

Mar 14 2009, 03:09 AM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
thanks Sheppey |
|
|
|
![]() |
Mar 14 2009, 06:06 AM
Post
#2
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
Hi there lets see what I can do to assist, if at any stage you are unsure then stop and come back to me for clariffication - I do not bite
This post has been edited by Essexboy: Mar 14 2009, 06:06 AM |
|
|
|
Mar 14 2009, 06:52 AM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
Hi Essexboy I hope this makes sense to you coz brain tumour or not I gotta say it looks like it will bite.... I would love some help with this thanks OTListIt logfile created on: 14/03/2009 9:45:05 PM - Run 1 OTListIt2 by OldTimer - Version 2.0.3.6 Folder = C:\Users\jb hifi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5Z7XGIXL Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18372) Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 2.00 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 80.40% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys; %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222.23 Gb Total Space | 121.71 Gb Free Space | 54.77% Space Free | Partition Type: NTFS Drive D: | 232.88 Gb Total Space | 232.79 Gb Free Space | 99.96% Space Free | Partition Type: NTFS Drive E: | 10.66 Gb Total Space | 2.39 Gb Free Space | 22.42% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PORCUPINE-CONSU Current User Name: jb hifi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) PRC - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.) PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe () PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) PRC - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools) PRC - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard) PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) PRC - C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.) PRC - C:\Windows\Explorer.EXE (Microsoft Corporation) PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) PRC - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.) PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.) PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools) PRC - C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe () PRC - C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation) PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) PRC - C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) PRC - C:\Program Files\Registry Mechanic\RMTray.exe (PC Tools) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe () PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation) PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.) PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\agent.exe (Macrovision Corporation) PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation) PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\Users\jb hifi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5Z7XGIXL\OTListIt2[1].exe (OldTimer Tools) PRC - C:\Windows\system32\msfeedssync.exe (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (ACDaemon [Auto | Running]) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.) SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (BcmSqlStartupSvc [Auto | Running]) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation) SRV - (bepldr [On_Demand | Stopped]) -- C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe () SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (Com4Qlb [On_Demand | Stopped]) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.) SRV - (DpHost [Auto | Running]) -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.) SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation) SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation) SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (GoogleDesktopManager-090808-172447 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) SRV - (gusvc [Auto | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (HP Health Check Service [Auto | Running]) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard) SRV - (hpqcxs08 [On_Demand | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.) SRV - (hpqddsvc [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.) SRV - (hpqwmiex [Auto | Running]) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.) SRV - (IAANTMON [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation) SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (MSSQL$MSSMLBIZ [On_Demand | Running]) -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) SRV - (MSSQLServerADHelper [Disabled | Stopped]) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation) SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\Windows\system32\HPZinw12.dll (Hewlett-Packard) SRV - (NetTcpPortSharing [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (nvsvc [Auto | Running]) -- C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\Windows\system32\HPZipm12.dll (Hewlett-Packard) SRV - (QPCapSvc [Auto | Running]) -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe () SRV - (QPSched [Auto | Stopped]) -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe () SRV - (RapiMgr [Auto | Running]) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation) SRV - (sdAuxService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) SRV - (sdCoreService [Auto | Running]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) SRV - (ServiceLayer [On_Demand | Stopped]) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.) SRV - (SQLBrowser [Auto | Running]) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) SRV - (SQLWriter [Auto | Running]) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) SRV - (ThreatFire [On_Demand | Running]) -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools) SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation) SRV - (WcesComm [Auto | Running]) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation) SRV - (WinDefend [Auto | Stopped]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (Afc [On_Demand | Running]) -- C:\Windows\system32\drivers\Afc.sys (Arcsoft, Inc.) DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (ASPI32 [System | Running]) -- C:\Windows\System32\drivers\ASPI32.SYS (Adaptec) DRV - (ATSWPDRV [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\ATSwpDrv.sys (AuthenTec, Inc.) DRV - (BCM43XV [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation) DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (btwaudio [On_Demand | Stopped]) -- C:\Windows\system32\drivers\btwaudio.sys (Broadcom Corporation.) DRV - (btwavdt [On_Demand | Stopped]) -- C:\Windows\system32\drivers\btwavdt.sys (Broadcom Corporation.) DRV - (btwrchid [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\btwrchid.sys (Broadcom Corporation.) DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (E100B [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation) DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (HpqKbFiltr [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.) DRV - (HpqRemHid [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.) DRV - (HSFHWAZL [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.) DRV - (HSF_DPV [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\VSTDPV3.SYS (Conexant Systems, Inc.) DRV - (ialm [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation) DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation) DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (IKFileSec [Boot | Running]) -- C:\Windows\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.) DRV - (IKSysFlt [System | Running]) -- C:\Windows\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.) DRV - (IKSysSec [System | Running]) -- C:\Windows\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.) DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.) DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation) DRV - (motmodem [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\motmodem.sys (Motorola) DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (NETw3v32 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\NETw3v32.sys (Intel® Corporation) DRV - (NETw4v32 [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\NETw4v32.sys (Intel Corporation) DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (nmwcd [On_Demand | Stopped]) -- C:\Windows\system32\drivers\ccdcmb.sys (Nokia) DRV - (nmwcdc [On_Demand | Stopped]) -- C:\Windows\system32\drivers\ccdcmbo.sys (Nokia) DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (nvlddmkm [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation) DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (pccsmcfd [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\pccsmcfd.sys (Nokia) DRV - (pctfw2 [System | Running]) -- C:\Windows\System32\drivers\pctfw2.sys (PC Tools) DRV - (PxHelp20 [Boot | Running]) -- C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (rimmptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimmptsk.sys (REDC) DRV - (rimsptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimsptsk.sys (REDC) DRV - (rismxdp [Auto | Running]) -- C:\Windows\system32\DRIVERS\rixdptsk.sys (REDC) DRV - (RTL8169 [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\Rtlh86.sys (Realtek Corporation ) DRV - (RTLWUSB [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\wg111v2.sys (NETGEAR Inc.) DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (SiSRaid2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.) DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (smserial [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\smserial.sys (Motorola Inc.) DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (SynTP [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\SynTP.sys (Synaptics, Inc.) DRV - (TfFsMon [Boot | Running]) -- C:\Windows\system32\drivers\TfFsMon.sys (PC Tools) DRV - (TfNetMon [On_Demand | Running]) -- C:\Windows\system32\drivers\TfNetMon.sys (PC Tools) DRV - (TfSysMon [Boot | Running]) -- C:\Windows\system32\drivers\TfSysMon.sys (PC Tools) DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (upperdev [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider) DRV - (USBAAPL [On_Demand | Stopped]) -- C:\Windows\System32\Drivers\usbaapl.sys (Apple, Inc.) DRV - (usb_rndisx [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\usb8023x.sys (Microsoft Corporation) DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (winachsf [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\VSTCNXT3.SYS (Conexant Systems, Inc.) DRV - ({22D78859-9CE9-4B77-BF18-AC83E81A9263} [Auto | Running]) -- C:\Program Files\HP\QuickPlay\000.fcl (Cyberlink Corp.