I became aware of this problem yesterday when i couldn't access Steam. It got to 99% updating and then stopped and I got a Resident Shield alert that found "Trojan horse PSW.Generic.10.AIXT" filename "C:\Program Files\Steam\bin\FileSystem_Steam.dll". My system's also slower than usual.
I've detected and deleted this and a similar Trojan several times with AVG and Malwarebytes but the problem is still there.
I noticed once while I was running a Malwarebytes scan that my Resident Shield picked them up while the files were being scanned, but MB didn't:
"C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP677\A0501932.dll";"Trojan horse PSW.Generic10.AIXT";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP677\A0501965.exe";"Trojan horse Proxy.AVIS";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP677\A0502968.exe";"Trojan horse Proxy.AVIS";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP677\A0503010.dll";"Trojan horse PSW.Generic10.AIXT";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP677\A0503011.exe";"Trojan horse Proxy.AVIS";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP678\A0503395.dll";"Trojan horse PSW.Generic10.AIXT";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP680\A0503589.exe";"Trojan horse Proxy.AVIS";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP682\A0504105.exe";"Trojan horse Proxy.AVIS";"Moved to Virus Vault" "C:\System Volume Information\_restore{8D290BB5-E59C-462B-A0EE-E8949A1E4344}\RP682\A0504123.dll";"Trojan horse PSW.Generic10.AIXT";"Moved to Virus Vault"
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-07.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11/26/2008 7:11:03 AM System Uptime: 11/10/2012 12:48:23 PM (5 hours ago) . Motherboard: OEM_MB | | 2A72h Processor: AMD Athlon(tm) Dual Core Processor 4450B | Socket AM2 | 1801/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 139 GiB total, 46.807 GiB free. D: is FIXED (NTFS) - 10 GiB total, 2.534 GiB free. E: is CDROM () F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP667: 10/10/2012 11:03:12 PM - Software Distribution Service 3.0 RP668: 10/17/2012 4:28:23 AM - System Checkpoint RP669: 10/23/2012 6:24:13 AM - System Checkpoint RP670: 10/25/2012 5:06:01 PM - System Checkpoint RP671: 10/27/2012 3:24:42 AM - System Checkpoint RP672: 10/30/2012 3:29:33 AM - System Checkpoint RP673: 11/3/2012 6:12:24 AM - System Checkpoint RP674: 11/3/2012 6:09:09 PM - Installed Java 7 Update 7 RP675: 11/3/2012 8:49:45 PM - Installed DirectX RP676: 11/6/2012 11:09:59 AM - System Checkpoint RP677: 11/7/2012 7:06:39 PM - Installed iTunes RP678: 11/9/2012 11:07:27 PM - Removed TubeHunter Ultra RP679: 11/9/2012 11:19:21 PM - Removed Hi-Command RP680: 11/9/2012 11:20:01 PM - Removed Steam RP681: 11/9/2012 11:27:30 PM - Installed Steam RP682: 11/9/2012 11:34:08 PM - Removed Steam RP683: 11/10/2012 11:44:21 AM - Installed Steam . ==== Installed Programs ====================== . Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 8 Adobe Shockwave Player 11.5 Afterfall InSanity DEMO Amazon Kindle AMD Processor Driver AOL Toolbar 5.0 Apple Application Support Apple Mobile Device Support Apple Software Update µTorrent AVG Free 8.5 AVG Security Toolbar BattlEye (A2Free) Uninstall Bonjour Braid (Version 1.015) BT Broadband Desktop Help BT Broadband Talk Softphone 2.0 BT Home Hub BT Wireless Connection Manager BT Yahoo! Applications BTHomeHub Canon MP Navigator EX 1.0 Canon MP520 series Canon MP520 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu CCleaner CoreAAC CoView CutePDF Writer 2.8 CyberLink PowerDVD 8 Deus Ex - Game of the Year Edition Direct Show Ogg Vorbis Filter (remove only) DivX Converter DivX Plus DirectShow Filters DivX Setup DivX Version Checker Download Manager 2.3.10 Droid Assault (remove only) dtvblizzcon Player Dual-Core Optimizer Fps Terminator Fraps Futuremark SystemInfo GOG.com Downloader version 3.0.40 GOM PICKER GOM Player GOM Video Converter GOMTV Plug-in GOMTV Streamer Google Chrome Google Update Helper GoToAssist Corporate Half-Life Uplink Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB952117-v2) Hotfix for Windows XP (KB954550-v5) HP Backup and Recovery Manager HP Help and Support iTunes Java 7 Update 7 Java Auto Updater Java(TM) 6 Update 16 Java(TM) 6 Update 2 Junk Mail filter update LDC Driving Test Complete League of Legends LucasArts' Grim Fandango Machinarium Malwarebytes Anti-Malware version 1.65.1.1000 Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Chart Controls for Microsoft .NET Framework 3.5 Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft IntelliPoint 6.3 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Windows Media Video 9 VCM Microsoft XNA Framework Redistributable 3.0 Microsoft XNA Framework Redistributable 3.1 Microsoft XNA Framework Redistributable 4.0 mIRC MouseMaestro Input Device Driver V2.0.1-145AA MUL Mozilla Firefox 16.0.2 (x86 en-US) Mozilla Maintenance Service MPEG2 Codec(libmpeg2/mad) MSVCRT MSXML 6.0 Parser (KB925673) Mumble 1.2.3 NVIDIA Control Panel 296.10 NVIDIA Display Control Panel NVIDIA Drivers NVIDIA Graphics Driver 296.10 NVIDIA HD Audio Driver 1.3.12.0 NVIDIA Install Application NVIDIA nView 136.18 NVIDIA nView Desktop Manager NVIDIA PhysX NVIDIA PhysX System Software 9.12.0213 NVIDIA Update 1.7.11 NVIDIA Update Components Octoshape add-in for Adobe Flash Player Octoshape Streaming Services OpenAL PDF Complete Peggle Deluxe 1.01 Penumbra Pocket RAR documentation PunkBuster Services Quake Live Mozilla Plugin QuickTime RayViewer 1.08 Real Alternative 1.9.0 RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 S.T.A.L.K.E.R. - Shadow of Chernobyl Save Flash 4.2 ScanSoft OmniPage SE 4 Security Update for CAPICOM (KB931906) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687314) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2687315) 32-Bit Edition Segoe UI Skype Click to Call Skype™ 5.5 Spotify Spybot - Search & Destroy Steam System Requirements Lab System Requirements Lab CYRI TeamSpeak 2 RC2 TrueCrypt UE3Redist Unity Web Player Update for 2007 Microsoft Office System (KB967642) USB 2.0 Card Reader VC80CRTRedist - 8.0.50727.6195 Ventrilo Client Ventrilo Server Veoh Web Player VLC media player 0.9.9 WebFldrs XP Windows Genuine Advantage Validation Tool (KB892130) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 WinRAR archiver XML Paper Specification Shared Components Pack 1.0 Yahoo! Toolbar YouTube Downloader 2.5.5 . ==== Event Viewer Messages From Past Week ======== . 11/9/2012 9:29:18 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 11/9/2012 9:28:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 11/9/2012 9:28:21 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT oreans32 RasAcd Rdbss sptd Tcpip truecrypt 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:28:21 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 11/9/2012 9:27:42 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 11/9/2012 9:27:31 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 11/9/2012 9:27:26 PM, error: sptd - Driver detected an internal error in its data structures for . 11/9/2012 7:27:51 PM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period. 11/9/2012 2:44:00 PM, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 11/9/2012 2:39:50 PM, error: sr - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'FileSystem_Steam.dll' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 11/9/2012 10:55:58 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 bd03d83b, parameter3 b13e25e4, parameter4 00000000. 11/9/2012 10:13:37 AM, error: Service Control Manager [7034] - The vToolbarUpdater13.2.0 service terminated unexpectedly. It has done this 1 time(s). 11/9/2012 10:13:34 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 11/8/2012 9:37:20 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 11/4/2012 10:07:56 AM, error: Service Control Manager [7034] - The vToolbarUpdater12.2.6 service terminated unexpectedly. It has done this 1 time(s). 11/4/2012 10:07:54 AM, error: Service Control Manager [7034] - The NVIDIA Driver Helper Service service terminated unexpectedly. It has done this 1 time(s). 11/4/2012 10:07:53 AM, error: Service Control Manager [7034] - The PnkBstrA service terminated unexpectedly. It has done this 1 time(s). 11/4/2012 10:07:53 AM, error: Service Control Manager [7034] - The Hi-Rez Studios Authenticate and Update Service service terminated unexpectedly. It has done this 1 time(s). 11/4/2012 10:07:50 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/4/2012 10:05:05 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool. 11/3/2012 8:39:07 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/3/2012 4:12:10 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/3/2012 4:12:04 PM, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s). . ==== End Of File ===========================
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:27:42, on 10/11/2012 Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3264) Boot mode: Normal
"C:\Program Files\Steam\bin\FileSystem_Steam.dll". <<<--- Sounds like a false positive
My system's also slower than usual.
