Gringo,
Thanks a lot for helping me. I have done as you recommended in your post and have not heard any advertisements yet. I hope this worked but as I have learned in the past sometimes the problem appears to be gone but it isn't completely. Here are my log files, let me know what to do next. If it appears my computer is clean now I would like to get your recommendation on what software I should use to keep it safe (without causing a loss of performance). I have the trial version of Norton and it seems to be pretty good. I am considering paying to activate it once the trial version is up but let me know what your thoughts are. thanks again.
Andrew
MBAM Log
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3947
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
4/2/2010 6:57:48 PM
mbam-log-2010-04-02 (18-57-48).txt
Scan type: Quick scan
Objects scanned: 102805
Time elapsed: 2 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Windows\SysWOW64\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{a9722a0d-365f-47d2-b70b-37d046316d99} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{efb5a774-79f8-5037-dc3e-92c6e72f3672} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{efb5a774-79f8-5037-dc3e-92c6e72f3672} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ihoefgyztb (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ezlife (Adware.EZlife) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Windows\SysWOW64\rwpviuhukgbfl.dll (Adware.Adrotator) -> Delete on reboot.
C:\Users\Andrew Brown\Documents\downloads\adware-pro-v04.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\System32\qyuapejm.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Windows\System32\smmqklzn.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 1 (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 2 (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Users\Andrew Brown\AppData\Local\Temp\COM Security Update Level 7 (Adware.Adrotator) -> Quarantined and deleted successfully.
———————————————————————————————————————————————————————————————-
OTList
OTL logfile created on: 4/2/2010 7:05:04 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Andrew Brown\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.25 Gb Total Space | 329.51 Gb Free Space | 72.86% Space Free | Partition Type: NTFS
Drive D: | 13.21 Gb Total Space | 2.20 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 96.46 Mb Free Space | 97.41% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ANDREWBROWN-PC
Current User Name: Andrew Brown
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Andrew Brown\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccsvchst.exe (Symantec Corporation)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe (CyberLink Corp.)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
========== Modules (SafeList) ==========
MOD - C:\Users\Andrew Brown\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe (IDT, Inc.)
SRV:
64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:
64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:
64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:
64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:
64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:
64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:
64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:
64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:
64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:
64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:
64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:
64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:
64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:
64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:
64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:
64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:
64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:
64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:
64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV:
64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard)
SRV:
64bit: - (AESTFilters) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (NIS) – C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe (Symantec Corporation)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 23:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 23:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:
64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (ccHP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\cchpx64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symefa64.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\ironx64.sys (Symantec Corporation)
DRV:
64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symtdiv.sys (Symantec Corporation)
DRV:
64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:
64bit: - (SymDS) – C:\Windows\SysNative\drivers\NISx64\1105000.07F\symds64.sys (Symantec Corporation)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:
64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:
64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:
64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:
64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:
64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:
64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:
64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:
64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:
64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:
64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:
64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:
64bit: - (vwifimp) – C:\Windows\SysNative\drivers\vwifimp.sys (Microsoft Corporation)
DRV:
64bit: - (vwififlt) – C:\Windows\SysNative\drivers\vwififlt.sys (Microsoft Corporation)
DRV:
64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:
64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:
64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:
64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\drivers\usbvideo.sys (Microsoft Corporation)
DRV:
64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:
64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:
64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:
64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:
64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:
64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:
64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:
64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:
64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:
64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:
64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:
64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:
64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:
64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:
64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:
64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard)
DRV:
64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard)
DRV:
64bit: - (enecir) – C:\Windows\SysNative\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV:
64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:
64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100324.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100402.004\EX64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100402.004\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100326.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-4258229573-526587920-623500243-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2010/03/12 19:24:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/12 19:40:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\ [2010/03/13 13:22:16 | 000,000,000 | —D | M]
[2010/03/13 15:18:12 | 000,000,000 | —D | M] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla\Extensions
[2010/03/13 15:18:12 | 000,000,000 | —D | M] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla\Extensions\[removed]
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.5.0.127\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-4258229573-526587920-623500243-1001\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll File not found
O4:
64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:
64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:
64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/04/02 19:03:35 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/04/02 19:02:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2010/04/02 18:50:43 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Malwarebytes
[2010/04/02 18:50:37 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/02 18:50:35 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/02 18:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/02 18:50:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/04/02 18:48:41 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Users\Andrew Brown\Desktop\OTL.exe
[2010/04/02 00:57:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/04/01 21:44:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Tific
[2010/04/01 21:23:28 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/01 21:23:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/04/01 21:23:03 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/01 21:23:03 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/01 21:23:03 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/01 20:13:24 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/04/01 19:21:04 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CrashDumps
[2010/04/01 19:19:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/03/30 20:50:24 | 001,192,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wininet.dll
[2010/03/30 20:50:24 | 001,026,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstime.dll
[2010/03/30 20:50:24 | 000,977,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2010/03/30 20:50:24 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2010/03/30 20:50:24 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iedkcs32.dll
[2010/03/30 20:50:24 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2010/03/30 20:50:24 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedsbs.dll
[2010/03/30 20:50:24 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedsbs.dll
[2010/03/29 23:44:15 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\IUPUI MBA Application
[2010/03/29 19:08:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio
[2010/03/29 19:06:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2010/03/21 22:38:35 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CutePDF Writer
[2010/03/20 15:31:28 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Financial
[2010/03/18 21:39:30 | 000,000,000 | —D | C] – C:\Program Files\HP
[2010/03/18 21:39:25 | 000,127,488 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZSPOOL.DLL
[2010/03/18 21:39:25 | 000,115,200 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZLhp1020.DLL
[2010/03/18 21:39:25 | 000,061,952 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZIMF.DLL
[2010/03/18 21:39:25 | 000,049,664 | —- | C] (Zenographics, Inc.) – C:\Windows\SysNative\ZTAG.DLL
[2010/03/17 18:09:17 | 000,143,360 | R— | C] (Zenographics) – C:\Windows\apptune1020.exe
[2010/03/17 18:09:14 | 000,086,016 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZSPOOL.DLL
[2010/03/17 18:09:14 | 000,028,672 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\IMF32.DLL
[2010/03/17 18:09:14 | 000,024,576 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZTAG32.DLL
[2010/03/17 18:09:13 | 000,086,016 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\ZLhp1020.dll
[2010/03/17 18:09:13 | 000,028,672 | R— | C] (Zenographics, Inc.) – C:\Windows\SysWow64\zlm.dll
[2010/03/17 18:09:10 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Zenographics
[2010/03/15 23:40:04 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Adobe
[2010/03/15 22:36:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Config
[2010/03/15 22:34:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AnswerWorks 5.0
[2010/03/15 22:34:02 | 004,199,784 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\Windows\SysWow64\cdintf400.dll
[2010/03/15 22:32:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intuit