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/02/02 19:23:35 00,000,000 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions [2008/05/06 19:23:08 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{0ca81eb3-687d-4579-9480-fbff373b43bf} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{11F9F076-72B3-4586-995D-5042CF5D3AD4} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2008/05/06 00:04:36 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{3354F302-9928-4b07-B947-82F65A8FF70D} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{3C9A65A6-9563-4485-BA4A-4BCD698BCFB4} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\{c1309325-5574-41bc-ab8a-abae2acee24b} [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\clearfields@alex.alexander.googlepages.com [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\en-AU@dictionaries.addons.mozilla.org [2008/05/05 23:31:43 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\hashcolouredtabs@bristol.ac.uk [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\myfxva@Merci.chao [2008/05/05 23:54:13 | ---D | M] FF - C:\Users\jb hifi\AppData\Roaming\mozilla\Firefox\Profiles\wplemkrp.default\extensions\zotero@chnm.gmu.edu [2008/05/05 23:33:11 | ---D | M] O1 HOSTS File: (736 bytes) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: ::1 localhost O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - Reg Error: Key error. File not found O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll () O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.) O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll (Yontoo Technology, Inc.) O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll () O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Reg Error: Key error. File not found O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe (DigitalPersona, Inc.) O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google) O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.) O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools) O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.) O4 - HKLM..\Run: [Nitro PDF Printer Monitor] "C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe" () O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation) O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start ( Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" (CyberLink Corp.) O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.) O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.) O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation) O4 - HKLM..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe (Microsoft Corporation) O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation) O4 - HKCU..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler (Macrovision Corporation) O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\rmtray.exe /H (PC Tools) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [Bluetooth Namespace] - C:\Windows\system32\wshbth.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.) O13 - gopher Prefix: missing O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/OAS/ActiveX/MSDcode.cab (Microsoft Data Collection Control) O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f...etup1.0.1.1.cab (Reg Error: Key error.) O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://sheppey2007.spaces.live.com/PhotoUp...nPUplden-au.cab (Windows Live Photo Upload Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - Autorun File - C:\autoexec.bat () - [ NTFS ] O32 - Autorun File - E:\AUTOMODE () - [ NTFS ] ========== Files/Folders - Created Within 30 Days ========== [2009/03/14 14:36:02 | 00,000,442 | ---- | C] () -- C:\Windows\tasks\RegCure Program Check.job [2009/03/14 14:36:02 | 00,000,376 | ---- | C] () -- C:\Windows\tasks\RegCure.job [2009/03/14 14:35:59 | 00,000,523 | ---- | C] () -- C:\Users\Public\Desktop\RegCure.lnk [2009/03/14 14:35:59 | 00,000,000 | ---D | C] -- C:\Program Files\RegCure [2009/03/13 23:00:24 | 00,001,849 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2009/03/11 09:58:11 | 10,622,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll [2009/03/11 09:58:10 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL [2009/03/11 09:58:10 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll [2009/03/11 09:58:10 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx [2009/03/11 09:58:10 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll [2009/03/11 09:58:07 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll [2009/03/11 09:58:05 | 02,033,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2009/03/04 09:11:19 | 00,205,096 | ---- | C] () -- C:\Users\jb hifi\Documents\email message.docx [2009/03/03 16:38:36 | 00,001,578 | ---- | C] () -- C:\Users\jb hifi\Desktop\Picasa3 - Shortcut.lnk [2009/03/03 10:30:11 | 03,212,923 | -H-- | C] () -- C:\Users\jb hifi\AppData\Local\IconCache.db [2009/02/25 10:23:22 | 00,095,744 | ---- | C] () -- C:\Users\jb hifi\Desktop\EBAY BOOKS.xls [2009/02/24 15:46:49 | 00,038,208 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys [2009/02/24 15:46:47 | 00,033,088 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys [2009/02/24 15:46:45 | 00,051,520 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys [2009/02/24 15:46:45 | 00,012,608 