Ok, We need to get a comprehensive report of what is present in your system.
Download OTL by OldTimer, saving it to your desktop: http://oldtimer.geekstogo.com/OTL.exe • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. • Select All Users • Under the Custom Scan box paste this in: netsvcs activex msconfig %SYSTEMDRIVE%\*. %PROGRAMFILES%\*.exe %LOCALAPPDATA%\*.exe %windir%\Installer\*.* %windir%\system32\tasks\*.* %systemroot%\Fonts\*.exe %systemroot%\*. /mp /s /md5start consrv.dll explorer.exe winlogon.exe regedit.exe Userinit.exe svchost.exe MRESP50.SYS CBPSp50.sys /md5stop C:\Windows\assembly\tmp\U\*.* /s %Temp%\smtmp\1\*.* %Temp%\smtmp\2\*.* %Temp%\smtmp\3\*.* %Temp%\smtmp\4\*.* >C:\commands.txt echo list vol /raw /hide /c /wait >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c /wait type c:\diskreport.txt /c /wait erase c:\commands.txt /hide /c /wait erase c:\diskreport.txt /hide /c CREATERESTOREPOINT
• Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Thanks for replying, here are the two logs from OTL.
OTL logfile created on: 12/11/2012 09:10:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Professional Edition Service Pack 3, v.3264 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.3264) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.08% Memory free 4.84 Gb Paging File | 4.26 Gb Available in Paging File | 88.01% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 139.04 Gb Total Space | 50.14 Gb Free Space | 36.06% Space Free | Partition Type: NTFS Drive D: | 10.00 Gb Total Space | 2.53 Gb Free Space | 25.33% Space Free | Partition Type: NTFS Drive G: | 3.73 Gb Total Space | 3.72 Gb Free Space | 99.79% Space Free | Partition Type: FAT32
Computer Name: HP13888241712 | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error. ActiveX: {0430454D-47EA-11D6-AD58-00010333D0AD} - Reg Error: Value error. ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - Reg Error: Value error. ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} - Reg Error: Value error. ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error. ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error. ActiveX: {34C70B70-8FFF-4179-A2EB-0819FFA38126} - Reg Error: Value error. ActiveX: {362A5D5E-1BF6-4CA7-87B4-B6686F3C1BEF} - Reg Error: Value error. ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4a01a151-e350-4839-a2b8-03dc39d6c8e5} - Reg Error: Value error. ActiveX: {4b218e3e-bc98-4770-93d3-2731b9329278} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf ActiveX: {4DAEE2D4-A471-42AC-97A2-4C2A79C77648} - Reg Error: Value error. ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install ActiveX: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - Reg Error: Value error. ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {944D7BBB-EA1D-43EB-B49F-F517CF2B6C9D} - Reg Error: Value error. ActiveX: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - Reg Error: Value error. ActiveX: {AA218328-0EA8-4D70-8972-E987A9190FF4} - Reg Error: Value error. ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {CE734E0A-D6D3-4A92-AF9F-499BE87A025C} - Reg Error: Value error. ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error. ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F53CE5EC-1CD8-41EB-A220-F8EA247E3A06} - Reg Error: Value error. ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
< type c:\diskreport.txt /c > Microsoft DiskPart version 5.1.3565 Copyright (C) 1999-2003 Microsoft Corporation. On computer: HP13888241712 Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- Volume 0 E DVD-ROM 0 B Volume 1 F DVD-ROM 0 B Volume 2 C NTFS Partition 139 GB Healthy System Volume 3 D HP_RECOVERY NTFS Partition 10 GB Healthy Volume 4 G 01256816966 FAT32 Removeable 3820 MB
========== Alternate Data Streams ==========
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
< End of report >
