Jump to content

inangie

Honorary Members
  • Posts

    44
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Thank you so much for helping me! :)

  2. Alright, I have finished step 1. And I will consider your recommendations in step 2. Thank you for helping me that much. I really appreciate that.
  3. Ok, both of them worked, and maxlook created a window and said it's cleaned up, also Combofix said it's uninstalled. So now im going to progress to the rest. Thank you.
  4. Thank you so much! Also thanks for your recommendations on the antispyware and antivirus programs above. I still have a question though. In step 1, when I executed the Run program and typed "maxlook -cleanup" or "Combofix /Uninstall", there was an error message came up and said, "Windows cannot find 'maxlook (or ComboFix)'. Make sure you typed the name correctly, and then try again." Is it alright?
  5. Here is the log of OTL: ========== FILES ========== C:\SwSetup\HPGame\games\wheeloffortune-setup.exe moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.52.30\susp0000\svc0000 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.52.30\susp0000 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.52.30 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0001\svc0000 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0001 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0000\svc0000 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0000 folder moved successfully. C:\TDSSKiller_Quarantine\14.10.2010_14.40.52 folder moved successfully. C:\TDSSKiller_Quarantine folder moved successfully. C:\Users\Administrator\Desktop\Files_for_submission.zip moved successfully. C:\Users\Administrator\Saved Games\Gang Garrison 2\Gang Garrison 2.exe moved successfully. OTL by OldTimer - Version 3.2.15.2 log created on 10192010_073733 I think my computer is running ok now, there is no more false warning from fake Antivirus 2010. But I restart the AVG Anti-virus and to attempted to run a whole computer scan, but it will not scan anything. Should I try to reinstall it or try to uninstall and look for another antivirus program to scan my computer and get protected?
  6. Here is the scan log of Kaspersky Online Scanner: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, October 19, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, October 19, 2010 01:32:02 Records in database: 4185997 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 166541 Threats found: 3 Infected objects found: 11 Suspicious objects found: 0 Scan duration: 03:33:14 File name / Threat / Threats count C:\Qoobox\Quarantine\[4]-Submit_2010-10-16_04.38.44.zip Infected: Rootkit.Win32.Agent.bjqb 1 C:\SwSetup\HPGame\games\wheeloffortune-setup.exe Infected: Trojan-Mailfinder.Win32.Blen.ys 1 C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0000\svc0000\tsk0000.dta Infected: Rootkit.Win32.Agent.bjqb 1 C:\TDSSKiller_Quarantine\14.10.2010_14.40.52\susp0001\svc0000\tsk0000.dta Infected: Rootkit.Win32.Agent.bjqb 1 C:\TDSSKiller_Quarantine\14.10.2010_14.52.30\susp0000\svc0000\tsk0000.dta Infected: Rootkit.Win32.Agent.bjqb 1 C:\Users\Administrator\Desktop\Files_for_submission.zip Infected: Rootkit.Win32.Agent.bjqb 4 C:\Users\Administrator\Saved Games\Gang Garrison 2\Gang Garrison 2.exe Infected: Constructor.Win32.IDL.ev 1 C:\Windows\maxdrive\vbma92a1.sys Infected: Rootkit.Win32.Agent.bjqb 1 Selected area has been scanned.
  7. I ran the scan with MBAM but it didn't find any thing, this makes me feel weird, is this normal? here is the log of MBAM: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4877 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 10/18/2010 11:38:09 PM mbam-log-2010-10-18 (23-38-09).txt Scan type: Quick scan Objects scanned: 149330 Time elapsed: 9 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
  8. This is the links of the file scan from step 1: vbma92a1.sys http://virscan.org/report/64c78f1fc77836e8...76e024b855.html tsk0000.dta http://virscan.org/report/876c22aa08da1d24...f4d3d32a17.html But an error message came up as I tried to upload cpuz_x32.sys to scan, the message is "ERROR: Can't find upload file!" And then I pressed the Browse button on virscan.org and see the location of the file, but when I located in C:\Users\Angie\AppData\Local\Temp\ , there is no file in the Temp folder, so I can't scan that file.