[2010/03/15 22:32:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Quicken
[2010/03/15 22:32:22 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Intuit
[2010/03/15 22:31:50 | 000,000,000 | —D | C] – C:\ProgramData\Intuit
[2010/03/14 14:05:31 | 000,409,624 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStor.sys
[2010/03/14 14:05:31 | 000,000,000 | —D | C] – C:\Intel
[2010/03/14 14:05:24 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\InstallShield
[2010/03/14 14:04:23 | 004,239,976 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\NVStWiz.exe
[2010/03/14 14:03:33 | 000,183,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcod168.dll
[2010/03/14 12:38:26 | 000,000,000 | —D | C] – C:\ProgramData\{657095DF-DBDB-4B17-8245-B38845C97069}
[2010/03/14 12:25:10 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\HP Support Assistant
[2010/03/14 01:21:50 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Roaming\.#
[2010/03/14 01:04:34 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\TurboTax
[2010/03/14 01:04:26 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Quicken
[2010/03/14 01:04:09 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Quaestor Stuff
[2010/03/14 01:04:03 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Projects
[2010/03/14 01:03:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Old Masters
[2010/03/14 01:02:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Musicnotes
[2010/03/14 01:02:18 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Internships
[2010/03/14 01:02:12 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\General Academic Info
[2010/03/14 01:02:06 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Games
[2010/03/14 00:43:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\DC Downloads
[2010/03/14 00:41:42 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Classes
[2010/03/13 23:47:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2010/03/13 23:47:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acro Software
[2010/03/13 23:18:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\LightScribe
[2010/03/13 23:05:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\LightScribe
[2010/03/13 23:00:23 | 000,000,000 | —D | C] – C:\ProgramData\LightScribe
[2010/03/13 15:18:16 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\LimeWire
[2010/03/13 15:18:12 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Mozilla
[2010/03/13 15:17:57 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\LimeWire
[2010/03/13 15:17:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\LimeWire
[2010/03/13 14:59:31 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Apple Computer
[2010/03/13 14:59:31 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apple Computer
[2010/03/13 14:59:25 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/03/13 14:59:25 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/03/13 14:59:24 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/03/13 14:59:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/03/13 14:59:06 | 000,000,000 | —D | C] – C:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2010/03/13 14:58:31 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/03/13 14:58:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/03/13 14:58:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/03/13 14:58:10 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/13 14:57:59 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apple
[2010/03/13 14:57:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2010/03/13 14:57:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/03/13 14:57:28 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/03/13 14:57:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/03/13 13:52:52 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Tracing
[2010/03/13 13:26:17 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\WildTangent
[2010/03/13 13:15:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2010/03/13 13:12:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Microsoft Help
[2010/03/13 13:02:08 | 014,629,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010/03/13 13:02:08 | 011,406,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010/03/13 13:02:07 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2010/03/13 13:02:07 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2010/03/13 13:02:06 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010/03/13 13:02:06 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010/03/13 13:01:16 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2010/03/13 13:01:16 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2010/03/13 13:01:16 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2010/03/13 13:01:16 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2010/03/13 13:01:16 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2010/03/13 13:01:15 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2010/03/13 13:01:15 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2010/03/13 13:01:15 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2010/03/13 13:01:15 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2010/03/13 13:01:15 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/03/13 13:01:15 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2010/03/13 13:01:15 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/03/13 13:01:15 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2010/03/13 13:01:15 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2010/03/13 13:01:15 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/03/13 13:01:15 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2010/03/13 13:01:14 | 000,960,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/03/13 13:01:14 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/03/13 13:01:14 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2010/03/13 13:01:14 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/03/13 13:01:14 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/03/13 13:01:14 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/03/13 13:01:14 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/03/13 