OTL Extras logfile created on: 12/11/2012 09:10:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Professional Edition Service Pack 3, v.3264 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.3264) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.08% Memory free 4.84 Gb Paging File | 4.26 Gb Available in Paging File | 88.01% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 139.04 Gb Total Space | 50.14 Gb Free Space | 36.06% Space Free | Partition Type: NTFS Drive D: | 10.00 Gb Total Space | 2.53 Gb Free Space | 25.33% Space Free | Partition Type: NTFS Drive G: | 3.73 Gb Total Space | 3.72 Gb Free Space | 99.79% Space Free | Partition Type: FAT32
Computer Name: HP13888241712 | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\WINDOWS\SMINST\Scheduler.exe" = C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler -- () "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\Yahoo!\Messenger\ypager.exe" = C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger -- () "C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.) "C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) "C:\Program Files\World of Warcraft\Repair.exe" = C:\Program Files\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility "C:\Program Files\THQ\Dawn Of War\W40k.exe" = C:\Program Files\THQ\Dawn Of War\W40k.exe:*:Enabled:W40k "C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade "C:\Documents and Settings\Administrator\Local Settings\temp\Blizzard Launcher Temporary - c3abbc60\Launcher.exe" = C:\Documents and Settings\Administrator\Local Settings\temp\Blizzard Launcher Temporary - c3abbc60\Launcher.exe:*:Enabled:Blizzard Launcher "C:\Program Files\Steam\steamapps\common\warhammer 40,000 dawn of war ii - beta\DOW2.exe" = C:\Program Files\Steam\steamapps\common\warhammer 40,000 dawn of war ii - beta\DOW2.exe:*:Enabled:DOW2 "C:\Program Files\VentSrv\ventrilo_srv.exe" = C:\Program Files\VentSrv\ventrilo_srv.exe:*:Enabled:ventrilo_srv -- () "C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- () "C:\Documents and Settings\Administrator\Local Settings\temp\Blizzard Launcher Temporary - 0ec68050\Launcher.exe" = C:\Documents and Settings\Administrator\Local Settings\temp\Blizzard Launcher Temporary - 0ec68050\Launcher.exe:*:Enabled:Blizzard Launcher "C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- () "C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- () "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation) "C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Disabled:Octoshape add-in for Adobe Flash Player -- (Octoshape ApS) "C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III "C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher "C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC) "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation) "C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- () "C:\Documents and Settings\Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" = C:\Documents and Settings\Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client -- (Octoshape ApS) "C:\Program Files\World of Warcraft\WoW-3.1.1.9835-to-3.1.2.9901-enGB-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.1.9835-to-3.1.2.9901-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Documents and Settings\Administrator\Desktop\WowExpansionMaster_1024_2100_B_English-avi-downloader.exe" = C:\Documents and Settings\Administrator\Desktop\WowExpansionMaster_1024_2100_B_English-avi-downloader.exe:*:Enabled:Blizzard Downloader "C:\Documents and Settings\Administrator\Desktop\WoW-Intro-enGB-downloader.exe" = C:\Documents and Settings\Administrator\Desktop\WoW-Intro-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player "C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby "C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client "C:\Program Files\Java\jre1.6.0_02\bin\javaw.exe" = C:\Program Files\Java\jre1.6.0_02\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary "C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation) "C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation) "C:\Program Files\NAMCO BANDAI Games\Warhammer Mark of Chaos\Warhammer.exe" = C:\Program Files\NAMCO BANDAI Games\Warhammer Mark of Chaos\Warhammer.exe:*:Enabled:Warhammer®: Mark of Chaos™ "C:\Documents and Settings\Administrator\My Documents\Downloads\SC2-battlereport-4_PEGI-downloader.exe" = C:\Documents and Settings\Administrator\My