  9. I finished step 4 and now should I go back to step 1 and run the file scan for cpuz_x32.sys?
  10. And here is the log of Combofix in step 3: ComboFix 10-10-15.03 - Administrator 10/16/2010 4:39.1.2 - x86 Microsoft
  11. here is the OTL fixlog: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. C:\Users\Administrator\Desktop\OTL(2).scr moved successfully. C:\Users\Administrator\Desktop\eXplorer.exe moved successfully. C:\Users\Administrator\Desktop\iExplore.exe moved successfully. C:\Users\Administrator\Desktop\OTH.scr moved successfully. C:\Users\Administrator\Desktop\OTH(2).scr moved successfully. C:\Users\Administrator\Desktop\OTL.scr moved successfully. C:\Users\Administrator\Desktop\in.exe moved successfully. C:\Users\Administrator\Desktop\OTL(3).exe moved successfully. C:\Users\Administrator\Desktop\inalangie.exe moved successfully. C:\Users\Administrator\Desktop\OTL(2).exe moved successfully. C:\Users\Administrator\Desktop\OTL.exe moved successfully. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2C52DE7C-DB6A-42EC-93AE-D17BD539BA7F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C52DE7C-DB6A-42EC-93AE-D17BD539BA7F}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{630EDC35-FD85-48BB-9B32-6B368AC2CD3E} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{630EDC35-FD85-48BB-9B32-6B368AC2CD3E}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7BA8D332-7384-4137-8D8D-73B0DAFC04AC}C:\program files\utorrent\utorrent.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8E63E824-AA65-4D08-965C-0F43D2718C7F}C:\program files\easymule\emule.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{BD747BF5-7163-4875-87B5-4E98392EE189}C:\program files\easymule\emule.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7891C201-3244-46DA-AE7C-9813460C5733}C:\program files\easymule\emule.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BB8C8B60-DAFA-468F-AAE2-BD0921A37C4F}C:\program files\utorrent\utorrent.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{EE5F72BA-73C1-449F-873C-080E8024220E}C:\program files\easymule\emule.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F3079C73-BB3A-49B0-932A-D6A56902F93C}C:\program files\bitcomet\bitcomet.exe deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 80181 bytes ->Temporary Internet Files folder emptied: 7369875 bytes ->Java cache emptied: 13978980 bytes ->FireFox cache emptied: 49756578 bytes ->Flash cache emptied: 114106 bytes User: All Users User: Angie ->Temp folder emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 68.00 mb [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Angie User: Default User: Default User User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.15.2 log created on 10152010_111434 Files\Folders moved on Reboot... File\Folder C:\Users\Administrator\AppData\Local\Temp\~DF104A.tmp not found! File\Folder C:\Users\Administrator\AppData\Local\Temp\~DF1056.tmp not found! File\Folder C:\Users\Administrator\AppData\Local\Temp\~DFD97A.tmp not found! File\Folder C:\Users\Administrator\AppData\Local\Temp\~DFD986.tmp not found! C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPMTMF1F\ads[5].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NPMTMF1F\ads[6].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AE6LX1A2\iframe[1].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AE6LX1A2\index[6].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9FUVOLNN\876c22aa08da1d24ea0ad6f4d3d32a17[1].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9FUVOLNN\ads[8].htm moved successfully. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully. Registry entries deleted on Reboot...
  12. I was waiting for the scanner to finish and then do the cpuz_x32.sys file again with the method which you had suggested. However, a different scan result came up, and here is the web link: http://virscan.org/report/876c22aa08da1d24...f4d3d32a17.html
  13. Btw, I tried once again for the tsk0000.dta and when the message (the same one above and only the file name is different) came up there are two buttons underneath it one is "ReScan", and other one is "Scan Report". I just pressed ReScan, and it's checking for virus.
  14. When I uploaded the vbma92a1.sys and tsk0000.dta (both three of them), the website said "The file are vbma92a1.sys uploaded by other users and scanned successfully at 2010/10/09 18:38:22, and 33 softwares update the database from last scan to now." And then when I click "Scan Report", it redirect me to a webpage, here is the address: http://virscan.org/report/d069bf727c8896c0...3ede0ecd1b.html or do you want me to copy the content of the webpage and post it as a reply? And for the cpuz_x32.sys, I tried to upload the file but error message came up :" ERROR: Failed to find flength file!" And when I tried again, error message came up :"ERROR: Can't find upload file!" Should I continue to step 2?