13:01:13 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010/03/13 13:01:13 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/03/13 13:01:13 | 000,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010/03/13 13:01:13 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010/03/13 13:01:13 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2010/03/13 13:01:13 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2010/03/13 13:01:03 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/03/13 13:01:03 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010/03/13 13:01:03 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010/03/13 13:00:50 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010/03/13 13:00:50 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010/03/13 13:00:50 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010/03/13 13:00:50 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010/03/13 13:00:50 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iyuv_32.dll
[2010/03/13 13:00:50 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvidc32.dll
[2010/03/13 13:00:50 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msyuv.dll
[2010/03/13 13:00:50 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrle32.dll
[2010/03/13 13:00:50 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsbyuv.dll
[2010/03/13 13:00:49 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010/03/13 13:00:49 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010/03/13 13:00:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010/03/13 13:00:49 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010/03/13 13:00:49 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010/03/13 13:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010/03/13 13:00:44 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010/03/13 13:00:44 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010/03/13 13:00:39 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2010/03/13 01:02:48 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\Documents\Downloads
[2010/03/13 00:59:32 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Google
[2010/03/13 00:59:23 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Deployment
[2010/03/13 00:59:23 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Apps
[2010/03/13 00:50:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\CyberLink
[2010/03/13 00:50:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\CyberLink
[2010/03/13 00:50:54 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\PowerCinema
[2010/03/12 23:50:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2010/03/12 23:37:58 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[2010/03/12 19:40:01 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2010/03/12 19:37:01 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\HpUpdate
[2010/03/12 19:28:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Macromedia
[2010/03/12 19:28:56 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Adobe
[2010/03/12 19:27:48 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\hpqLog
[2010/03/12 19:24:49 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\IsolatedStorage
[2010/03/12 19:24:16 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/03/12 19:24:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/03/12 19:24:15 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/03/12 19:22:27 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Searches
[2010/03/12 19:22:20 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Identities
[2010/03/12 19:22:19 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Contacts
[2010/03/12 19:22:17 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\VirtualStore
[2010/03/12 19:05:55 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Hewlett-Packard
[2010/03/12 19:04:58 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Hewlett-Packard
[2010/03/12 19:04:26 | 000,000,000 | RHSD | C] – C:\Users\Andrew Brown\Documents\My Pictures
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\Temporary Internet Files
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Templates
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Start Menu
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\SendTo
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Recent
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\PrintHood
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\NetHood
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Documents\My Videos
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Documents\My Music
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\My Documents
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Local Settings
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\History
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Cookies
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\Application Data
[2010/03/12 19:04:26 | 000,000,000 | -HSD | C] – C:\Users\Andrew Brown\AppData\Local\Application Data
[2010/03/12 19:04:25 | 000,000,000 | –SD | C] – C:\Users\Andrew Brown\AppData\Roaming\Microsoft
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Videos
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Saved Games
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Pictures
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Music
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Links
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Favorites
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Downloads
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Documents
[2010/03/12 19:04:25 | 000,000,000 | R–D | C] – C:\Users\Andrew Brown\Desktop
[2010/03/12 19:04:25 | 000,000,000 | -H-D | C] – C:\Users\Andrew Brown\AppData
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Temp
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\Microsoft
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Roaming\Media Center Programs
[2010/03/12 19:04:25 | 000,000,000 | —D | C] – C:\Users\Andrew Brown\AppData\Local\HuluDesktop
========== Files - Modified Within 30 Days ==========
[2010/04/02 19:06:41 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/02 19:06:41 | 000,023,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/02 19:03:42 | 001,572,864 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT
[2010/04/02 19:03:35 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/04/02 19:03:35 | 000,615,360 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/04/02 19:03:35 | 000,103,702 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/04/02 19:02:26 | 000,000,905 | —- | M] () – C:\Users\Andrew Brown\Desktop\ERUNT.lnk
[2010/04/02 19:00:06 | 000,000,334 | —- | M] () – C:\Windows\tasks\AdwarePro.job
[2010/04/02 18:59:10 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/04/02 18:59:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/04/02 18:59:01 | 3214,045,184 | -HS- | M] () – C:\hiberfil.sys
[2010/04/02 18:58:27 | 002,236,010 | -H– | M] () – C:\Users\Andrew Brown\AppData\Local\IconCache.db
[2010/04/02 18:50:39 | 000,001,009 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 18:43:36 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\Andrew Brown\Desktop\OTL.exe
[2010/04/02 07:12:33 | 000,000,478 | —- | M] () – C:\Windows\win.ini
[2010/04/02 07:11:20 | 001,101,086 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1105000.07F\Cat.DB
[2010/04/02 07:11:03 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001UA.job
[2010/04/02 07:11:03 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001Core.job
[2010/04/02 00:57:04 | 000,002,093 | —- | M] () – C:\Users\Andrew Brown\Desktop\HijackThis.lnk
[2010/03/31 22:47:35 | 000,000,360 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForAndrew Brown.job
[2010/03/31 22:47:30 | 000,435,184 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/03/29 23:56:53 | 000,002,611 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Publisher 2007.lnk
[2010/03/29 23:56:47 | 000,002,645 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/03/29 23:56:40 | 000,002,693 | —- | M] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Outlook 2007.lnk
[2010/03/29 21:54:31 | 000,115,920 | —- | M] () – C:\Users\Andrew Brown\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/29 15:24:58 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/03/18 07:03:44 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/15 22:33:45 | 000,000,126 | —- | M] () – C:\Windows\QUICKEN.INI
[2010/03/15 20:28:16 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/03/14 14:03:19 | 000,183,912 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcod168.dll
[2010/03/14 14:01:04 | 001,047,740 | —- | M] () – C:\Windows\SysNative\oem20.inf
[2010/03/14 14:00:18 | 003,896,832 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmihvsrv64.dll
[2010/03/14 14:00:18 | 003,561,472 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmihvui64.dll
[2010/03/14 14:00:18 | 003,053,560 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\drivers\BCMWL664.SYS
[2010/03/14 14:00:18 | 000,095,472 | —- | M] (Broadcom Corporation) – C:\Windows\SysNative\bcmwlcoi.dll
[2010/03/14 14:00:18 | 000,006,656 | —- | M] () – C:\Windows\SysNative\bcmwlrc.dll
[2010/03/14 12:39:26 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/03/13 13:19:54 | 000,524,288 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/03/13 13:19:54 | 000,524,288 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/03/13 13:19:54 | 000,065,536 | -HS- | M] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/03/13 03:00:39 | 000,039,219 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010/03/13 03:00:39 | 000,039,219 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010/03/12 19:40:34 | 000,023,117 | —- | M] () – C:\Windows\hpqins15.dat
[2010/03/12 19:24:15 | 000,173,104 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/03/12 19:24:15 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/03/12 19:24:15 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/03/12 19:04:41 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:41 | 000,000,000 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:26 | 000,000,020 | -HS- | M] () – C:\Users\Andrew Brown\ntuser.ini
[2010/03/09 04:28:28 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/03/09 04:28:27 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/03/09 04:28:26 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/03/09 04:28:20 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deploytk.dll
========== Files Created - No Company Name ==========
[2010/04/02 19:02:26 | 000,000,905 | —- | C] () – C:\Users\Andrew Brown\Desktop\ERUNT.lnk
[2010/04/02 18:50:39 | 000,001,009 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 00:57:04 | 000,002,093 | —- | C] () – C:\Users\Andrew Brown\Desktop\HijackThis.lnk
[2010/04/01 21:36:56 | 000,000,334 | —- | C] () – C:\Windows\tasks\AdwarePro.job
[2010/03/29 23:56:53 | 000,002,611 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Publisher 2007.lnk
[2010/03/29 23:56:47 | 000,002,645 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/03/29 23:56:40 | 000,002,693 | —- | C] () – C:\Users\Andrew Brown\Desktop\Microsoft Office Outlook 2007.lnk
[2010/03/18 21:39:25 | 000,574,100 | —- | C] () – C:\Windows\SysNative\hp1022n.img
[2010/03/18 21:39:25 | 000,567,296 | —- | C] () – C:\Windows\SysNative\ZSHP1020.EXE
[2010/03/18 21:39:25 | 000,206,768 | —- | C] () – C:\Windows\SysNative\hp1022.img
[2010/03/18 21:39:25 | 000,128,380 | —- | C] () – C:\Windows\SysNative\hp1020.img
[2010/03/18 21:39:25 | 000,010,632 | —- | C] () – C:\Windows\SysNative\ZSHP1020.CHM
[2010/03/18 07:03:44 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/17 18:09:13 | 000,574,100 | R— | C] () – C:\Windows\SysWow64\hp1022n.img
[2010/03/17 18:09:13 | 000,206,768 | R— | C] () – C:\Windows\SysWow64\hp1022.img
[2010/03/17 18:09:13 | 000,128,612 | R— | C] () – C:\Windows\SysWow64\hp1020.img
[2010/03/17 18:09:12 | 000,397,312 | R— | C] () – C:\Windows\SysWow64\zshp1020.exe
[2010/03/17 18:09:12 | 000,106,496 | R— | C] () – C:\Windows\SysWow64\vshp1020.dll
[2010/03/17 18:09:12 | 000,007,294 | R— | C] () – C:\Windows\SysWow64\ZSHP1020.HLP
[2010/03/15 22:32:15 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2010/03/15 20:28:16 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/03/14 14:01:15 | 001,047,740 | —- | C] () – C:\Windows\SysNative\oem20.inf
[2010/03/14 12:39:26 | 000,001,097 | —- | C] () – C:\Users\Public\Desktop\HP Support Assistant.lnk
[2010/03/13 23:47:18 | 000,085,504 | —- | C] () – C:\Windows\SysNative\cpwmon64.dll
[2010/03/13 18:12:50 | 000,000,360 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForAndrew Brown.job
[2010/03/13 00:59:34 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001UA.job
[2010/03/13 00:59:34 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4258229573-526587920-623500243-1001Core.job
[2010/03/12 19:40:02 | 000,023,117 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/12 19:40:02 | 000,000,366 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/03/12 19:24:16 | 000,007,440 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/03/12 19:24:16 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\QSwitch.txt
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\DSwitch.txt
[2010/03/12 19:22:49 | 000,000,000 | —- | C] () – C:\Users\Andrew Brown\AppData\Local\AtStart.txt
[2010/03/12 19:22:47 | 000,000,186 | —- | C] () – C:\ProgramData\HPWALog.txt
[2010/03/12 19:04:41 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:41 | 000,000,000 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_cNB_Pavilion dv6 Notebook PC_Y5335KV_0U_QCNF0065FQP_E587925-003_4A_I3659_SHP_V32.24_F.16_T100122_WU3-0_L409_M4087_J500_7Intel_86E5_91.60_#100210_N14E44357_(WA783UA#ABA)_XMOBILE_CN10
_Z.MRK
[2010/03/12 19:04:26 | 000,524,288 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/03/12 19:04:26 | 000,524,288 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/03/12 19:04:26 | 000,065,536 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/03/12 19:04:26 | 000,000,020 | -HS- | C] () – C:\Users\Andrew Brown\ntuser.ini
[2010/03/12 19:04:25 | 001,572,864 | -HS- | C] () – C:\Users\Andrew Brown\NTUSER.DAT
[2010/02/10 05:45:11 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2010/02/10 05:45:05 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2010/02/10 05:44:54 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2010/02/10 05:44:35 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2010/02/10 05:43:59 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2010/02/10 05:18:42 | 000,000,283 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/02/10 05:18:42 | 000,000,224 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/01/09 21:05:19 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2010/01/09 21:02:26 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2010/01/09 21:01:34 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2010/01/09 21:01:04 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2009/09/29 19:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
< End of report >
———————-
OTL Extra
OTL Extras logfile created on: 4/2/2010 7:05:04 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Andrew Brown\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.25 Gb Total Space | 329.51 Gb Free Space | 72.86% Space Free | Partition Type: NTFS
Drive D: | 13.21 Gb Total Space | 2.20 Gb Free Space | 16.63% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 96.46 Mb Free Space | 97.41% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ANDREWBROWN-PC
Current User Name: Andrew Brown
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416015FF}" = Java™ 6 Update 15 (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{64A3A4F4-B792-11D6-A78A-00B0D0160150}" = Java™ SE Development Kit 6 Update 15 (64-bit)
"{84BC87D4-0480-4E10-B15D-1E7886D55180}" = iTunes
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CutePDF Writer Installation" = CutePDF Writer 2.8
"FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{0345CF70-FA00-4F4E-A218-0FA494F465A4}" = LightScribe Template Designs - Business Pack 1
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1747DF05-6890-440B-B094-2146F5DC50E0}" = HP MediaSmart SlingPlayer
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 19
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47D7C9B8-BD44-4D2E-9040-E946477B2F9A}" = Microsoft Live Search Toolbar
"{495A8A3C-8FD0-4C46-9979-95C26181A1AB}" = HP Support Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{88A4002B-BDBA-49A2-927C-D81E8DF32B1B}" = LightScribe Applications
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B51605BF-6326-4553-AE96-6D7F1813D5F5}" = HP User Guides 0154
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP-LaserJet 1020 series" = LaserJet 1020 series
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"LimeWire" = LimeWire 5.5.7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NIS" = Norton Internet Security
"qwipdrrzgxgdcwghf" = Performance Solution Hotrevenue
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-4258229573-526587920-623500243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
========== Last 10 Event Log Errors ==========
[ Hewlett-Packard Events ]
Error - 3/22/2010 7:03:13 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)
Error - 3/22/2010 7:03:14 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)
Error - 3/29/2010 11:57:21 PM | Computer Name = AndrewBrown-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a(Object
A_0, EventArgs A_1)
[ System Events ]
Error - 3/13/2010 12:18:25 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.
Error - 3/13/2010 12:18:34 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.
Error - 3/13/2010 12:18:42 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.
Error - 3/13/2010 12:18:51 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.
Error - 3/13/2010 12:18:59 AM | Computer Name = AndrewBrown-PC | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.
Error - 3/18/2010 7:03:44 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 3/18/2010 7:03:44 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 3/18/2010 7:03:45 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 3/18/2010 7:03:46 AM | Computer Name = AndrewBrown-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 3/18/2010 9:57:34 PM | Computer Name = AndrewBrown-PC | Source = bowser | ID = 8003
Description =
< End of report >