Documents\Downloads\SC2-battlereport-4_PEGI-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Documents and Settings\Administrator\My Documents\Downloads\Terran_Demo_English_EU.avi-downloader.exe" = C:\Documents and Settings\Administrator\My Documents\Downloads\Terran_Demo_English_EU.avi-downloader.exe:*:Enabled:Blizzard Downloader "C:\Program Files\TmNationsForever\TmForever.exe" = C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever "C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe "C:\Program Files\StarCraft II Beta\StarCraft II.exe" = C:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary "C:\Program Files\Bumblebee Studios\Bloodline Champions Beta\Binary\BloodlineChampionsLoader.exe" = C:\Program Files\Bumblebee Studios\Bloodline Champions Beta\Binary\BloodlineChampionsLoader.exe:*:Enabled:BloodlineChampionsLoader "C:\UDK\The Ball UDK Demo\Binaries\Win32\UDK.exe" = C:\UDK\The Ball UDK Demo\Binaries\Win32\UDK.exe:*:Enabled:UDK "C:\Program Files\Steam\steamapps\etherloper\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\etherloper\team fortress 2\hl2.exe:*:Enabled:hl2 "C:\WINDOWS\system32\spoolsv.exe" = C:\WINDOWS\system32\spoolsv.exe:*:Enabled:spoolsv.exe -- (Microsoft Corporation) "C:\Program Files\id Software\Quake 4 Multiplayer Demo\Quake4.exe" = C:\Program Files\id Software\Quake 4 Multiplayer Demo\Quake4.exe:*:Enabled:Quake 4 "C:\Documents and Settings\Administrator\Application Data\GameRanger\GameRanger\GameRanger.exe" = C:\Documents and Settings\Administrator\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger "C:\Program Files\AoE2\empires2.exe" = C:\Program Files\AoE2\empires2.exe:*:Enabled:Age of Empires II "C:\Program Files\AoE2\age2_x1\age2_x1.exe" = C:\Program Files\AoE2\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion "C:\Program Files\RayV\RayV\RayV.exe" = C:\Program Files\RayV\RayV\RayV.exe:*:Enabled:RayV -- (RayV) "C:\Program Files\RayV\RayV\RayV.dll" = C:\Program Files\RayV\RayV\RayV.dll:*:Enabled:RayV -- (RayV) "C:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe" = C:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm "C:\Program Files\GRETECH\GomTVStreamer\GomTVStreamerLive.exe" = C:\Program Files\GRETECH\GomTVStreamer\GomTVStreamerLive.exe:*:Enabled:GomTVStreamerLive.exe -- () "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation) "C:\Program Files\Java\jre6\bin\javaws.exe" = C:\Program Files\Java\jre6\bin\javaws.exe:*:Disabled:Java(TM) Web Start Launcher "C:\Documents and Settings\Administrator\Application Data\RayV\Viewer\RayV.dll" = C:\Documents and Settings\Administrator\Application Data\RayV\Viewer\RayV.dll:*:Enabled:RayV "C:\Games\World_of_Tanks_closed_Beta\WorldOfTanks.exe" = C:\Games\World_of_Tanks_closed_Beta\WorldOfTanks.exe:*:Enabled:World of Tanks "C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager "C:\Program Files\THQ\Dawn Of War\W40kWA.exe" = C:\Program Files\THQ\Dawn Of War\W40kWA.exe:*:Enabled:W40kWA "C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe" = C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe:*:Enabled:UDK -- (Epic Games, Inc.) "C:\Documents and Settings\Administrator\Desktop\Gang Garrison 2\Gang Garrison 2.exe" = C:\Documents and Settings\Administrator\Desktop\Gang Garrison 2\Gang Garrison 2.exe:*:Enabled:Gang Garrison 2 "C:\Program Files\Steam\steamapps\common\hacker evolution untold - demo\Hacker Evolution Untold.exe" = C:\Program Files\Steam\steamapps\common\hacker evolution untold - demo\Hacker Evolution Untold.exe:*:Enabled:Hacker Evolution: Untold - Demo "C:\Program Files\Steam\steamapps\common\wasteland angel - demo\bin\x86\dx9\Angel.exe" = C:\Program Files\Steam\steamapps\common\wasteland angel - demo\bin\x86\dx9\Angel.exe:*:Enabled:Wasteland Angel - Demo "C:\Games\World_of_Tanks\WorldOfTanks.exe" = C:\Games\World_of_Tanks\WorldOfTanks.exe:*:Enabled:World of Tanks "C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.) "C:\Program Files\Steam\steamapps\common\the ball demo\Binaries\Win32\TheBall.exe" = C:\Program Files\Steam\steamapps\common\the ball demo\Binaries\Win32\TheBall.exe:*:Enabled:The Ball Demo "C:\Program Files\Steam\steamapps\common\dungeon defenders demo\Binaries\Win32\DunDefGame.exe" = C:\Program Files\Steam\steamapps\common\dungeon defenders demo\Binaries\Win32\DunDefGame.exe:*:Enabled:DunDefGame "C:\Program Files\Steam\steamapps\common\dungeons the dark lord demo\dungeons-server.exe" = C:\Program Files\Steam\steamapps\common\dungeons the dark lord demo\dungeons-server.exe:*:Enabled:Dungeons - The Dark Lord Demo Server "C:\Program Files\Steam\steamapps\common\defcon\defcon.exe" = C:\Program Files\Steam\steamapps\common\defcon\defcon.exe:*:Enabled:Defcon "C:\Program Files\Steam\steamapps\common\oddworld abes oddysee demo\AbeDemo.exe" = C:\Program Files\Steam\steamapps\common\oddworld abes oddysee demo\AbeDemo.exe:*:Enabled:Oddworld: Abe's Oddysee Demo "C:\Program Files\Hi-Rez Studios\games\tribes alpha\Binaries\Win32\TribesAscend.exe" = C:\Program Files\Hi-Rez Studios\games\tribes alpha\Binaries\Win32\TribesAscend.exe:*:Enabled:TribesAscend "C:\Program Files\Steam\steamapps\common\hoard\win32\Reuben.exe" = C:\Program Files\Steam\steamapps\common\hoard\win32\Reuben.exe:*:Enabled:HOARD - Demo "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) "C:\Documents and Settings\Administrator\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Administrator\Application Data\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd) "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation) "C:\Program Files\Steam\steamapps\common\the void\bin\win32\Game.exe" = C:\Program Files\Steam\steamapps\common\the void\bin\win32\Game.exe:*:Enabled:The Void "C:\Program Files\Steam\steamapps\common\the void\bin\win32\Config.exe" = C:\Program Files\Steam\steamapps\common\the void\bin\win32\Config.exe:*:Enabled:The Void "C:\Program Files\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe" = C:\Program Files\Steam\steamapps\common\FTL Faster Than Light\FTLGame.exe:*:Enabled:FTL: Faster Than Light "C:\Program Files\Steam\steamapps\common\bastion\Bastion.exe" = C:\Program Files\Steam\steamapps\common\bastion\Bastion.exe:*:Enabled:Bastion "C:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\Bioshock.exe" = C:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\Bioshock.exe:*:Enabled:BioShock "C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.) "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) "C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended "{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP520_series" = Canon MP520 series "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1 "{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.5 "{1D46A3A0-B37D-423A-91C2-101A49E2FF80}" = Ventrilo Server "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7 "{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0 "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0 "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}" = HP Backup and Recovery Manager "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5 "{456A5815-604D-4D72-94DF-346D2B978A59}_is1" = GOG.com Downloader version 3.0.40 "{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE "{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail "{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour "{79A2AB22-00D8-4F09-A00A-F1CB7DB3E916}_is1" = Penumbra "{7B63B2922B174135AFC0E1377DD81EC2}" = "{868EC22E-7E82-4760-9265-3F2E705BF24B}" = League of Legends "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195 "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5 "{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8 "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 296.10 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 136.18 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.12.