  15. Here is the log of Extras.Txt: OTL Extras logfile created on: 10/14/2010 6:35:24 PM - Run 1 OTL by OldTimer - Version 3.2.15.2 Folder = C:\Users\Administrator\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free 4.00 Gb Paging File | 3.00 Gb Available in Paging File | 82.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 66.48 Gb Total Space | 17.78 Gb Free Space | 26.74% Space Free | Partition Type: NTFS Drive D: | 8.04 Gb Total Space | 1.80 Gb Free Space | 22.43% Space Free | Partition Type: NTFS Computer Name: MEMORIES2 | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 90 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-3347607031-721071281-896682233-500\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{2CFD1406-17E2-4E31-9B2A-48398A00D9AE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{BD8C9876-D020-4640-A0F2-A54A0E3C667A}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{02A5E248-9C62-4825-AF4A-639FDCDFB76F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{16966575-01B9-4E8E-AA59-05DDA23F60BB}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe | "{18CDF69B-2AC8-47E5-A6D8-4D581A618267}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{2C52DE7C-DB6A-42EC-93AE-D17BD539BA7F}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{4CA7B5A8-30FA-4D1A-93BF-9ADCC28BACEC}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{5263EB6C-C32D-42ED-85BA-6ACF0EFA275E}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{5B83DE6B-BB2F-4372-A8A6-8F5F35689DA3}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | "{5E4C870B-F118-4492-AB7C-72FC110E942E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{630EDC35-FD85-48BB-9B32-6B368AC2CD3E}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "{84964846-0ADE-4863-A648-CE7765AD75F2}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{9F854534-00F2-4FC6-9DCE-27D00FE51D06}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{A8A9484E-DD95-40AB-AE90-65A9024FFAFF}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe | "{B0284CB3-0B8D-4465-B4D8-BFB005C86368}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{BA127B7C-3CA3-494B-9858-B4DD1995C09A}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "{C41AE8F2-87AD-46A2-B2C6-2E3C25654AB5}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe | "{C7C9370D-3276-45B7-8743-1BA48E38EBB1}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe | "{D12B869A-36A9-4CD7-8C1C-C26C2F6B6D12}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe | "{EA468C31-1C10-4FED-A10C-B6C3D4C56FE1}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe | "{EF42A82C-013A-4A8C-89FD-BE5F15858225}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe | "{FB86B605-8063-4112-8CA2-7DD9D8C21F6B}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe | "TCP Query User{14C4C763-E287-40AC-BC9C-20D423BCAA97}C:\program files\dosbox-0.61\dosbox.exe" = protocol=6 | dir=in | app=c:\program files\dosbox-0.61\dosbox.exe | "TCP Query User{217B592B-F5B1-4DD5-9BEA-C5CC71A78DA9}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "TCP Query User{2349757A-3EF0-4307-9FFF-8A4E9CBEB10E}C:\program files\dosbox-0.61\dosbox.exe" = protocol=6 | dir=in | app=c:\program files\dosbox-0.61\dosbox.exe | "TCP Query User{2DFC4BC8-188B-4363-8FEE-05C9D472A2FE}C:\program files\microsoft games\age of empires iii\age3y.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe | "TCP Query User{311F6DDE-AC7D-4C09-AE04-3DE3932BBF03}C:\program files\microsoft lifecam\lifecam.exe" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe | "TCP Query User{56E0D778-CC0B-45D1-AE19-9611171783F6}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "TCP Query User{5CFC0DAB-0CAC-4547-9308-C54236EE7D80}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe | "TCP Query User{5FDC6F15-7793-46D1-A9A8-49585CE2FE4B}C:\program files\hp\hp software update\hpwucli.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "TCP Query User{660C9454-EE5C-492D-9ED9-6AFF9BA4FDC8}C:\program files\tudou\itudou\itudou.exe" = protocol=6 | dir=in | app=c:\program files\tudou\itudou\itudou.exe | "TCP Query User{6D8F98C0-7398-45AF-8215-D08F48F6B49C}C:\program files\microsoft lifecam\lifeexp.exe" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe | "TCP Query User{7BA8D332-7384-4137-8D8D-73B0DAFC04AC}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe | "TCP Query User{8E63E824-AA65-4D08-965C-0F43D2718C7F}C:\program files\easymule\emule.exe" = protocol=6 | dir=in | app=c:\program files\easymule\emule.exe | "TCP Query User{B2E7F952-993C-4B2C-A12E-3F6A8B9838BD}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe | "TCP Query User{B4A8BEBC-BD1A-4FCF-82FC-C4899101BFD2}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe | "TCP Query User{B7192848-F2E5-4A35-9D9A-99ABB05B21AF}C:\program