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfKbMon.sys [2009/02/23 16:56:43 | 00,000,000 | ---D | C] -- C:\Users\jb hifi\Desktop\my clipart [2009/02/22 10:56:58 | 00,000,000 | ---D | C] -- C:\Users\jb hifi\Desktop\seldom used desktop [2009/02/22 09:15:01 | 00,000,862 | ---- | C] () -- C:\Users\Public\Desktop\Registry Mechanic.lnk [2009/02/22 09:14:58 | 00,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic [2009/02/17 13:07:35 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll [2009/02/17 13:07:35 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax [2009/02/17 13:07:33 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll [2009/02/17 13:07:33 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax [2009/02/17 13:07:33 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax [2009/02/14 14:09:29 | 00,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer [2009/02/14 14:09:29 | 00,000,000 | ---D | C] -- C:\Program Files\Yontoo Layers Client for Internet Explorer ========== Files - Modified Within 30 Days ========== [2009/03/14 21:45:30 | 00,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F1D56839-5295-47F6-A1FA-B59FE19C424C}.job [2009/03/14 21:37:02 | 00,000,360 | ---- | M] () -- C:\Windows\tasks\Check Updates for Windows Live Toolbar.job [2009/03/14 21:09:53 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009/03/14 21:09:53 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009/03/14 19:26:21 | 00,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2009/03/14 17:00:02 | 00,000,442 | ---- | M] () -- C:\Windows\tasks\RegCure Program Check.job [2009/03/14 14:52:59 | 00,000,376 | ---- | M] () -- C:\Windows\tasks\RegCure.job [2009/03/14 14:35:59 | 00,000,523 | ---- | M] () -- C:\Users\Public\Desktop\RegCure.lnk [2009/03/13 23:00:24 | 00,001,849 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2009/03/13 22:59:11 | 00,000,205 | ---- | M] () -- C:\Users\jb hifi\Desktop\Facebook Home.url [2009/03/12 08:00:50 | 00,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini [2009/03/12 03:16:15 | 00,760,648 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2009/03/12 03:16:15 | 00,649,990 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2009/03/12 03:16:15 | 00,124,218 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2009/03/12 03:11:48 | 00,000,445 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2009/03/12 03:09:51 | 00,414,896 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2009/03/12 03:09:47 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009/03/12 03:09:45 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009/03/12 03:07:21 | 00,002,315 | ---- | M] () -- C:\Windows\bthservsdp.dat [2009/03/12 03:07:11 | 03,212,923 | -H-- | M] () -- C:\Users\jb hifi\AppData\Local\IconCache.db [2009/03/10 10:57:30 | 00,028,029 | ---- | M] () -- C:\ProgramData\nvModes.001 [2009/03/04 09:11:20 | 00,205,096 | ---- | M] () -- C:\Users\jb hifi\Documents\email message.docx [2009/03/03 16:54:44 | 00,001,578 | ---- | M] () -- C:\Users\jb hifi\Desktop\Picasa3 - Shortcut.lnk [2009/03/03 10:39:24 | 00,000,501 | ---- | M] () -- C:\Users\jb hifi\Documents\My Sharing Folders.lnk [2009/03/01 08:14:37 | 00,031,232 | ---- | M] () -- C:\Users\jb hifi\Desktop\HOME RAINFALL.xls [2009/02/25 22:29:55 | 00,070,144 | ---- | M] () -- C:\Users\jb hifi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/02/24 15:46:49 | 00,038,208 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys [2009/02/24 15:46:47 | 00,033,088 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys [2009/02/24 15:46:45 | 00,051,520 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys [2009/02/24 15:46:45 | 00,012,608 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\TfKbMon.sys [2009/02/22 09:15:01 | 00,000,862 | ---- | M] () -- C:\Users\Public\Desktop\Registry Mechanic.lnk ========== LOP Check ========== [2009/03/14 21:37:02 | 00,000,360 | ---- | M] () -- C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job [2009/03/14 19:26:21 | 00,000,868 | ---- | M] () -- C:\Windows\Tasks\Google Software Updater.job [2009/03/14 17:00:02 | 00,000,442 | ---- | M] () -- C:\Windows\Tasks\RegCure Program Check.job [2009/03/14 14:52:59 | 00,000,376 | ---- | M] () -- C:\Windows\Tasks\RegCure.job [2009/03/12 03:09:47 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT [2009/03/12 03:07:23 | 00,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2009/03/14 21:45:30 | 00,000,422 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{F1D56839-5295-47F6-A1FA-B59FE19C424C}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 2862 bytes -> C:\Users\jb hifi\Desktop\Jayne Live Space.url:favicon @Alternate Data Stream - 156 bytes -> C:\ProgramData\TEMP:D1B5B4F1 @Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:1CA73D29 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:0D786AE3 @Alternate Data Stream - 1150 bytes -> C:\Users\jb hifi\Desktop\Facebook Home.url:favicon < End of report > OTListIt Extras logfile created on: 14/03/2009 9:45:05 PM - Run 1 OTListIt2 by OldTimer - Version 2.0.3.6 Folder = C:\Users\jb hifi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5Z7XGIXL Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18372) Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 2.00 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 