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B42A6552-1A83-4D79-9137-AB0C9036249A}" = Quake Live Mozilla Plugin "{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3 "{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver "{C59E50F4-0AE2-4742-8059-9EF67E379AFB}" = RayViewer 1.08 "{C7DDA8E7-AD3D-4F51-AC1E-B0FF57002192}" = Microsoft IntelliPoint 6.3 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D10CB652-9332-4242-B7A9-2D61570144F7}" = USB 2.0 Card Reader "{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support "{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX "{DAB5C521-80B2-48C3-B0DA-326A1B331F55}" = GoToAssist Corporate "{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4 "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F8EE079D-A1A6-48A0-8B02-5CC7E1FEE342}" = Afterfall InSanity DEMO "{FF3D660E-E5CC-47FD-8050-1B4DE3BA81A9}" = Dual-Core Optimizer "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Amazon Kindle" = Amazon Kindle "AOL Toolbar" = AOL Toolbar 5.0 "AVG Secure Search" = AVG Security Toolbar "AVG8Uninstall" = AVG Free 8.5 "BattlEye A2 Free" = BattlEye (A2Free) Uninstall "Braid_is1" = Braid (Version 1.015) "BT Broadband Desktop Help" = BT Broadband Desktop Help "BT Broadband Talk Softphone Frontier_is1" = BT Broadband Talk Softphone 2.0 "BT Home Hub" = BT Home Hub "BT Wireless Connection Manager" = BT Wireless Connection Manager "BT Yahoo! Applications" = BT Yahoo! Applications "BtcMouseMaestro" = MouseMaestro Input Device Driver V2.0.1-145AA MUL "BTHomeHub" = BTHomeHub "Canon MP520 series User Registration" = Canon MP520 series User Registration "CanonMyPrinter" = Canon My Printer "CanonSolutionMenu" = Canon Utilities Solution Menu "CCleaner" = CCleaner "CoreAAC" = CoreAAC "CoView_is1" = CoView "CutePDF Writer Installation" = CutePDF Writer 2.8 "Deus Ex - Game of the Year Edition_is1" = Deus Ex - Game of the Year Edition "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "DivX Setup" = DivX Setup "Download Manager" = Download Manager 2.3.10 "DroidAssault" = Droid Assault (remove only) "Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX "Fraps" = Fraps "GOM Picker" = GOM PICKER "GOM Player" = GOM Player "GOM Video Converter" = GOM Video Converter "GomTV Launcher Plugin" = GOMTV Plug-in "GomTVStreamer" = GOMTV Streamer "Google Chrome" = Google Chrome "GoToAssist" = GoToAssist Corporate "Half-Life Uplink" = Half-Life Uplink "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "LDC Driving Test Complete2.2" = LDC Driving Test Complete "LucasArts' Grim Fandango" = LucasArts' Grim Fandango "Machinarium" = Machinarium "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000 "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "mIRC" = mIRC "Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US) "MozillaMaintenanceService" = Mozilla Maintenance Service "MP Navigator EX 1.0" = Canon MP Navigator EX 1.0 "MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager "OggDS" = Direct Show Ogg Vorbis Filter (remove only) "OpenAL" = OpenAL "PDF Complete" = PDF Complete "Peggle Deluxe 1.01" = Peggle Deluxe 1.01 "PocketRAR" = Pocket RAR documentation "PunkBusterSvc" = PunkBuster Services "RayV" = dtvblizzcon Player "RealAlt_is1" = Real Alternative 1.9.0 "RealPlayer 12.0" = RealPlayer "Save Flash" = Save Flash 4.2 "Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2 "TrueCrypt" = TrueCrypt "UDK-06f58e28-1a8c-4631-ae8f-7bb68abcf9df" = Fps Terminator "uTorrent" = µTorrent "Veoh Web Player Beta" = Veoh Web Player "VLC media player" = VLC media player 0.9.9 "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "WMV9_VCM" = Microsoft Windows Media Video 9 VCM "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist "Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player "Octoshape Streaming Services" = Octoshape Streaming Services "Spotify" = Spotify "UnityWebPlayer" = Unity Web Player
========== Last 20 Event Log Errors ==========
[ Application Events ] Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6094
Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6094
Error - 02/11/2012 07:11:17 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 02/11/2012 07:11:18 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 8172
Error - 02/11/2012 07:11:18 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 8172
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1953
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1953
Error - 03/11/2012 12:22:54 | Computer Name = HP13888241712 | Source = Application Error | ID = 1000 Description = Faulting application bioshock.exe, version 1.0.0.0, faulting module msvcr80.dll, version 8.0.50727.6195, fault address 0x0001500a.