files\steam\steamapps\insurrogate24\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\insurrogate24\team fortress 2\hl2.exe | "TCP Query User{BD747BF5-7163-4875-87B5-4E98392EE189}C:\program files\easymule\emule.exe" = protocol=6 | dir=in | app=c:\program files\easymule\emule.exe | "TCP Query User{F56ACB45-8F4D-4EC0-8B56-BCD69E4860BC}C:\program files\silkroad\silkerrsender.exe" = protocol=6 | dir=in | app=c:\program files\silkroad\silkerrsender.exe | "TCP Query User{FC73AC66-27A7-4DD5-99D0-A2D8E9A561EA}C:\users\angie\downloads\sro_l4_full_client_downloader.exe" = protocol=6 | dir=in | app=c:\users\angie\downloads\sro_l4_full_client_downloader.exe | "UDP Query User{33827917-1430-41D2-9E07-57253CE5E94F}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe | "UDP Query User{356D608A-DA12-4ED5-9D38-1BC5ECFA7446}C:\program files\microsoft lifecam\lifecam.exe" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe | "UDP Query User{50F4F7D1-B273-47B6-9A7E-44CE4D78AE0E}C:\program files\steam\steamapps\insurrogate24\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\insurrogate24\team fortress 2\hl2.exe | "UDP Query User{5DE8D926-BC03-4949-A701-80D606F53179}C:\program files\hp\hp software update\hpwucli.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp software update\hpwucli.exe | "UDP Query User{63D90A42-10CE-45B6-910A-75D75B63145E}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe | "UDP Query User{6BD8AA05-39EC-433D-B569-F9D7CB1B9548}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | "UDP Query User{7891C201-3244-46DA-AE7C-9813460C5733}C:\program files\easymule\emule.exe" = protocol=17 | dir=in | app=c:\program files\easymule\emule.exe | "UDP Query User{8C8971FB-3142-41A3-96CD-639720661332}C:\program files\tudou\itudou\itudou.exe" = protocol=17 | dir=in | app=c:\program files\tudou\itudou\itudou.exe | "UDP Query User{99CB3D8E-011D-409A-B5F2-5CBCC740CAC0}C:\program files\microsoft lifecam\lifeexp.exe" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe | "UDP Query User{9E3047C3-D928-4F36-AC4F-5E85064F4F82}C:\program files\dosbox-0.61\dosbox.exe" = protocol=17 | dir=in | app=c:\program files\dosbox-0.61\dosbox.exe | "UDP Query User{A133BDA5-3302-40B0-A61A-1A4D25407146}C:\program files\dosbox-0.61\dosbox.exe" = protocol=17 | dir=in | app=c:\program files\dosbox-0.61\dosbox.exe | "UDP Query User{A3AA6A5C-D62A-4CCE-9144-6998614B2DD9}C:\program files\microsoft games\age of empires iii\age3y.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe | "UDP Query User{BB8C8B60-DAFA-468F-AAE2-BD0921A37C4F}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe | "UDP Query User{BD7AAD69-9DA4-4511-B77C-DF80B7B04C1B}C:\users\angie\downloads\sro_l4_full_client_downloader.exe" = protocol=17 | dir=in | app=c:\users\angie\downloads\sro_l4_full_client_downloader.exe | "UDP Query User{DE5BD161-6D71-4ADE-930B-0E96D72AC738}C:\program files\microsoft games\age of mythology\aomx.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of mythology\aomx.exe | "UDP Query User{EE5F72BA-73C1-449F-873C-080E8024220E}C:\program files\easymule\emule.exe" = protocol=17 | dir=in | app=c:\program files\easymule\emule.exe | "UDP Query User{F3079C73-BB3A-49B0-932A-D6A56902F93C}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe | "UDP Query User{F888BBD4-149E-4819-A943-1EB34ABA8427}C:\program files\silkroad\silkerrsender.exe" = protocol=17 | dir=in | app=c:\program files\silkroad\silkerrsender.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{067EC517-9731-43FD-B4D5-296EE0027BBB}" = LogMeIn Hamachi "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data "{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library "{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 17 "{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine "{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9 "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3FFB3B34-D639-4384-9AE9-DDE58430D86F}" = MSCU for Microsoft Vista "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy "{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver "{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista "{88A548E6-4B09-43E7-AD55-3C7D1B37706D}" = ESU for Microsoft Vista "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger "{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1 "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support "{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4 "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B6335C5F-0064-4F90-8447-52614F8F0CE0}" = HP User Guides 0079 "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9 "{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D32067CD-7409-4792-BFA0-1469BCD8F0C8}" = HP Wireless Assistant "{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes "{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729) "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01 "{F6B29003-A078-4491-AFBE-62EFB6CFFE19}" = HP Total Care Advisor "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel "{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = HP Active Support Library 32 bit components "Ad-Aware" = Ad-Aware "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Age of Mythology 1.0" = Age of Mythology "Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion "Aleks 3.8" = Aleks 3.8 "Browser Defender_is1" = Browser Defender 2.0.6.15 "CNXT_HDAUDIO" = Conexant HD Audio "ENTERPRISE" = Microsoft Office Enterprise 2007 "Free iPod Video Converter_is1" = Free iPod Video Converter 1.26 "Free WMA to MP3 Converter_is1" = Free WMA to MP3 Converter 1.16 "Freecorder Toolbar" = Freecorder Toolbar "HDMI" = Intel® Graphics Media Accelerator Driver "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III "LogMeIn Hamachi" = LogMeIn Hamachi "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10) "NIS" = Norton Internet Security "PuTTY_is1" = PuTTY version 0.60 "Spyware Doctor" = Spyware Doctor 7.0 "Steam App 440" = Team Fortress 2 "SynTPDeinstKey" = Synaptics Pointing Device Driver "The KMPlayer" = The KMPlayer (remove only) "VobSub" = VobSub v2.23 (Remove Only) "WinDjView" = WinDjView 1.0.3 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "Xming_is1" = Xming 6.9.0.31 "Xming-fonts_is1" = Xming-fonts 7.5.0.11 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10/12/2010 3:54:22 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 5:19:14 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 7:47:52 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 7:48:24 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 8:44:57 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 8:58:41 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/12/2010 10:04:40 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/13/2010 7:04:26 AM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/14/2010 12:11:32 PM | Computer Name = Memories2 | Source = EventSystem | ID = 4609 Description = Error - 10/14/2010 12:36:12 PM | Computer Name = Memories2 | Source = Application Hang | ID = 1002 Description = The program regsearch.exe version 2.0.6.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 1c4 Start Time: 01cb6bbd9cfbc5f0 Termination Time: 0 [ Media Center Events ] Error - 10/27/2008 7:58:22 PM | Computer Name = Memories2 | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 9/21/2009 7:27:19 PM | Computer Name = Memories2 | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. Error - 10/11/2009 10:26:03 PM | Computer Name = Memories2 | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule. [ OSession Events ] Error - 4/29/2008 7:07:03 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 5640 seconds with 2340 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:07:26 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:08:07 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:08:32 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:09:40 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 54 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:10:13 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 17 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:20:29 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 603 seconds with 420 seconds of active time. This session ended with a crash. Error - 4/29/2008 7:20:55 PM | Computer Name = Memories2 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 10/14/2010 3:08:09 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7000 Description = Error - 10/14/2010 3:18:00 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7030 Description = Error - 10/14/2010 3:30:59 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7030 Description = Error - 10/14/2010 4:06:21 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7000 Description = Error - 10/14/2010 4:06:21 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7000 Description = Error - 10/14/2010 4:08:19 PM | Computer Name = Memories2 | Source = Dhcp | ID = 1002 Description = The IP address lease 130.85.226.178 for the Network Card with network address 001A7390D5B4 has been denied by the DHCP server 1.1.1.1 (The DHCP Server sent a DHCPNACK message). Error - 10/14/2010 4:12:56 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7031 Description = Error - 10/14/2010 4:15:07 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7031 Description = Error - 10/14/2010 6:17:52 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7000 Description = Error - 10/14/2010 6:17:52 PM | Computer Name = Memories2 | Source = Service Control Manager | ID = 7000 Description = < End of report >
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.