2010 09:46:34 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 02/02/2010 09:46:34 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 02/02/2010 12:05:59 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7031
Description =
Error - 02/02/2010 15:40:58 | Computer Name = Sara-PC | Source = DCOM | ID = 10005
Description =
Error - 02/02/2010 15:40:58 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 02/02/2010 15:40:58 | Computer Name = Sara-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >