OOoops sorry. Too much of a hurry, I guess.
OTL logfile created on: 4/21/2010 11:15:02 PM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 301.00 Mb Available Physical Memory | 59.00% Memory free
459.00 Mb Paging File | 335.00 Mb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 22.77 Gb Free Space | 59.55% Space Free | Partition Type: NTFS
Drive D: | 981.05 Mb Total Space | 961.82 Mb Free Space | 98.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet004
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand] – – (TuneUp.Defrag)
SRV - File not found [On_Demand] – – (getPlus® Helper) getPlus®
SRV - File not found [Auto] – – (aawservice)
SRV - [2009/04/27 01:22:08 | 000,020,680 | —- | M] (ESET) [On_Demand] – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe – (EhttpSrv)
SRV - [2009/04/27 01:22:04 | 000,731,840 | —- | M] (ESET) [Auto] – C:\Program Files\ESET\ESET Smart Security\ekrn.exe – (ekrn)
SRV - [2008/07/26 08:25:36 | 000,150,040 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/07/26 08:23:42 | 000,186,904 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2008/02/23 15:45:17 | 000,658,432 | —- | M] (Macrovision Europe Ltd.) [On_Demand] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2007/09/11 00:45:04 | 000,124,832 | —- | M] () [Auto] – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor6.0)
SRV - [2007/08/09 03:27:52 | 000,098,304 | —- | M] (HP) [Auto] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/03/07 16:47:46 | 000,076,848 | —- | M] () [On_Demand] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/04 17:38:08 | 000,049,152 | —- | M] (Viewpoint Corporation) [Disabled] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/04/27 14:59:24 | 000,266,240 | —- | M] (Microsoft Corporation) [Auto] – C:\Program Files\UPHClean\uphclean.exe – (UPHClean)
SRV - [2003/03/03 14:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | Boot] – – (vkquwexg)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (easdrv)
DRV - File not found [Kernel | System] – – (Changer)
DRV - File not found [Kernel | On_Demand] – – (catchme)
DRV - File not found [Kernel | On_Demand] – – (bvrp_pci)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Registry Filter)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Real-Time Scanner)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Connect Filter)
DRV - [2009/04/27 01:22:12 | 000,113,960 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\eamon.sys – (eamon)
DRV - [2009/04/27 01:22:08 | 000,033,096 | —- | M] (ESET) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwndis.sys – (Epfwndis)
DRV - [2009/04/27 01:22:04 | 000,131,976 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\epfw.sys – (epfw)
DRV - [2009/04/27 01:22:04 | 000,055,768 | —- | M] (ESET) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwtdi.sys – (epfwtdi)
DRV - [2008/07/26 11:26:56 | 000,023,832 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys – (FilterService)
DRV - [2008/07/26 11:26:44 | 004,658,584 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys – (LVUVC) Logitech QuickCam S5500(UVC)
DRV - [2008/07/26 11:26:22 | 000,041,752 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys – (LVUSBSta)
DRV - [2008/07/26 11:25:48 | 000,627,864 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys – (LVRS)
DRV - [2008/07/26 08:25:02 | 000,025,624 | —- | M] () [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2008/05/02 22:46:00 | 006,554,496 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys – (nv)
DRV - [2008/04/13 14:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 14:40:58 | 000,042,112 | —- | M] () [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys – (Imapi)
DRV - [2008/04/13 14:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2007/04/23 14:11:54 | 000,224,896 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wg111v3.sys – (RTL8187B)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2005/02/23 14:58:56 | 000,011,776 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys – (Afc)
DRV - [2004/08/04 01:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 01:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 01:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 01:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 01:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 01:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 01:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 01:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 01:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 01:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2003/08/29 04:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys – (BCMModem)
DRV - [2003/08/06 02:04:00 | 000,100,373 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2003/08/06 02:04:00 | 000,098,068 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2003/08/06 02:04:00 | 000,083,284 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2003/08/06 02:04:00 | 000,034,837 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2003/08/06 02:04:00 | 000,025,685 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2003/08/06 02:04:00 | 000,014,229 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2003/08/06 02:04:00 | 000,006,357 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2003/08/06 02:04:00 | 000,004,117 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2003/08/06 02:04:00 | 000,002,233 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys – (tfsndres)
DRV - [2003/07/31 04:21:00 | 000,084,576 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2003/07/14 12:28:40 | 000,005,621 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys – (sscdbhk5)
DRV - [2003/07/14 12:28:22 | 000,023,219 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys – (ssrtln)
DRV - [2003/06/20 03:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys – (drvnddm)
DRV - [2002/11/08 14:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2002/10/08 12:57:40 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:57:38 | 000,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys – (MODEMCSA)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 13:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/17 22:40:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:15:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/04/15 19:11:34 | 000,000,000 | —D | M]
[2010/04/17 22:40:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Extensions
[2010/04/17 22:40:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions
[2010/04/17 22:40:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/17 22:40:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions\staged-xpis
[2010/04/08 16:42:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/04/20 19:32:39 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 www.Brenz.pl
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [combofix] C:\CF\CF26651.cfx File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [qyfvwm] C:\WINDOWS\System32\msejfzrl.DLL File not found
O4 - HKU\Andrew_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Andrew_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\Cynthia_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Cynthia_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\LocalService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\LocalService_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\NetworkService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\NetworkService_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
F3 - HKU\.DEFAULT WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\fonts\services.exe File not found
F3 - HKU\.DEFAULT WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\fonts\services.exe File not found
F3 - HKU\Andrew_ON_C WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\fonts\services.exe File not found
F3 - HKU\Andrew_ON_C WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\fonts\services.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: mslivemsn = C:\Program Files\Windows NT\Accessories\svchost.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: exec = C:\WINDOWS\fonts\services.exe File not found
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Cynthia_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9}
http://download.microsoft.com/download/0/5…b?1076002397078 (MSSecurityAdvisor Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1120230108640 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{468c9b16-2eb4-11dd-8ee1-00038a000015}\Shell\AutoRun\command - "" = F:\EXPLORER.EXE – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: BtwSvc - C:\WINDOWS\SYSTEM32\BtwSvc.dll (dreas company)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003/10/23 03:03:14 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/04/20 19:48:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/04/18 09:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Mozilla
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Mozilla
[2010/04/17 22:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Malwarebytes
[2010/04/17 22:38:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\GTek
[2010/04/17 18:55:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\NetworkService\Cookies
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Macromedia
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Identities
[2010/04/17 18:47:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\Cynthia\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\SendTo
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Recent
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Application Data
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Start Menu
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Pictures
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Music
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Favorites
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Templates
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\PrintHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\NetHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Local Settings
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sun
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sonic
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Real
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Desktop
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\ApplicationHistory
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Utilities
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Unused Desktop Shortcuts
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\TomAdamczyk
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\The Letter
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\SeacoastOrientalRugEnvlogo
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\sallie
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\R. conley
[2010/04/17 18:45:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\PPS Files
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\patti
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\P. Montrone
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Nilsson
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\m
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Kremans
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\joe
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Izabelle's 8th Bday & jumping Pandy 07 054
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Humor
[2010/04/17 18:45:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Hide These Temp
[2010/04/17 18:45:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\elena
[2010/04/17 18:44:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\My Documents\Advanta_files
[2010/04/17 18:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Share-to-Web Upload Folder
[2010/04/17 18:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ESET
[2010/04/17 18:36:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010/04/17 18:16:56 | 000,000,000 | —D | C] – C:\~ErdUserProfile.$$$
[2010/04/17 17:58:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Andrew\Cookies
[2010/04/17 17:58:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/04/17 17:57:47 | 000,000,000 | –SD | C] – C:\Documents and Settings\Andrew\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\SendTo
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Recent
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Application Data
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Start Menu
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Pictures
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Music
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Favorites
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Templates
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\PrintHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\NetHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Local Settings
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sun
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sonic
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Real
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Macromedia
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Identities
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ApplicationHistory
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 17:57:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\Cookies
[2010/04/17 17:57:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\LocalService\Local Settings
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data
[2010/04/17 17:57:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Local Settings
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data
[2010/04/17 04:35:31 | 000,000,000 | -H-D | C] – C:\ErdUndoCache
[2010/04/16 07:20:49 | 000,000,000 | —D | C] – C:\Program Files\Protection System
[2010/04/15 19:32:45 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2010/04/15 19:15:47 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2010/04/15 17:58:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/12 23:40:08 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/12 22:57:38 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/12 22:36:43 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/12 22:33:20 | 000,057,856 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/12 08:26:57 | 000,000,000 | —D | C] – C:\OEMSettings
[2010/04/12 08:25:41 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/04/11 23:24:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 23:24:01 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 23:23:59 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/10 14:18:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/10 14:18:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/10 14:18:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/10 14:18:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/10 14:16:49 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/09 07:21:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/04/09 06:59:38 | 000,000,000 | —D | C] – C:\Infection
[2005/05/11 23:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
========== Files - Modified Within 30 Days ==========
[2010/04/21 07:30:39 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/21 07:30:39 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/21 07:30:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/21 07:24:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
[2010/04/21 07:00:00 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/04/20 19:33:03 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/04/20 19:32:42 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/20 19:32:39 | 000,000,314 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/20 19:32:39 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\Hosts
[2010/04/20 19:32:38 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/20 19:32:33 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/04/20 19:32:30 | 535,891,968 | -HS- | M] () – C:\hiberfil.sys
[2010/04/20 19:31:55 | 000,786,432 | -H– | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/20 19:31:55 | 000,786,432 | -H– | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/18 11:09:34 | 004,240,656 | -H– | M] () – C:\Documents and Settings\Andrew\Local Settings\Application Data\IconCache.db
[2010/04/17 18:48:03 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:48:03 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:38:47 | 000,000,104 | —- | M] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:07:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/15 19:06:24 | 000,182,038 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/15 18:28:48 | 000,001,964 | —- | M] () – C:\WINDOWS\disney.ini
[2010/04/14 18:31:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/14 18:14:01 | 000,000,292 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 22:36:56 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/04/11 10:24:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
[2010/04/09 17:14:00 | 000,000,749 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/04/09 17:14:00 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/04/08 20:17:45 | 000,000,882 | —- | M] () – C:\WINDOWS\orun32.ini
[2010/04/05 15:04:51 | 000,000,127 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/04/05 12:02:32 | 000,077,062 | —- | M] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/05 11:59:02 | 000,004,017 | —- | M] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/26 05:23:51 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/03/26 05:23:49 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2010/03/25 14:05:47 | 000,000,293 | —- | M] () – C:\WINDOWS\iPlayer.INI
========== Files Created - No Company Name ==========
[2010/04/20 19:30:13 | 535,891,968 | -HS- | C] () – C:\hiberfil.sys
[2010/04/17 18:47:41 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:47:41 | 000,008,192 | -H– | C] () – C:\Documents and Settings\Cynthia\ntuser.dat.LOG
[2010/04/17 18:47:41 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:44:34 | 002,392,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Ey Iran.pps
[2010/04/17 18:44:34 | 000,728,850 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ISLAMICOSCARGOESTO.wmv
[2010/04/17 18:44:34 | 000,460,690 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Cash002.zip
[2010/04/17 18:44:34 | 000,455,999 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Heriz ka.pdf
[2010/04/17 18:44:34 | 000,301,056 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ANDREWSLIST.xls
[2010/04/17 18:44:34 | 000,226,340 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Andrewslist.123
[2010/04/17 18:44:34 | 000,068,096 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Invoice.doc
[2010/04/17 18:44:34 | 000,025,600 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Gift Certificate.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Espacio Design 4.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Appraisal letter March 30.doc
[2010/04/17 18:44:34 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ITALIAN.doc
[2010/04/17 18:44:34 | 000,000,794 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Bidjar 11.7 X18.9.lnk
[2010/04/17 18:44:34 | 000,000,761 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Get High Speed Internet!.lnk
[2010/04/17 18:44:33 | 000,486,272 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Speedsters.jpg
[2010/04/17 18:44:33 | 000,438,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Vahid.zip
[2010/04/17 18:44:33 | 000,430,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\123.pps
[2010/04/17 18:44:33 | 000,383,424 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\2008 Tagavi A Form 1040 Individual Tax Return.tax2008
[2010/04/17 18:44:33 | 000,227,684 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\5.5 X 7.9.JPG
[2010/04/17 18:44:33 | 000,154,870 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\AhundovFamilyTree.zip
[2010/04/17 18:44:33 | 000,122,300 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Setade_Koodeta.pdf
[2010/04/17 18:44:33 | 000,092,672 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\rug cleaning certificate.doc
[2010/04/17 18:44:33 | 000,077,062 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/17 18:44:33 | 000,060,587 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\pelosinowruzletter_3.08.pdf
[2010/04/17 18:44:33 | 000,050,176 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\warm up certificate.doc
[2010/04/17 18:44:33 | 000,040,960 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\saddle fitting.doc
[2010/04/17 18:44:33 | 000,034,775 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\LtrtoclientwithdraftlettertoAttyMiller9-6-07.wpd.zip
[2010/04/17 18:44:33 | 000,029,184 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News.doc
[2010/04/17 18:44:33 | 000,026,624 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News #3 2nd edition.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Taylor.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\seacoast media.doc
[2010/04/17 18:44:33 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tonry.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\TUFTED.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted rugs.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted 2.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Sale.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\sale sideways.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Persian.doc
[2010/04/17 18:44:33 | 000,022,090 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Advanta.htm
[2010/04/17 18:44:33 | 000,020,992 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\nicker news3.doc
[2010/04/17 18:44:33 | 000,004,017 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/04/17 18:44:33 | 000,000,440 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Shortcut to Vendors.lnk
[2010/04/17 18:38:47 | 000,000,104 | —- | C] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:01:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/04/17 17:57:47 | 000,016,384 | -H– | C] () – C:\Documents and Settings\Andrew\ntuser.dat.LOG
[2010/04/17 17:57:47 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/17 17:57:46 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/17 17:57:40 | 000,786,432 | -H– | C] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/17 17:57:40 | 000,008,192 | -H– | C] () – C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2010/04/17 17:57:40 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\LocalService\NTUSER.INI
[2010/04/17 17:57:37 | 000,008,192 | -H– | C] () – C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2010/04/17 17:57:37 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\NetworkService\NTUSER.INI
[2010/04/17 17:57:36 | 000,786,432 | -H– | C] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/15 19:15:53 | 000,000,314 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/12 22:36:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/12 22:36:48 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/10 14:18:54 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/10 14:18:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/10 14:18:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/10 14:18:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/10 14:18:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/07 17:05:10 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/05 15:04:51 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/06/17 10:32:47 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/05/02 22:46:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/02 22:46:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/02 22:46:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/14 20:15:10 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/08/01 14:13:44 | 000,000,344 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/06/08 12:28:18 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/06/08 12:27:56 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/06/08 12:23:33 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/28 15:36:44 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/09/18 14:56:55 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2005/06/30 10:17:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/04/13 11:38:24 | 000,004,560 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/18 12:20:46 | 000,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/11/18 12:11:29 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/11/18 12:11:28 | 000,000,365 | —- | C] () – C:\WINDOWS\upst.ini
[2004/10/30 15:14:45 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2004/08/24 13:39:18 | 000,000,844 | —- | C] () – C:\WINDOWS\hegames.ini
[2004/08/24 13:39:14 | 000,000,080 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2004/08/07 15:31:23 | 000,000,024 | —- | C] () – C:\WINDOWS\RVBOOK.INI
[2004/01/23 11:29:51 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2004/01/23 11:25:39 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2003/12/29 11:42:06 | 000,001,964 | —- | C] () – C:\WINDOWS\disney.ini
[2003/12/05 17:22:04 | 000,000,293 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/01 16:42:01 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/10/29 17:31:35 | 000,000,024 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/10/23 03:48:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/10/23 03:46:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/10/23 03:35:08 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/10/23 03:19:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/23 03:19:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/10/23 03:07:02 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:13:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 000,042,112 | —- | C] () – C:\WINDOWS\System32\drivers\imapi.sys
[2002/08/29 06:00:00 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\FInstall.sys
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2010/04/21 07:00:00 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010/04/20 19:32:39 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2008/02/16 13:09:20 | 023,454,528 | —- | M] ( ) – C:\AdbeRdr812_en_US.exe
[2005/12/06 10:37:30 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2007/05/23 13:35:47 | 011,470,608 | —- | M] () – C:\avgas-setup-7.5.0.50.exe
[2006/06/08 11:20:38 | 000,274,432 | —- | M] (Versis) – C:\c0.exe
[2004/08/31 11:15:49 | 009,663,488 | —- | M] (Skype Software S.A. ) – C:\SkypeSetup.exe
[2006/12/27 17:21:52 | 002,035,200 | —- | M] () – C:\ventrilo-2.3.0-Windows-i386.exe
< MD5 for: AGP440.SYS >
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 14:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:atapi.sys
[2003/01/31 16:43:30 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3C33F5479520844A186C2D43ECFFD477 – C:\I386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 06:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=5E5291243091DC2F97A583569153299A – C:\WINDOWS\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007/06/13 07:26:03 | 001,057,792 | —- | M] (Microsoft Corporation) MD5=AFCFE2590EA360162D845D093FD13363 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 06:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 03:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: RUNDLL32.EXE >
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=037B1E7798960E0420003D05BB577EE6 – C:\WINDOWS\ServicePackFiles\i386\rundll32.exe
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=037B1E7798960E0420003D05BB577EE6 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rundll32.exe
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=09263C41BEE92C17D663BF487BCF2962 – C:\WINDOWS\SYSTEM32\rundll32.exe
[2002/08/29 06:00:00 | 000,031,744 | —- | M] (Microsoft Corporation) MD5=0FB22DD37C17F80AD71316049F725170 – C:\I386\RUNDLL32.EXE
[2004/08/04 03:56:55 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=DA285490BBD8A1D0CE6623577D5BA1FF – C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe
< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 06:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll
< MD5 for: USERINIT.EXE >
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=3833FA6B1774DDCAC290CE0643CFCD1B – C:\_OTL\MovedFiles\04202010_194810\C_\userinit.exe
[2004/08/04 03:56:57 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,050,688 | —- | M] (Microsoft Corporation) MD5=A0B3BE24EB75AA0A08C14C1682D3DC56 – C:\WINDOWS\SYSTEM32\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2002/08/29 06:00:00 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB – C:\I386\USERINIT.EXE
< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 06:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/06/20 13:46:57 | 000,147,968 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dnsapi.dll
[2010/03/11 08:38:52 | 006,067,200 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ieframe.dll
[2010/03/11 08:38:52 | 000,268,288 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\iertutil.dll
[2008/04/13 20:12:00 | 000,274,944 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\mstask.dll
[2008/04/13 20:12:02 | 000,067,072 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ntdsapi.dll
[2008/04/13 20:12:03 | 000,023,040 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\psapi.dll
[2008/06/17 15:02:19 | 008,461,312 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\shell32.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2002/09/03 14:22:52 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 14:22:52 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 14:22:52 | 000,397,312 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services >
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\.NET CLR Data]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\.NET CLR Networking]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\.NET Data Provider for Oracle]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\.NET Data Provider for SqlServer]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\.NETFramework]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\6to4]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Abiosdsk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\abp480n5]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ACPI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ACPIEC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ad-Watch Connect Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ad-Watch Real-Time Scanner]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ad-Watch Registry Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AdobeActiveFileMonitor6.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\adpu160m]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aeaudio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aec]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Afc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\agp440]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\agpCPQ]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Aha154x]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aic78u2]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aic78xx]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Alerter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ALG]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AliIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\alim1541]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\amdagp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\amsint]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\asc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\asc3350p]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\asc3550]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ASP.NET]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ASP.NET_1.1.4322]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ASP.NET_2.0.50727]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