[ Application Events ] Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 6094
Error - 02/11/2012 07:11:15 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 6094
Error - 02/11/2012 07:11:17 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 02/11/2012 07:11:18 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 8172
Error - 02/11/2012 07:11:18 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 8172
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: Continuously busy for more than a second
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledEvent 1953
Error - 03/11/2012 06:01:58 | Computer Name = HP13888241712 | Source = Bonjour Service | ID = 100 Description = Task Scheduling Error: m->NextScheduledSPRetry 1953
Error - 03/11/2012 12:22:54 | Computer Name = HP13888241712 | Source = Application Error | ID = 1000 Description = Faulting application bioshock.exe, version 1.0.0.0, faulting module msvcr80.dll, version 8.0.50727.6195, fault address 0x0001500a.
[ OSession Events ] Error - 17/12/2009 10:51:00 | Computer Name = HP13888241712 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 243 seconds with 180 seconds of active time. This session ended with a crash.
Error - 17/12/2009 10:51:11 | Computer Name = HP13888241712 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash.
Error - 17/12/2009 10:51:34 | Computer Name = HP13888241712 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 19 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ] Error - 10/11/2012 17:55:30 | Computer Name = HP13888241712 | Source = System Error | ID = 1003 Description = Error code 1000008e, parameter1 c0000005, parameter2 bd03d83b, parameter3 b0cae324, parameter4 00000000.
Error - 11/11/2012 04:46:35 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
Error - 11/11/2012 04:47:54 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
Error - 11/11/2012 12:52:39 | Computer Name = HP13888241712 | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort1, did not respond within the timeout period.
Error - 11/11/2012 12:53:06 | Computer Name = HP13888241712 | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).
Error - 11/11/2012 12:55:20 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
Error - 11/11/2012 12:55:47 | Computer Name = HP13888241712 | Source = atapi | ID = 262153 Description = The device, \Device\Ide\IdePort1, did not respond within the timeout period.
Error - 11/11/2012 12:57:02 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
Error - 12/11/2012 05:05:49 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
Error - 12/11/2012 05:07:15 | Computer Name = HP13888241712 | Source = DCOM | ID = 10016 Description = The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
• OTL may ask to reboot the machine. Please do so if asked. • Click OK. • A report will open. Copy and Paste that report in your next reply. • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
After the download is complete, perform the following tasks before using the ComboFix tool to scan your PC: Exit all windows that are currently open on your computer. To prevent interference, temporarily disable your antivirus, antispyware, firewall and other security tools that may be running on your computer.
Double-click on the combofix icon found on your desktop.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.
You'll be asked if you want to Begin cleanup process? Select Yes. This step removes the files, folders, and shortcuts created by the tools I had you download and run.
When done, you will be prompted to restart your computer. Please restart your computer.
Currently it is Monday, May 20, 2013 5:01 PM (GMT +3) There are a total of 59,521 posts in 13,140 threads. In the last 3 days there were 3 new threads and 6 reply posts. View Active Threads
Who's Online
This forum has 34611 registered members. Please welcome our newest member, caspied. 29 Guest(s), 0 Registered Member(s) are currently online. Details