80.40% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys; %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 222.23 Gb Total Space | 121.71 Gb Free Space | 54.77% Space Free | Partition Type: NTFS Drive D: | 232.88 Gb Total Space | 232.79 Gb Free Space | 99.96% Space Free | Partition Type: NTFS Drive E: | 10.66 Gb Total Space | 2.39 Gb Free Space | 22.42% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PORCUPINE-CONSU Current User Name: jb hifi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = FirefoxHTML] -- Reg Error: Key error. File not found ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 "UacDisableNotify" = 0 "InternetSettingsDisableNotify" = 0 "AutoUpdateDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc "{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card "{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{03CAB33F-D1C2-48C6-8766-DAE84DFC25FE}" = Microsoft Sync Framework Services v1.0 (x86) "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500 "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer "{0AB4C03C-D10F-422E-B060-75387F61599A}" = Nitro PDF Professional "{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy "{18561BB0-946A-4715-BA98-533FEAB2B737}" = IRISCard 4 Mini "{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}" = PC Connectivity Solution "{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86 "{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery "{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1 "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 12 "{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg "{2A0A6470-FD0F-4F45-9B11-85F3167DB943}" = Nokia Flashing Cable Driver "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) "{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan "{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support "{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1 "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant "{3727B920-F5A3-46A4-AC02-94F421A039C7}" = Windows Live Toolbar Extension (Windows Live Toolbar) "{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II "{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing "{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6 "{48110A46-A3A4-481E-8230-7873B7F4C696}" = Nokia Software Updater "{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply "{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant "{4FC19392-E4A5-4CCB-B45A-AB7E8126D3C9}" = Microsoft Easy Assist "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{5023B3E9-6B73-471E-8BD9-DA4442AE357C}" = ArcSoft Print Creations - Quick Photo Book "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport "{551418E1-C355-4463-8EE7-0F34C43B92A3}" = Nitro PDF Express "{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{71310D9B-7555-44FE-914C-A1B55CB7BC5D}" = Scrapbook "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone "{74F1B237-A32C-47C7-A5B7-A64B2ACBEAD2}" = ArcSoft Print Creations "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4 "{7E445682-2515-4F0B-AF0A-874DD818F9DC}" = Highlight Viewer (Windows Live Toolbar) "{7F362F06-A9A3-440F-8B19-6A01A72723C4}" = AuthenTec Fingerprint Sensor Minimum Install "{7FF0415A-C82A-4715-B31F-6DBB8D28C1CA}" = Windows Live Toolbar "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01 "{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088 "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01 "{865DB1C9-D5E4-408B-B37D-9927E605BD2D}" = ESU for Microsoft Vista "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client for Internet Explorer 1.02.28 "{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0015-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0016-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0019-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001A-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}_PROR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-040C-0000-0000000FF1CE}_PROR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-006E-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0115-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0117-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components "{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007 "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007 "{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse "{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints "{95FC661A-A0C5-4B18-92CE-90347DA79CC9}" = Smart Menus (Windows Live Toolbar) "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend "{A40D6757-B145-4FE7-B694-89180A9F3F64}" = Windows Live Outlook Toolbar (Windows Live Toolbar) "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A73ACE08-4CA7-4d08-912E-EFE4DF521B39}" = c7200_Help "{A8BD5A60-E843-46DC-8271-ABF20756BE0F}" = Microsoft Sync Framework Runtime v1.0 (x86) "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan "{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook "{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0 "{B3164E9E-BE08-4F3B-94BC-C6D09C0205E1}" = Nokia Connectivity Cable Driver "{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1 "{B7FB6B99-C93C-4818-825B-37EF4B64C80C}" = PS_AIO_02_Software "{BA6A83B9-1D51-4A28-99DC-B8E429DA24D7}" = ArcSoft Print Creations "{BB3E6B07-2351-4424-B563-29D587C39956}" = ArcSoft Print