\aspnet_state]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AsyncMac]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\atapi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Atdisk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Atmarpc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AudioSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\audstub]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BattC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BCMModem]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Beep]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BITS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\bvrp_pci]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cbidf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cbidf2k]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CCDECODE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cd20xrnt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdaudio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdfs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Changer]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CiSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ClipSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\clr_optimization_v2.0.50727_32]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CmdIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\COMSysApp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ContentFilter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ContentIndex]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cpqarray]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dac2w2k]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dac960nt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Disk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dmadmin]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dmboot]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dmio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dmload]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dmserver]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DMusic]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Dnscache]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Dot3svc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Dot4]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Dot4Print]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dpti2o]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\drmkaud]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\drvmcdb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\drvncdb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\drvnddm]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DSBrokerService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DSproct]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dsunidrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\E100B]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\eamon]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EapHost]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\easdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EhttpSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ekrn]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EL90XBC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\epfw]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Epfwndis]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\epfwtdi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ERSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EventSystem]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fastfat]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FastUserSwitchingCompatibility]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fax]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fdc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FilterService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fips]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FLEXnet Licensing Service]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Flpydisk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FltMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FontCache3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ftdisk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\getPlus® Helper]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Gpc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gupdate]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\helpsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HidServ]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HidUsb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\hkmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\hpn]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HPZid412]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HPZipr12]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HPZius12]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HTTP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HTTPFilter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\i2omp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\i8042prt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\i81x]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimFP0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimFP1]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimFP2]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimFP3]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimFP4]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimTV0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimTV1]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimTV3]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iAimTV4]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ias]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ICSharing]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\idsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ILADFtmi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Imapi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ImapiService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\inetaccs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ini910u]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Inport]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IntelIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\intelppm]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ip6fw]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IpFilterDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IpInIp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IpNat]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IPSec]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IRENUM]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\isapnp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\JavaQuickStarterService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Kbdclass]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\kmixer]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\KSecDD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\lanmanserver]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\lanmanworkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ldap]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LicenseService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVCOMSer]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVPr2Mon]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVPrcSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVRS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVUSBSta]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LVUVC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MDM]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mnmdd]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mnmsrvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Modem]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MODEMCSA]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Mouclass]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mouhid]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MountMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mraid35x]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MRxDAV]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MRxSmb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSDTC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSDTC Bridge 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Msfs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSKSSRV]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSPCLOCK]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSPQM]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mssmbios]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSTEE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Mup]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NABTSFEC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\napagent]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NdisIP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NdisTapi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NdisWan]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NDProxy]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetDDE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetDDEdsdm]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Netman]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetTcpPortSharing]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Nla]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Npfs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ntfs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NtLmSsp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NtmsSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Null]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\nv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NVSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NwlnkFlt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NwlnkFwd]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\omci]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ose]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Outlook]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\P3]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Parport]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PartMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ParVdm]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PCI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PCIDump]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PCIIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PDRELI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\perc2]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\perc2hib]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PerfNet]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PerfOS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PerfProc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Pml Driver HPZ12]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PptpMiniport]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Processor]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectedStorage]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PSched]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ptilink]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PxHelp20]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ql1080]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ql12160]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ql1240]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ql1280]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasAcd]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasAuto]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Rasl2tp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasMan]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasPppoe]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Raspti]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDPCDD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDPDD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\rdpdr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDPNP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDPWD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDSessMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\redbook]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteRegistry]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcLocator]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RSVP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SamSs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Schedule]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ScsiPort]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\seagate]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Secdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\seclogon]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SENS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\serenum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Serial]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ServiceModelEndpoint 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ServiceModelOperation 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ServiceModelService 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sfloppy]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ShellHWDetection]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Simbad]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sisagp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SLIP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SMSvcHost 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\smwdm]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sparrow]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\splitter]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Spooler]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srservice]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Srv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sscdbhk5]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SSDPSRV]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ssrtln]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\StillCam]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\stisvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\streamip]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\swenum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\swmidi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SwPrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\swwd]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\symc810]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\symc8xx]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sym_hi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sym_u3]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sysaudio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SysmonLog]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TapiSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDPIPE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDTCP]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TermDD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TermService]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnboio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsncofs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsndrct]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsndres]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnifs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnopio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnpool]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnudf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tfsnudfa]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Themes]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TlntSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TosIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TrkWks]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TSDDD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TuneUp.Defrag]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Udfs]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ultra]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UPHClean]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\upnphost]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UPS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbaudio]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbccgp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbehci]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbhub]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbprint]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbscan]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\USBSTOR]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbuhci]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usbvideo]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\usb_rndisx]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\UxTuneUp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VgaSave]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\viaagp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ViaIde]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Viewpoint Manager Service]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VolSnap]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\VSS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\w32time]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\W3SVC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Wanarp]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wanatw]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WDICA]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wdmaud]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WebClient]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Windows Workflow Foundation 3.0.0.0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\winmgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winsock]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinSock2]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinTrust]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WmdmPmSN]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Wmi]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WmiApRpl]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WmiApSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WMPNetworkSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WpdUsb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WS2IFSL]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WSTCODEC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WZCSVC]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\xmlprov]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\_VOIDcbvttrrpti]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\_VOIDd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{1A1CBABA-7939-4300-89B4-A2FC3ED1A4FB}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{897681E9-2067-422E-A8FD-37CBF811F708}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{9E4666F9-5B38-457B-AD43-3D143745F1A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{F03DADE8-1256-4290-93D5-CA3CD6AC7B61}]
< End of report >
Extras -
OTL Extras logfile created on: 4/21/2010 11:15:02 PM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 301.00 Mb Available Physical Memory | 59.00% Memory free
459.00 Mb Paging File | 335.00 Mb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 22.77 Gb Free Space | 59.55% Space Free | Partition Type: NTFS
Drive D: | 981.05 Mb Total Space | 961.82 Mb Free Space | 98.04% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet004
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"" =
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"" =
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"" =
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\trueplay.exe" = C:\Program Files\Real\RealPlayer\trueplay.exe:*:Disabled:RealOne Player – (RealNetworks, Inc.)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – File not found
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{00F0588F-5F9C-4661-84E0-176790BDF709}" = ESET Smart Security
"{0143CF89-5CF2-4F2D-80D5-BFAE64E1BA00}" = Media Wizard 3.0
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{06230E02-2B7E-11D2-92D0-0040051BD005}" = OLYMPUS CAMEDIA Master 2.5
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{60859BF2-5151-473C-8F76-7F3A232CF7E7}" = MM Number Heroes
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70C002F0-5308-42D8-A65A-91436B90255C}" = MakeAMov
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AEAEEAD6-38EC-4321-92A7-599367E21FF2}" = Rosetta Stone V3 DEMO
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus®
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DD2F0FE7-A3FD-45AE-92A6-DA46166B3158}" = Find Rugs
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF6F70D0-C242-4047-946B-98EA8208481A}" = ArcSoft TotalMedia Backup & Record
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"102 Dalmatians Activity Center" = 102 Dalmatians Activity Center
"ACDSee" = ACDSee
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"AOL Toolbar 5.0" =
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Excel Invoice Manager_is1" = Excel Invoice Manager 2.12.1016
"Full Speed2.1" = Full Speed
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"InstallShield_{70C002F0-5308-42D8-A65A-91436B90255C}" = Make a Movie
"InstallShield_{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"InstallShield_{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"InterActual Player" = InterActual Player
"Knowmad" = Knowmad
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetAlyzer_is1" = NetAlyzer 0.3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealOne Player
"Revo Uninstaller" = Revo Uninstaller 1.85
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"The ClueFinders Reading Adventures Ages 9-12" = The ClueFinders Reading Adventures Ages 9-12
"TS2AC" = Toy Story 2 Activity Center
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
< End of report >
How's that? Again, I'm standing by … all day today, I"m home.
H
Update 4/24/10 - while waiting for a reply (I definitely am alert to a page 4 here…) I rebooted the system multiple times. Sometimes I get past the logon, up to the wallpaper and then it hangs. Hard reset needed. Most times I do get past the logon, up to the wallpaper and then it logs right off. So, it looks like I'm at where we were about a week or more ago - just not able to log on and stay logged on. I've tried this with all three resident accounts in normal mode and all three resident accounts and the Admin account in Safe Mode. HTH and we're standing by.
Note: My brother is obviously anxious about this primarily because the kids have no computer for homework purposes. So I loaned them my laptop the other day. But that computer doesn't have things like their classwork, passwords and other school related features installed (and I'd rather not have those on my stuff). Again the fact that we're getting any assistance for no cost isn't lost on me. Quite to the contrary, I do appreciate it greatly. However, brother calls me daily asking about it and I've run out of things to tell him. I've fully explained about the whole process at "WhatTheTech" being what it is and what it would mean re-installing and starting from zero. He says to me this morning "Let's just do it"… I do have his files preserved off on an external drive. I'll keep going here but I hope you'll understand that at some point, it's going to come down to returning the computer in some state of usability. I surely want to keep going and see it through. On the other hand there's the competing exigency of getting it back to the family as soon as possible. That's our situation at present….
Again, standing by… Thank you again!
H