Creations - Order Calendar "{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint "{C7AF7F33-9092-997E-2D29-DE8095863FE3}" = DigitalPersona Personal 3.0.0 "{C867F57B-39C1-4341-A164-F569839BCCBF}" = Cards "{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update "{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE4888DB-CE49-485b-AA3A-A9E0F361B277}" = C7200 "{D0077228-CFBE-4BFF-99CB-3D8B23709175}" = Microsoft Sync Framework for Devices CTP1 "{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component "{D25BDCF5-19F6-4d9e-B9C9-273FE81446C4}" = PS_AIO_02_ProductContext "{D5577624-0626-4C4B-87AA-D966DA1739D6}" = Nokia PC Suite "{D64BC2CF-0F12-47d7-B412-B4F3FD684253}" = HP Photosmart All-In-One Software 9.0 "{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}" = Windows Live Favorites for Windows Live Toolbar "{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm "{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox "{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support "{EF0D2E55-6FE2-4e35-BE22-A742E85D84E3}" = PS_AIO_02_Software_min "{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer "{F619E2AF-677D-49bc-9618-D60BDFB925DB}" = C7200_doccd "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE "{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista "{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status "{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner "3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) "9CD348AE9C64C4B939B624E8E24F3903EFDFC82B" = Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1 "C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows Driver Package - Nokia Modem (05/22/2008 3.8) "Click'N Design 3D (V5)" = Click'N Design 3D (V5) "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Desktop Maestro_is1" = Desktop Maestro 2.0 "Google Desktop" = Google Desktop "Google Updater" = Google Updater "HammerSnipe PowerTool_is1" = HammerSnipe PowerTool "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149) "HP Imaging Device Functions" = HP Imaging Device Functions 9.0 "HP Photosmart Essential" = HP Photosmart Essential 2.01 "HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0 "HPOCR" = HP OCR Software 9.0 "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft SQL Server 2005" = Microsoft SQL Server 2005 "mIRC" = mIRC "Nokia PC Suite" = Nokia PC Suite "NVIDIA Drivers" = NVIDIA Drivers "Picasa 3" = Picasa 3 "PROHYBRIDR" = 2007 Microsoft Office system "PROR" = Microsoft Office Professional 2007 "RegCure" = RegCure 1.5.2.7 "Registry Mechanic_is1" = Registry Mechanic 8.0 "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4 "SMSERIAL" = Motorola SM56 Data Fax Modem "Spyware Doctor" = Spyware Doctor 6.0 "SynTPDeinstKey" = Synaptics Pointing Device Driver "ViewpointMediaPlayer" = Viewpoint Media Player "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "Windows Live Toolbar" = Windows Live Toolbar ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Plaxo" = Plaxo Toolbar for Windows ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 11/03/2009 5:36:21 AM | Computer Name = Porcupine-Consulting | Source = VSS | ID = 8194 Description = Error - 11/03/2009 5:38:16 AM | Computer Name = Porcupine-Consulting | Source = VSS | ID = 8194 Description = Error - 11/03/2009 5:44:26 AM | Computer Name = Porcupine-Consulting | Source = Windows Search Service | ID = 3038 Description = Error - 11/03/2009 5:44:27 AM | Computer Name = Porcupine-Consulting | Source = Windows Search Service | ID = 3028 Description = Error - 11/03/2009 5:44:27 AM | Computer Name = Porcupine-Consulting | Source = Windows Search Service | ID = 3058 Description = Error - 11/03/2009 5:46:17 AM | Computer Name = Porcupine-Consulting | Source = Application Error | ID = 1000 Description = Faulting application QLBCTRL.exe, version 6.3.5.1, time stamp 0x46f16d1f, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x00000000, process id 0x170, application start time 0x01c9a22e213fe713. Error - 11/03/2009 5:48:15 AM | Computer Name = Porcupine-Consulting | Source = Outlook | ID = 34 Description = Failed to get the Crawl Scope Manager with error=0x8001010d. Error - 11/03/2009 5:48:15 AM | Computer Name = Porcupine-Consulting | Source = Outlook | ID = 35 Description = Failed to determine if the store is in the crawl scope (error=0x8001010d). Error - 11/03/2009 5:48:21 AM | Computer Name = Porcupine-Consulting | Source = Outlook | ID = 35 Description = Failed to determine if the store is in the crawl scope (error=0x8001010d). Error - 11/03/2009 5:48:25 AM | Computer Name = Porcupine-Consulting | Source = Outlook | ID = 35 Description = Failed to determine if the store is in the crawl scope (error=0x8001010d). [ DigitalPersona Pro Events ] Error - 21/02/2009 9:51:52 PM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 22/02/2009 2:30:14 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 25/02/2009 3:24:56 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 25/02/2009 5:02:17 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 28/02/2009 8:59:54 PM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 2/03/2009 9:38:06 PM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 4/03/2009 7:08:15 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 6/03/2009 6:39:28 PM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 10/03/2009 2:21:20 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. Error - 11/03/2009 5:45:40 AM | Computer Name = Porcupine-Consulting | Source = DigitalPersona Pro | ID = 17827075 Description = Agent cannot start. Description: Found other running Agent. [ Media Center Events ] Error - 1/04/2008 11:22:15 PM | Computer Name = jbhifi-PC | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.SqmFlushSession failed; Win32 GetLastError returned 0D Process: DefaultDomain Object Name: Media Center Guide Error - 16/04/2008 6:41:33 PM | Computer Name = Porcupine-Consulting | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight. Error - 17/04/2008 7:02:10 PM | Computer Name = Porcupine-Consulting | Source = MCUpdate | ID = 0 Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight. Error - 25/10/2008 2:16:15 AM | Computer Name = Porcupine-Consulting | Source = Media Center Guide | ID = 0 Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide [ OSession Events ] Error - 3/05/2008 4:13:07 AM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 17 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/05/2008 11:50:19 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 49 seconds with 0 seconds of active time. This session ended with a crash. Error - 16/06/2008 10:34:42 AM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash. Error - 1/10/2008 10:59:18 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7 seconds with 0 seconds of active time. This session ended with a crash. Error - 4/11/2008 11:11:25 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 62 seconds with 60 seconds of active time. This session ended with a crash. Error - 4/11/2008 11:11:37 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4 seconds with 0 seconds of active time. This session ended with a crash. Error - 12/11/2008 2:10:50 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6324.5001, Microsoft Office Version: 12.0.6215.1000. This session lasted 213432 seconds with 0 seconds of active time. This session ended with a crash. Error - 8/01/2009 11:05:01 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 54 seconds with 0 seconds of active time. This session ended with a crash. Error - 5/02/2009 10:17:14 PM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 214162 seconds with 11100 seconds of active time. This session ended with a crash. Error - 22/02/2009 10:07:50 AM | Computer Name = Porcupine-Consulting | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 21 seconds with 0 seconds of active time. This session ended with a crash. [ System Events ] Error - 7/10/2008 3:47:47 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 3:54:54 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:10:29 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:17:36 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:38:11 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:47:25 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:52:25 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 4:59:32 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 5:04:32 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. Error - 7/10/2008 5:24:21 AM | Computer Name = Porcupine-Consulting | Source = ipnathlp | ID = 34001 Description = The ICS_IPV6 failed to configure IPv6 stack. < End of report > |
|
|
|
Mar 14 2009, 07:04 AM
Post
#4
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
OK nothing jumps out at me there. What is your e-mail client ? i.e. Outlook, Outlook express, windows live mail
Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately. |
|
|
|
Mar 14 2009, 07:33 AM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
well i certainly hope this makes sense to you...
Malwarebytes' Anti-Malware 1.34 Database version: 1848 Windows 6.0.6001 Service Pack 1 14/03/2009 10:31:47 PM mbam-log-2009-03-14 (22-31-47).txt Scan type: Quick Scan Objects scanned: 70902 Time elapsed: 3 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 18 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Mar 14 2009, 07:36 AM
Post
#6
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
Yep sure does - this is not a malware problem but I feel I may have a solution
First we will reset IE, if that does not work I will run a small regfix To Reset Web settings 1. Open Internet Explorer. 2. On the Tools menu, click Internet Options. 3. Click the Programs tab, and then click the Reset Web Settings button. 4. Under Internet programs, verify that the correct e-mail program is selected. 5. Click to select the Internet Explorer should check to see whether it is the default browser check box. 6. Click Apply, and then click OK. Note : If you receive a message when Internet Explorer starts telling you that IE is not currently your default browser, click Yes to make it your default. Let me know how that goes whilst I prepare the reg fix |
|
|
|
Mar 14 2009, 07:44 AM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
Sorry i did that and no good. I blame IE 8 as the problem only started since i downloaded that. I am using Outlook 2007 by the way... wow I would love to know how you are doing this so fast... this has to be your life......... you are being incredibly helpful and I really do thank you as I am housebound these days since good old Jonathon entered my head..
cheers Jayne |
|
|
|
Mar 14 2009, 07:53 AM
Post
#8
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
OK Jayne I have a registry fix based on my Vista/IE8 system
Download and run ERUNT http://www.larshederer.homepage.t-online.de/erunt/ Start ERUNT, confirm the Welcome message. Type in the name of a restore folder where the backed up registry files should be saved, or click "..." to browse your computer's drives and select a folder. You can also simply leave the default, which is a folder named ERDNT inside your Windows folder, the advantage being that you have access to this folder from the Windows Recovery Console in case Windows does not boot anymore. Next, select the backup options: - System registry: - Current user registy: . - Other open user registries: Click "OK" and wait until the backup process is complete. (Note that depending on your system configuration this may take some time, and that the first bar is NOT a progress bar, just an indicator that the program is still running.) The ERDNT program for later restoration of the registry is automatically copied to the restore folder. WARNING these fixes are designed for this user only and may cause damage if run on an uninfected machine REGISTRY FIX QUOTE REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Classes\htmlfile\shell\open\command] @="\"C:\Program Files\Internet Explorer\IEXPLORE.EXE\" -nohome" Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file. Ensure there is no space above the REGEDIT4. Then in notepad go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES Then in the FILE NAME box type fix.reg This will create a fix.reg file on your desktop ![]() To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done. Then retry the links If that fails then the next option will be to uninstall IE8 and install the RC version |
|
|
|
Mar 14 2009, 08:28 AM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
Sorry Essexboy
No go after all your hard work.. I will try and uninstall the IE8 and instal the RC version (whatever that is) I dont even know how to uninstall the IE8 unless it is from add remove programs.. but for now I need to go to bed it is getting very late here in Oz I thank you for all of your help and am only sorry it didnt work out. thanks again jayne |
|
|
|
Mar 14 2009, 08:34 AM
Post
#10
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
If it was easy Jayne you wouldn't need me and I would be roaming loose on the streets somewhere causing mayhem, so you are doing good
OK to uninstall IE8 go to control panel Programmes and Features Then on the Left select View Installed Updates When the list is full Locate IE8 and uninstall Then download IE8 RC1 from here On completion let me know if that resolves it This post has been edited by Essexboy: Mar 14 2009, 08:35 AM |
|
|
|
Mar 14 2009, 07:28 PM
Post
#11
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
Essexboy
Love your work but alas to no avail... I do not have IE8 on my list of installed updates.. and I did try to just download your version and was not able to as it said I have a more current version on my computer... I am now at the point of considering a boat anchor would be a good idea if only I had a boat.. come to think of it I would still have to be able to drive to get to the ocean so forget that idea and I shall plod on with your help if you are still willing to give it... At least it will make for good conversation for you.. lol cheers Jayne |
|
|
|
Mar 15 2009, 05:54 AM
Post
#12
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
HI Jayne defeat at this stage is not an option.. So if you have the time so do I
Give me a few hours whilst I do some more research and I will be back with another try |
|
|
|
Mar 15 2009, 07:08 AM
Post
#13
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
you are rapidly becoming a god you had better be careful i may expect you to come up with the answer now...
thanks cheers Jayne |
|
|
|
Mar 15 2009, 07:18 AM
Post
#14
|
|
![]() SuperMember Group: Classroom Teacher Posts: 1,397 Joined: 8-November 08 From: Darkest Cornwall Member No.: 82,302 Operating System: Vista Ultimate Windows 7 |
OK Jayne whilst I beaver around the web, let me have a look a bit deeper to see if I can find an errant registry entry. This will give you something to do as well
To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link. Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
Please attach the log in your next post. To attach a file, do the following:
|
|
|
|
Mar 15 2009, 08:03 AM
Post
#15
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 14-March 09 Member No.: 84,674 Operating System: vista |
Hi Essexboy
sorry cant do the scan when it gets to the part of scanning the application it comes up with an error message that reads Access violation at address 770895973 in module 'ntdll.dll' read of address 0000002C I press ok and then everything hangs up.. i am actually off to bed again now it is getting past my beauty sleep and by this time of night my drugs are totally fuzzing my head.. dont worry if it didnt work you still are gaining to god status for even trying cheers Jayne |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | Jeff Davis | 63 | Today, 03:54 AM Last post by: Jeff Davis |
|||
![]() |
2 | Havoc | 66 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | Ticker | 301 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | valhuse | 88 | Yesterday, 03:59 PM Last post by: LDTate |
|||
|
Time is now: 21st November 2009 - 01:49 PM |